EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/2026-dhs-hsin-breach
032/430

File EL-0399CriticalOngoingEspionage Operation / Government Network Intrusion

DHS Homeland Security Information Network Breach

Also filed as HSIN Breach · World Cup Security Network Breach

Unknown hackers breached DHS's unclassified Homeland Security Information Network, which was coordinating 2026 World Cup security. Staff twice dismissed warning signs as false positives.

  • #government
  • #dhs
  • #world-cup
  • #sharepoint
  • #united-states
Notoriety9/10
Event
20 May 2026
Disclosed
1 Jul 2026
Target
US Department of Homeland Security
Status
Ongoing

01Summary

DHS disclosed on 1 July 2026 that an unknown actor compromised HSIN between late May and early June. Attackers targeted core servers and the SharePoint collaboration system, potentially exposing security planning and coordination for World Cup events. Suspicious activity was spotted in mid-to-late May but twice ruled harmless, which let the intruders stay for weeks. Classified systems were not affected. DHS has not said whether documents were stolen or who was behind the attack.

02Key revelations

  1. 01Early alerts were twice dismissed as false positives.

03Victims and impact

Countries affected

  • United States

04Data exposed

Data types

  • Event security planning
  • Coordination documents

05Timeline

  1. 2026-05-20Suspicious activity first seen (mid-to-late May); twice dismissed.
  2. 2026-07-01DHS discloses the breach.

06Significance and legacy

Significance

Compromise of the platform that coordinated security for a global sporting event while the event was under way.

07Disclosure and media

Publishing organisations

  • BleepingComputer
  • Nextgov/FCW
  • TechRepublic

08Sources

References

  1. [1]BleepingComputer: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/
  2. [2]Nextgov/FCW: https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/
Fact sheetEL-0399

Dates

Event
20 May 2026
Started
20 May 2026
Disclosed
1 Jul 2026
Ongoing
No

Target

Organisation
Department of Homeland Security — Homeland Security Information Network (HSIN)
Type
Federal Government Department
Sector
Government / Homeland Security
Country
United States
Gov. level
Federal

Actor

Arrested
No
Convicted
No

Data

Sensitivity
Confidential

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.