Publisher: Nextgov/FCW (David DiMolfetta)
Date Published: July 13, 2026
Relevant To: Federal information-sharing network (HSIN) breach — case study in repeated false-positive dismissal of intrusion signals before breach confirmation
Verification Status: Verified (confirmed via full-text fetch)
Notes: Nextgov/FCW (David DiMolfetta) reports DHS personnel twice dismissed signs of intruders inside the Homeland Security Information Network (HSIN) as harmless before a breach was confirmed, per an internal incident readout. HSIN houses sensitive (unclassified) data shared across federal, state, local, industry, and international partners, and is being used to support ongoing World Cup security/logistics and America250 events. Timeline: May 15-24, FEMA analysts detected altered files, malicious code run via a legitimate web-server program, and deleted activity logs — ruled a false positive. May 25-June 3, similar low-profile activity triggered more alerts, again dismissed. June 4, hackers installed hidden backdoors and stole credential files, at which point a breach was declared active. DHS has not determined attacker affiliation; may brief Congress in a classified setting. Sen. Mark Warner (D-VA) called the exposed data “highly sensitive” with national-security exposure risk despite being unclassified. Notes a pattern: this follows a suspected China-linked FBI surveillance-system breach (Feb. 2026) and a FEMA/CBP employee-data breach (fall 2025). Relevant to BPA’s government-data-security tracking as a case study in detection failure (two false-positive rulings) enabling extended dwell time for attackers inside a sensitive federal information-sharing system.