01Summary
DHS disclosed on 1 July 2026 that an unknown actor compromised HSIN between late May and early June. Attackers targeted core servers and the SharePoint collaboration system, potentially exposing security planning and coordination for World Cup events. Suspicious activity was spotted in mid-to-late May but twice ruled harmless, which let the intruders stay for weeks. Classified systems were not affected. DHS has not said whether documents were stolen or who was behind the attack.
02Key revelations
- 01Early alerts were twice dismissed as false positives.
03Victims and impact
Countries affected
- United States
04Data exposed
Data types
- Event security planning
- Coordination documents
05Timeline
- 2026-05-20Suspicious activity first seen (mid-to-late May); twice dismissed.
- 2026-07-01DHS discloses the breach.
06Significance and legacy
Significance
Compromise of the platform that coordinated security for a global sporting event while the event was under way.
07Disclosure and media
Publishing organisations
- BleepingComputer
- Nextgov/FCW
- TechRepublic
08Sources
References
- [1]BleepingComputer: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/
- [2]Nextgov/FCW: https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/









