AIO APEX

Hackers spent up to five weeks inside a DHS network used to plan World Cup security, senator demands DOJ probe

PYMNTS / Reuters
Share:
Hackers spent up to five weeks inside a DHS network used to plan World Cup security, senator demands DOJ probe

The Department of Homeland Security's Homeland Security Information Network — a platform used by federal, state, local, and approved private-sector partners to share sensitive intelligence and coordinate on major events — was breached for as long as five weeks in late May and early June 2026, according to reports first surfaced this week. Senator Mark Warner, Vice Chair of the Senate Select Committee on Intelligence, is now calling for a joint investigation by DHS and the Department of Justice.

What Was Compromised

Hackers reportedly gained access to HSIN servers and a SharePoint-based collaboration environment used by the network's federal, state, and local partners. DHS has confirmed the incident, stating that affected systems were isolated immediately upon discovery, vulnerabilities were mitigated, and a forensic investigation is underway. The department says there is no evidence that classified networks were affected, and HSIN remains operational. The precise scope of what data was accessed, and the identity of the intruders, has not been publicly disclosed.

Why HSIN Matters

HSIN is not a classified system, but it functions as critical connective tissue for homeland security coordination — used for sharing intelligence, planning security operations, and managing incident response across thousands of federal, state, local, tribal, and private-sector partners. Warner specifically flagged that HSIN is being used for security planning around the 2026 FIFA World Cup and America250 celebrations, and that it played a role in the response to a January 2025 mid-air collision. A breach of a system this deeply embedded in event security planning carries stakes well beyond a typical data exposure incident.

Not the First Lapse

This isn't HSIN's first security failure. In 2023, a misconfiguration on the platform exposed restricted DHS intelligence material to users who weren't authorized to see it. The recurrence of security failures on the same system — this time an actual intrusion rather than a misconfiguration — is likely to intensify scrutiny of how DHS manages access controls and monitoring across the platform.

What Warner Is Demanding

Warner has called on DHS and the DOJ to jointly determine who breached the network, what specific information was accessed, how the attackers gained entry, and whether the intrusion spread to any downstream networks belonging to HSIN's partner organizations. He's also pushing for a detailed briefing to Congress on the incident and a concrete plan to prevent recurrence, stating that DHS needs to “take a serious look within and account for how this happened” to restore confidence in the platform.

The Timing Problem

The breach's timing — discovered just months before the World Cup and America250 events HSIN is meant to help secure — puts pressure on DHS to resolve both the immediate forensic questions and the longer-term trust problem before those events arrive. Whether the intrusion is attributed to a nation-state actor, a criminal group, or something else entirely will shape how seriously Congress treats this as a national security matter rather than a routine breach disclosure. As reported by PYMNTS, based on Reuters' original reporting, DHS has not yet provided the public briefing Warner is requesting.

Originally reported by PYMNTS / Reuters. Read the original article for additional details.

View original source
Share: