Hackers breached DHS after alarms were twice ruled ‘false positives’


Hackers managed to find their way into the US Department of Homeland Security’s primary information sharing platform, gaining unfettered access to the HSIN network that hosts unclassified information that multiple US agencies and international rely on.

The hack allowed the attackers to modify server files, run malicious code and steal credential files while installing backdoors and deleting logs to remove their digital footprint.

Their movements were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time before an active breach was declared a month later.

Read more…
Source:  TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • US offers $5 million reward for information on North Korean hackers

    April 15, 2020

    The US government is willing to pay up to $5 million for information on North Korea’s hackers and their ongoing hacking operations. The reward for reporting North Korean hackers was announced today in a joint report published by the Departments of State, Treasury, Homeland Security, and the Federal Bureau of Investigation. The joint report contains a summary ...

  • US government agencies have shadow IT infrastructure problem, cybersecurity risks, says GAO

    March 5, 2020

    Federal agencies are facing increasing cybersecurity risks due to a bevy of IT facilities aren’t being tracked as full-fledged data centers, according to a General Accountability Office report. As noted previously, federal agencies have been consolidating and closing data centers over the years, but a narrower definition of what facilities should fall under an optimization program means that ...

  • Swiss encryption company secretly owned by U.S. and German intelligence agencies

    February 11, 2020

    The U.S. intelligence community actively monitored for decades the diplomatic and military communications of numerous Latin American nations through encryption machines supplied by a Swiss company that was secretly owned by the CIA and the German intelligence agency, BND, according to reports today by the German public television channel, ZDF and the Washington Post. Declassified records ...

  • Federal Agencies Use Cellphone Location Data for Immigration Enforcement

    February 7, 2020

    The Trump administration has bought access to a commercial database that maps the movements of millions of cellphones in America and is using it for immigration and border enforcement, according to people familiar with the matter and documents reviewed by The Wall Street Journal. The location data is drawn from ordinary cellphone apps, including those for ...

  • Malware infection disrupts production at defence contractor plants in three countries

    September 27, 2019

    One of the biggest defence contractors in the world is having a very bad week after malware infected the company’s network and caused “significant disruption” at plants in three countries, the company said on Thursday. The infection took root on Tuesday, September 24, and affected Rheinmetall AG, a German corporation based in Düsseldorf, and one of ...

  • New Bedford Hit With $5.3m Ransomware Demand

    September 5, 2019

    A Massachusetts city has revealed that cyber-criminals tried to hold its data ransom to the tune of more than $5m over the summer, in a sign of the growing risk to organizations from online extortionists. The city of New Bedford was hit with the popular Ryuk strain of ransomware in early July, encrypting data on over 150 ...