That network, the Homeland Security Information Network (HSIN), is used by federal, state, local, tribal, territorial law enforcement and private sector partners to share intelligence, collaborate on events and respond to incidents, Warner said in a Wednesday (July 1) press release.
“The information in HSIN, while not classified, is highly sensitive, and its exposure risks national security,” Warner said. “DHS and DOJ must thoroughly investigate who breached HSIN, what the attackers accessed, and ensure all DHS partners are provided with timely information and the tools necessary to mitigate any associated risks from the breach.”
“Furthermore, DHS must take a serious look within and account for how this happened and ensure that a breach like this does not happen again,” Warner said.
Nextgov/FCW reported Tuesday (June 30) that HSIN had been accessed by an unknown “threat actor” in late May or early June and that DHS investigators were probing the incident.
It was unclear who performed the hack or whether they took any documents from the system, the report said, citing unnamed sources.
The report said the breach could raise concerns about the theft of details around security planning for World Cup events across the United States.
Asked by Nextgov/FCW to respond to the report, a DHS spokesperson said the agency was responding to the incident.
“The Department of Homeland Security is aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment,” the spokesperson said, per the report. “We immediately took action to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation.”
According to the report, Nextgov/FCW learned in 2023 that a contractor’s coding error caused restricted HSIN data to be exposed to unapproved users inside the platform at that time.
In another, separate incident, it was reported in April that the Federal Bureau of Investigation (FBI) had classified a breach of its networks as a “major incident,” meaning that agencies and their contractors were required to implement security measures to protect computer systems.