UDHS A.I CyberSecurity Scoring
UDHS
Company Information
Website:https://www.dhs.gov
Employees number:37,484
Number of followers:988,518
NAICS:92
Industry Type:Government Administration
Homepage:dhs.gov
UDHS Risk Score (AI oriented)
Between 0 and 549
UDHSGovernment Administration
Updated:
01/07/2026
01/07/2026
508/1000
Critical
C
UDHS Global Score (TPRM)
xxxx
UDHSGovernment Administration
Score locked

UDHSCritical
Current Score
508C (CRITICAL)
01000
13 incidents
-36.86 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
508
JUNE 2026
508
MAY 2026
515
Cyber Attack
25 May 2026 • UDHS
U.S. Department of Homeland Security: DHS confirms hackers breached HSIN info-sharing platform
Cyberattack on Homeland Security Information Network (HSIN)
499
CRITICAL-16
US-1782931085
DHS Investigates Cyberattack on Sensitive Information-Sharing Network
The U.S. Department of Homeland Security (DHS) is probing a recent cyberattack targeting the Homeland Security Information Network (HSIN), a critical platform used by federal, state, local, and private-sector partners to share sensitive but unclassified information. The breach, first reported by Nextgov, occurred between late May and early June and was carried out by an unidentified threat actor.
According to sources familiar with the matter, the attackers compromised HSIN servers and a SharePoint system used for collaboration. While the extent of the damage remains unclear including whether any documents were stolen DHS’s Office of Intelligence and Analysis is conducting a forensic assessment. The agency has not attributed the attack to any specific group or foreign government.
HSIN serves as a vital tool for real-time communication, incident management, and threat intelligence sharing, including data on persons of interest and security planning. With the U.S. overseeing security for the 2024 World Cup, concerns have arisen that the breach could have exposed interagency coordination details, response procedures, or event security plans.
In a statement to BleepingComputer, DHS confirmed the incident, emphasizing that classified systems were unaffected. The agency isolated the affected systems, mitigated the vulnerability, and launched an investigation. The platform remains operational for partners, though further details are withheld due to the ongoing probe.
This is not the first security lapse for HSIN. In 2023, a contractor coding error led to an access misconfiguration in HSIN-Intel, exposing restricted data including U.S. person data and personally identifiable information to all users. The issue was later detailed in an internal DHS memo obtained by Wired.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
506
MARCH 2026
510
Cyber Attack
28 Feb 2026 • UDHS
HomeLand Justice and Handla Hack: Cyber Advisory: Increased Cyber Risk Amid U.S.–Israel–Iran Escalation
Heightened Threat Activity Following Middle East Escalation
494
CRITICAL-16
SCOUS-1772461744
Cybersecurity Alert: Heightened Threat Activity Following Middle East Escalation
On February 28, 2026, coordinated U.S. and Israeli military strikes in Iran resulted in the death of Supreme Leader Ayatollah Ali Khamenei, triggering immediate retaliatory missile attacks by Iran. The escalation has raised concerns about a surge in state-aligned and ideologically motivated cyber threats, particularly from Iran-linked actors.
### Threat Assessment
Security researchers, including Sophos X-Ops Counter Threat Unit (CTU), warn of an elevated risk of disruptive cyber operations in the near term (days to weeks). Likely targets include:
- Government agencies
- Critical infrastructure
- Financial services
- Defense-adjacent commercial entities
### Anticipated Attack Methods
Historically, Iran-backed groups have employed:
- Website defacements (e.g., propaganda-driven messaging)
- DDoS attacks (disrupting services)
- Ransomware & wiper malware (destructive payloads)
- Hack-and-leak operations (data theft extortion)
- Phishing & password spraying (credential-based attacks)
- Exploitation of internet-exposed systems (unpatched vulnerabilities)
Notable threat actors include:
- "HomeLand Justice" – Linked to wiper and hack-and-leak operations against Albanian government entities (2022–present).
- "Handla Hack" – A hacktivist persona tied to Iran’s Ministry of Intelligence and Security (MOIS), which claimed attacks in Jordan on February 28 and has threatened further regional targets.
### Historical Context & MITRE ATT&CK Techniques
Iran-aligned groups have previously conducted multi-stage attacks, combining:
- Initial access (phishing, exploiting public-facing apps, VPN breaches)
- Credential theft (password spraying, OS credential dumping)
- Lateral movement (process injection, account manipulation)
- Defense evasion (disabling security tools, obfuscating files)
- Impact (ransomware, wiper malware, defacement, data destruction)
### Defensive Recommendations
Organizations are advised to prioritize:
- Identity & access controls (MFA enforcement, least-privilege access)
- Exposure reduction (patching vulnerabilities, minimizing attack surfaces)
- Detection & response (EDR/XDR monitoring, phishing alert triage)
- Resilience & recovery (validating backups, incident response playbooks)
Cyber activity tied to geopolitical tensions may persist beyond immediate news cycles, requiring sustained vigilance. Security teams should monitor for MITRE ATT&CK techniques associated with Iran-linked operations, particularly around identity infrastructure, exposed services, and backup systems. Further updates will be provided as the situation evolves.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
FEBRUARY 2026
504
JANUARY 2026
555
Breach
07 Jan 2026 • UDHS
U.S. Department of Homeland Security, U.S. Customs and Border Protection and U.S. Immigration and Customs Enforcement: ICE Agent Doxxing Platform was Crippled After Coordinated DDoS Attack
Cyberattack Targets ICE List Wiki Ahead of Federal Agent Data Leak
498
CRITICAL-57
US-CUSU-S1768592906
Cyberattack Targets ICE List Wiki Ahead of Federal Agent Data Leak
A major cyberattack disrupted the ICE List Wiki a Netherlands-based activist platform just as it prepared to publish the identities of thousands of U.S. federal agents, primarily from Immigration and Customs Enforcement (ICE). The site, run by activist Dominick Skinner, was hit by a sustained distributed denial-of-service (DDoS) attack last Tuesday evening, flooding its servers with malicious traffic and forcing it offline.
The leaked data, provided by a Department of Homeland Security (DHS) whistleblower, includes names, personal phone numbers, and work histories of approximately 4,500 ICE and Border Patrol employees. The whistleblower’s decision to release the information was reportedly triggered by the fatal shooting of 37-year-old Renee Nicole Good by an ICE agent in Minneapolis on January 7, 2026. Activists quickly identified the officer involved as Jonathan E. Ross, with the incident described as the "last straw" for the whistleblower.
While the site has since resumed operations, Skinner noted that much of the attack traffic appeared to originate from a Russian bot farm, though the true source remains obscured by proxy networks. The sophistication of the assault suggests a coordinated effort to suppress the leak. Despite the disruption, Skinner’s team operating from the Netherlands to avoid U.S. jurisdiction plans to proceed with publishing the data, though they intend to exclude certain personnel, such as medical and childcare staff. The group is also migrating to more secure servers to prevent future disruptions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
570
Cyber Attack
05 Jan 2026 • UDHS
FBI, CISA, U.S. Department of Homeland Security and Defense Department's Cyber Crime Center: US Homeland Security warns of escalating Iranian cyberattack risks
DHS Warning of Escalating Cyberattack Risks by Iran-Backed Hacking Groups
555
CRITICAL-15
FBICISUS-UNI1767786135
DHS Warns of Escalating Cyber Threats from Iran-Backed Hackers Amid Rising Tensions
The U.S. Department of Homeland Security (DHS) issued a National Terrorism Advisory System (NTAS) bulletin on Sunday, warning of heightened cyberattack risks from Iran-backed hacking groups and pro-Iranian hacktivists following recent geopolitical escalations. The advisory highlights a "heightened threat environment" in the U.S., with low-level cyberattacks likely targeting vulnerable networks.
The DHS cautioned that violent extremists within the U.S. could mobilize in response to the Israel-Iran conflict, particularly if Iranian leadership issues a religious ruling calling for retaliatory violence. The bulletin also noted that anti-Semitic and anti-Israel sentiment has already motivated recent domestic attacks, raising concerns about further violence.
The warning follows a pattern of Iranian state-affiliated hackers and hacktivists exploiting poorly secured U.S. networks. In October, authorities in the U.S., Canada, and Australia reported that Iranian hackers were acting as initial access brokers, breaching organizations in healthcare, government, IT, engineering, and energy sectors through brute-force attacks, password spraying, and MFA fatigue (push bombing).
A separate August advisory from CISA, the FBI, and the Defense Department’s Cyber Crime Center (DC3) identified Br0k3r (also known as Pioneer Kitten, Fox Kitten, and other aliases) as a state-sponsored Iranian threat group involved in selling access to compromised networks to ransomware affiliates in exchange for a share of profits.
While the DHS did not explicitly link the NTAS bulletin to recent events, the warning comes after U.S. strikes on Iranian nuclear facilities—including Fordow, Natanz, and Isfahan—on Saturday, just over a week after Israel targeted Iranian nuclear and military sites on June 13. Iran’s Foreign Minister, Abbas Araghchi, responded by warning of "everlasting consequences" and asserting Iran’s right to defend its sovereignty.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JANUARY 2026
573
Vulnerability
31 Dec 2025 • UDHS
U.S. federal agencies: CISA Orders Federal Agencies to Patch Critical MongoDB Vulnerability Called MongoBleed
MongoBleed Vulnerability Exploitation
570
CRITICAL-3
US-1767173563
CISA Issues Emergency Directive for MongoBleed Vulnerability in MongoDB
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch a critical vulnerability in MongoDB, dubbed MongoBleed, following active exploitation by cyber attackers. The flaw enables threat actors to extract credentials, API keys, and other sensitive data from vulnerable databases, posing severe risks to data integrity and confidentiality.
MongoBleed exploits default or misconfigured security settings, allowing unauthorized access, data theft, manipulation, or deletion. Attackers may also intercept network traffic in poorly secured environments. The vulnerability underscores persistent risks in database systems with inadequate hardening.
CISA’s directive requires immediate patch deployment to mitigate potential breaches, which could lead to operational disruptions, reputational damage, and legal consequences. Agencies must also enforce stronger password policies, implement continuous monitoring, and conduct security audits to address misconfigurations. Additional measures include personnel training and advanced threat detection to bolster defenses.
The alert highlights the urgency of maintaining up-to-date cybersecurity protocols to protect national data infrastructure from evolving threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
569
NOVEMBER 2025
567
OCTOBER 2025
562
SEPTEMBER 2025
565
Cyber Attack
01 Sep 2025 • UDHS
U.S. federal agency: CISA: US agency breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March
U.S. Government Agency Breached via Cisco Firewall Vulnerabilities, Persistent Malware Detected
550
CRITICAL-15
US-1776976007
U.S. Government Agency Breached via Cisco Firewall Vulnerabilities, Persistent Malware Detected
In September 2025, a U.S. federal agency was compromised by sophisticated hackers exploiting vulnerabilities in Cisco Adaptive Security Appliances (ASA). The Cybersecurity and Infrastructure Security Agency (CISA) revealed that attackers deployed FIRESTARTER, a malware strain allowing persistent access to compromised Cisco Firepower devices without re-exploiting the original flaws.
The breach was discovered through CISA’s continuous monitoring, which detected suspicious connections on an agency’s Cisco Firepower device running ASA software. Forensic analysis uncovered FIRESTARTER, installed before September 25, 2025, enabling hackers to regain access in March 2026. Additionally, attackers used Line Viper, a secondary malware, to establish unauthorized VPN sessions, bypass authentication, and extract administrative credentials, certificates, and private keys.
The vulnerabilities CVE-2025-30333 and CVE-2025-20362 were first flagged by CISA in September 2025, with federal agencies ordered to patch them. However, CISA later confirmed that patched systems remained vulnerable due to FIRESTARTER’s persistence mechanism. The agency also noted that attackers exploited dormant federal accounts to maintain access.
While CISA has not attributed the attack, reports suggest alignment with China-linked state interests, consistent with previous campaigns like ArcaneDoor (2024). Cisco’s analysis supports this assessment, linking the activity to the same threat actors.
In response, CISA issued updated directives requiring federal agencies to:
- Conduct malware checks by May 1, 2026, with initial confirmations due by midnight on Friday.
- Submit an inventory of all Cisco Firepower devices by May 1.
- Follow CISA’s guidance for physical disconnection of infected devices if necessary.
CISA emphasized that standard patching is insufficient to remove FIRESTARTER, warning agencies to avoid unplugging devices without explicit instructions. The agency will compile a report on the campaign for the National Cyber Director and White House by August 1, 2026.
The incident underscores the risks of persistent malware in critical security infrastructure, particularly in widely used Cisco ASA and Firepower Threat Defense (FTD) systems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
565
JULY 2025
694
Ransomware
24 Jul 2025 • UDHS
Government entities: BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement
BlackSuit Ransomware Infrastructure Disrupted in Coordinated Global Takedown
558
CRITICAL-136
US-1771976815
BlackSuit Ransomware Infrastructure Disrupted in Coordinated Global Takedown
On July 24, 2026, a multinational law enforcement operation led by the U.S. Department of Homeland Security’s Homeland Security Investigations (HSI) dismantled key infrastructure tied to the BlackSuit (Royal) ransomware group, a persistent threat targeting critical U.S. sectors since 2022. The effort, which included the FBI, U.S. Secret Service, IRS Criminal Investigation (IRS-CI), and international partners from the UK, Germany, Ireland, France, Canada, Ukraine, and Lithuania, resulted in the seizure of four servers, nine domains, and over $1 million in cryptocurrency.
BlackSuit, known for its high-impact attacks, has compromised more than 450 U.S. victims, including schools, hospitals, energy providers, and government entities. The group’s operations have drawn scrutiny for their direct threat to public safety and critical infrastructure.
While officials hailed the takedown as a significant step in disrupting ransomware operations, cybersecurity experts cautioned that the impact may be temporary. Craig Jones, Chief Security Officer at Ontinue, noted that without arrests, the group’s operators retain the skills, funding, and infrastructure to reemerge under a new identity a pattern observed with other ransomware crews.
The operation reflects a proactive, disruption-first approach by U.S. agencies, with officials emphasizing that accountability for cybercriminals remains a priority. Deputy Assistant Director Michael Prado of HSI’s Cyber Crimes Center (C3) underscored the need to dismantle the entire ecosystem enabling ransomware, while U.S. Attorney Erik S. Siebert reaffirmed law enforcement’s commitment to aggressive action against such threats.
Though the takedown neutralized only a portion of BlackSuit’s infrastructure, it marks a broader effort to curb ransomware’s global reach. Authorities continue to pursue further measures to hold operators accountable and prevent future resurgences.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2025
709
Cyber Attack
11 Jul 2025 • UDHS
Nozomi Networks, CyberAv3ngers and Homeland Justice: Nozomi finds 133% surge in Iranian cyberattacks targeting US, as transportation and manufacturing most affected
Iranian Cyberattacks Surge 133% Amid Geopolitical Tensions, Targeting U.S. Critical Infrastructure
693
CRITICAL-16
US-NOZTRE1774333876
Iranian Cyberattacks Surge 133% Amid Geopolitical Tensions, Targeting U.S. Critical Infrastructure
Nozomi Networks Labs reported a sharp escalation in cyberattacks linked to Iranian threat groups, with a 133% increase in incidents during May and June 2024 compared to the previous two months. The surge peaking at 18 attacks in May before declining to 10 in June coincided with heightened regional conflicts involving Iran, with U.S. organizations as the primary targets.
At least 28 confirmed attacks were attributed to six Iranian state-sponsored or affiliated groups: MuddyWater, APT33, OilRig, CyberAv3ngers, FoxKitten, and Homeland Justice. The transportation and manufacturing sectors bore the brunt of the activity, though critical infrastructure, energy, and government entities were also heavily targeted.
### Key Threat Actors & Their Campaigns
- MuddyWater emerged as the most active, compromising at least five U.S. companies in transportation and manufacturing. The group, operational since 2017, has historically focused on the Middle East but expanded its reach to North America, Europe, Asia, and the Middle East, targeting government, telecommunications, and energy sectors.
- APT33 conducted attacks against three U.S. firms, with infrastructure traced to operations spanning North America, Europe, the Middle East, and Asia, including Germany, France, Saudi Arabia, and Japan. The group’s focus on strategic geopolitical and economic hubs suggests intelligence-gathering and disruption objectives.
- OilRig maintained its long-standing campaign against Gulf region targets, including energy, government, and telecommunications sectors, but also extended operations to the U.S., Spain, and Turkey. Attack paths originating from Iran indicate a broader geopolitical and intelligence-driven agenda.
- CyberAv3ngers, known for targeting operational technology (OT), reused an IP address from a prior attack and deployed the OrpaCrab (IOCONTROL) malware, first identified in December 2023. The group’s recent activity targeted the U.S., Ukraine, Iraq, and Cyprus, with a focus on critical infrastructure and industrial sectors.
- FoxKitten concentrated on Israel, Greece, and North Macedonia, aligning with its history of espionage and long-term access within government and critical infrastructure networks in the Eastern Mediterranean and Middle East.
- Homeland Justice, a hacktivist collective, demonstrated a global reach, striking targets in the U.S., Canada, Saudi Arabia, India, and Australia. The group’s politically motivated attacks spanned critical infrastructure and government entities, reflecting a broad disruption strategy.
### Geopolitical Context & U.S. Response
The surge in Iranian cyberactivity follows escalating regional tensions, prompting U.S. security agencies to issue warnings last week. Critical infrastructure operators were advised to monitor for threats and isolate OT/ICS assets from public internet access, particularly those with ties to Israeli defense or research entities. The agencies emphasized the heightened risk to the defense industrial base (DIB) and other high-value sectors in the near term.
Nozomi Networks confirmed that its threat intelligence feeds including a Mandiant TI Expansion Pack already contain signatures to detect these groups, though the broader threat landscape underscores the expanding scope and sophistication of Iranian cyber operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
DECEMBER 2024
697
Vulnerability
01 Dec 2024 • UDHS
Department of Homeland Security
Commercial Drone Threats to National Security
694
CRITICAL-3
US-001010525
The DHS encountered growing threats from commercial drones being modified to carry hazardous payloads, impacting national security. Attempted mitigations include improved detection and response capabilities through local law enforcement training and technology deployment. These clandestine drone activities pose a significant risk, requiring urgent action and cooperation between federal and local agencies to ensure public safety and preserve critical infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MAY 2023
728
Breach
01 May 2023 • UDHS
U.S. Department of Homeland Security (DHS)
DHS Data Hub Misconfiguration Exposes Sensitive Intelligence to Unauthorized Users
650
CRITICAL-78
US-4641646100525
In March–May 2023, a misconfigured DHS Homeland Security Information Network (HSIN-Intel) platform exposed sensitive but unclassified intelligence data—including investigative leads shared with the FBI, National Counterterrorism Center, and local law enforcement—to tens of thousands of unauthorized users. The access controls were incorrectly set to 'everyone,' granting visibility to non-intelligence government workers (e.g., disaster response teams), private contractors, and foreign government personnel. The breach stemmed from poor access management and lack of segmentation, highlighting systemic failures in cloud security governance. While no classified data was compromised, the exposure risked operational security, counterterrorism efforts, and trust in interagency intelligence-sharing. The incident underscored how human error and process gaps—rather than sophisticated cyberattacks—remain a dominant cause of high-impact breaches in critical infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2020
746
Ransomware
16 Jun 2020 • UDHS
US Federal Agencies
Russian Basketball Player Arrested for Ransomware Negotiation
656
CRITICAL-90
US-341071125
Daniil Kasatkin, a 26-year-old Russian professional basketball player, was arrested at Charles de Gaulle Airport in Paris on June 21, 2023, for his alleged involvement in a ransomware gang that operated between 2020 and 2022. The gang is accused of targeting around 900 organizations, including two US federal agencies. Kasatkin is facing charges of 'conspiracy to commit computer fraud' and 'computer fraud conspiracy.' His lawyers deny the allegations, claiming he is not tech-savvy and was unaware of any unlawful activities. The US has not yet released any statements or evidence regarding the crimes.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JANUARY 2018
766
Breach
01 Jan 2018 • UDHS
U.S. Department of Homeland Security
DHS Data Breach Incident
702
HIGH-64
USD331181223
DHS had a privacy incident that resulted in the exposure of information for 247,167 active and retired federal employees.
The database utilised by the DHS Office of the Inspector General (OIG) and kept in the Department of Homeland Security OIG Case Management System was compromised by a data breach.
Employee names, Social Security numbers, dates of birth, jobs, grades, and duty locations are among the data that has been made public.
In addition to putting additional security measures in place to restrict access to this kind of information, the Department of Homeland Security notified those who were impacted through notification letters.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2016
810
Data Leak
01 Feb 2016 • UDHS
U.S. Department of Homeland Security
Department of Justice Email Account Compromise
744
CRITICAL-66
USD181261023
A Department of Justice employee's email account was compromised by a hacker, who took 200GB of data, including records of 20,000 FBI workers and 9,000 DHS employees.
Delving deeper into the archive, one finds information about DHS security experts, programme analysts, IT, infosec, and security, as well as 100 individuals who hold the title of intelligence.
Motherboard claims that a hacker gained access to a Department of Justice employee's email account. As evidence, the hacker used the hacked account to send the email directly to Motherboard contributor Joseph Cox.
The apparent job titles, names, phone numbers, and email addresses of over 9,000 purported Department of Homeland Security (DHS) workers and over 20,000 purported FBI employees.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for UDHS ??
What was UDHS's A.I Rankiteo Cyber Score in June 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in May 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in April 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in March 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in February 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in January 2026 ??
What was UDHS's A.I Rankiteo Cyber Score in December 2025 ??
What was UDHS's A.I Rankiteo Cyber Score in November 2025 ??
What was UDHS's A.I Rankiteo Cyber Score in October 2025 ??
What was UDHS's A.I Rankiteo Cyber Score in September 2025 ??
What was UDHS's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on UDHS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with UDHS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view UDHS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?