Platform Shifts

GAO to audit DHS summer cyber breach and other security

 ·  By Flavia Pembridge
Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.
Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security. Photo: Towfiqu barbhuiya/Pexels

According to sources familiar with the matter, the Government Accountability Office plans to audit the Department of Homeland Security’s chief information-sharing system. The review will examine three security breaches that occurred on DHS networks between 2023 and 2026, one of which was an external hacking incident first reported/FCW this summer. The audit will focus on the Homeland Security Information Network (HSIN), a platform that enables federal agencies, law-enforcement bodies and other authorized partners to exchange sensitive but unclassified data. Users depend on HSIN to circulate threat alerts, coordinate protection for large-scale events, and react to emergency situations.

GAO has pinpointed two incidents that resulted from mistakes by employees or contractors. In 2023, a coding flaw introduced by a contractor allowed HSIN participants to view information for which they lacked clearance, as detailed in a memo obtained by Nextgov/FCW. A comparable lapse occurred in 2025. The latest breach involved a malicious actor whose affiliation has not been identified.

During that episode, DHS analysts dismissed suspicious activity on two occasions, treating it as benign and thereby permitting the intruders to remain in the system for several weeks. Internal readouts indicate that anomalous behavior began in mid-May, and by June 4 the attackers had installed covert access points and exfiltrated credential data used for authenticating accounts, prompting officials to declare an active breach.

This summer’s intrusion is placed by the audit within a broader pattern of security weaknesses on the platform. The examination also questions whether DHS has supplied Congress and HSIN stakeholder groups with sufficient detail to assess what information may have been compromised. The review is being conducted in response to a directive contained in the fiscal 2025 defense policy package. GAO’s assessment is expected to record the incidents and may scrutinize DHS for failing to notify Congress promptly about the security failures. The department has said it was aware of a recent cyber event affecting a specific, unclassified legacy information-sharing environment, that it isolated the impacted systems, remediated the vulnerability, and launched a forensic investigation.

Sen. Mark Warner, D-Va., vice chairman of the Senate Intelligence Committee, previously noted that HSIN supported security coordination for this summer’s World Cup and America250 events and warned that the network’s exposure “risks national security.” The extent of any data that may have been taken from the system remains unclear. While the audit will cover incidents through 2026, the timing of the final report has not been announced.

Leave a Comment

Your email address will not be published.