GAO to probe DHS network breaches and notification delays
The Government Accountability Office is preparing an audit of three security incidents on the Department of Homeland Security’s Homeland Security Information Network. The review covers incidents from 2023 through 2026, including an intrusion reported this summer, and may criticize DHS for delaying notice to Congress. The audit follows a directive in the fiscal 2025 defense policy law.
The GAO review stems from a requirement in the fiscal 2025 defense policy law. It will cover three HSIN security failures from 2023 through 2026, including this summer’s breach by an unidentified malicious actor. Two earlier episodes involved mistakes by employees or contractors, including a 2023 coding flaw that let users reach restricted material and a comparable 2025 event.
HSIN distributes nonclassified sensitive material through restricted groups known as communities of interest. Some fusion center personnel reportedly still do not know whether their files were improperly viewed. A senator has said the platform supported coordination for World Cup and America250 security and that its exposure carries risks to national security.
The audit’s findings could affect how quickly Congress and state/local partners learn about breaches on a system used for threat sharing and emergency coordination. If confidence erodes, fusion centers and law enforcement may hesitate to share time-sensitive information, potentially complicating event security and disaster response. The review may also prompt stronger notification practices, though its practical impact will depend on whether agencies adopt recommended changes.