The United States Department of Homeland Security is investigating a cyber attack against the Homeland Security Information Network (HSIN). The system is an important information-sharing platform between the federal, state and local agencies of the United States, and the attacks occurred in late May and early June 2026, possibly involving sensitive and unclassified information.

The attack took place between the end of May and the beginning of June.

According to Nextgov, first disclosed, Blacking Computer confirmed that hackers had access to the HSIN server during the above time period. The United States Department of Homeland Security has confirmed its knowledge of this “recent cyber event”, but has not yet indicated the specific type, scale and availability of data that were accessed.

The spokesperson for the Department of Homeland Security described the affected system as an “undefined, old version of the information-sharing environment”. However, for practical purposes, HSIN is still in operation and is not decommissioned.

HSIN is still used for cross-sectoral security coordination

HSIN is not just a file storage or internal communication tool. It connects federal agencies, state police, local law enforcement and emergency management agencies to share intelligence, develop action programmes and coordinate in real time in emergencies.

Public information indicates that the platform is still supporting security synergies in the United States World Cup 2026. Mark Werner, a senior member of the Senate Intelligence Committee, also mentioned that the multisectoral emergency response also relied on this platform for coordination following an air crash in Washington, D.C., in 2025.

  • Target audience covers federal, state and local agencies
  • It's still being used for World Cup security coordination.
  • Former participant in coordination of major accident response

MPs claim to be leaking or endangering national security

Werner states that HSIN is highly sensitive, although technically non-confidential, and may pose national security risks if exposed. Such information, which usually needs to be shared among multiple agencies, is not necessarily classified at the highest level, but may still involve threat assessments, enforcement action arrangements and cross-sectoral synergy details.

At present, investigators have yet to disclose the identity, background and motivation of the attackers. It is also impossible to confirm whether the incident was a State-sponsored intelligence operation or a profit-making hack. As these key issues remain unclear, the scope of the impact of the incident is not yet fully assessed.

Federal cyber security incidents.

This incident is not an isolated case. The report mentions that, since 2025, the United States federal system has experienced a succession of cyber-security problems, including failures in government system access controls, leakage of contractor certificates and major incidents involving exposure to federal surveillance target information.

In this context, the invasion of HSIN further highlighted the pressure on the federal Government to maintain old information systems, monitor threats on a continuous basis and invest security resources. The Department of Homeland Security has not yet disclosed the progress of the repairs or provided a follow-up response.