DHS and DOJ must thoroughly investigate who breached HSIN, what the attackers accessed, and ensure all DHS partners are provided with timely information and the tools necessary to mitigate any associated risks from the breach. Furthermore, DHS must take a serious look within and account for how this happened and ensure a breach like this does not happen again.
Press DHS and DOJ to thoroughly investigate the breach of DHS's Homeland Security Information Network, determine who breached it and what was accessed, provide DHS partners timely information and mitigation tools, and ensure a similar breach does not happen again.
Occurrences
Evidence
The page says DHS publicly announced that HSIN had been hacked at least twice in 2009, once in March and once in April, citing Federal Computer Week reporting.
GAO described HSIN as DHS's web-based information-sharing application and said DHS was responsible for coordinating homeland security communications with governments, the private sector, and the public.
DHS I&A found that a technical error changed HSIN-Intel access to an all-users setting, exposing intelligence products to users not approved for HSIN-Intel access.
The DHS inquiry found 439 I&A products were improperly accessed 1,525 times, including access by private-sector users and non-U.S. citizens.
The mitigation memo recommended educating I&A staff on PII, SPII, and U.S. person information, while deferring to technical after-action findings on coding-error prevention.
WIRED reported, based on FOIA records, that DHS fixed the coding error and investigated potential harm, while noting gaps around affected outside agencies and oversight.
Assessments
The evidence supports only partial fulfillment. DHS later investigated an HSIN-related exposure, identified categories of improper access and affected materials, fixed the immediate coding issue, and adopted limited mitigation steps. But the record provided does not show Warner pressing DHS or DOJ, does not show DOJ involvement, does not establish timely partner notice or mitigation tools, and a similar HSIN-related exposure occurred years later. Because some promised investigative and remediation outcomes occurred without clear Warner attribution, this merits partial credit rather than full delivery.