Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
U.S. Department of Homeland Security

U.S. Department of Homeland Security Vendor Cyber Rating & Cyber Score

dhs.gov

The Department of Homeland Security (DHS) has a vital mission: to secure the nation from the many threats we face. This requires the hard work of more than 260,000 employees in jobs that range from aviation and border security to emergency response, from cybersecurity analyst to chemical facility inspector. Our duties are wide-ranging, and our goal is clear - keeping America safe. Mission 1: Counter Terrorism and Homeland Security Threats Mission 2: Secure U.S. Borders and Approaches Mission 3: Secure Cyberspace and Critical Infrastructure Mission 4: Preserve and Uphold the Nation's Prosperity and Economic Security Mission 5: Strengthen Preparedness and Resilience Mission 6: Champion the DHS Workforce and Strengthen the Department We


UDHS A.I CyberSecurity Scoring

UDHS
Company Information
Website:https://www.dhs.gov
Employees number:37,484
Number of followers:988,518
NAICS:92
Industry Type:Government Administration
Homepage:dhs.gov
UDHS Risk Score (AI oriented)
Between 0 and 549
logo
UDHSGovernment Administration
Updated:
01/07/2026
508/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
UDHS Global Score (TPRM)
xxxx
logo
UDHSGovernment Administration
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

UDHS
UDHSCritical
Current Score
508C (CRITICAL)
01000
13 incidents
-36.86 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
508Before Incident
JUNE 2026
508Before Incident
MAY 2026
515Before Incident
Cyber Attack
25 May 2026UDHS
U.S. Department of Homeland Security: DHS confirms hackers breached HSIN info-sharing platform

Cyberattack on Homeland Security Information Network (HSIN)

499After Incident
CRITICAL-16
US-1782931085
DHS Investigates Cyberattack on Sensitive Information-Sharing Network The U.S. Department of Homeland Security (DHS) is probing a recent cyberattack targeting the Homeland Security Information Network (HSIN), a critical platform used by federal, state, local, and private-sector partners to share sensitive but unclassified information. The breach, first reported by Nextgov, occurred between late May and early June and was carried out by an unidentified threat actor. According to sources familiar with the matter, the attackers compromised HSIN servers and a SharePoint system used for collaboration. While the extent of the damage remains unclear including whether any documents were stolen DHS’s Office of Intelligence and Analysis is conducting a forensic assessment. The agency has not attributed the attack to any specific group or foreign government. HSIN serves as a vital tool for real-time communication, incident management, and threat intelligence sharing, including data on persons of interest and security planning. With the U.S. overseeing security for the 2024 World Cup, concerns have arisen that the breach could have exposed interagency coordination details, response procedures, or event security plans. In a statement to BleepingComputer, DHS confirmed the incident, emphasizing that classified systems were unaffected. The agency isolated the affected systems, mitigated the vulnerability, and launched an investigation. The platform remains operational for partners, though further details are withheld due to the ongoing probe. This is not the first security lapse for HSIN. In 2023, a contractor coding error led to an access misconfiguration in HSIN-Intel, exposing restricted data including U.S. person data and personally identifiable information to all users. The issue was later detailed in an internal DHS memo obtained by Wired.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Data Compromised: Sensitive but unclassified information, potentially including interagency coordination details, response procedures, or event security plansSystems Affected: HSIN servers, SharePoint systemOperational Impact: Platform remains operational for partners, but investigation is ongoingIdentity Theft Risk: Potential exposure of personally identifiable information
DATA BREACH
Type Of Data Compromised: Sensitive but unclassified information, potentially including U.S. person data and personally identifiable informationSensitivity Of Data: HighPersonally Identifiable Information: Potentially exposed
APRIL 2026
506Before Incident
MARCH 2026
510Before Incident
Cyber Attack
28 Feb 2026UDHS
HomeLand Justice and Handla Hack: Cyber Advisory: Increased Cyber Risk Amid U.S.–Israel–Iran Escalation

Heightened Threat Activity Following Middle East Escalation

494After Incident
CRITICAL-16
SCOUS-1772461744
Cybersecurity Alert: Heightened Threat Activity Following Middle East Escalation On February 28, 2026, coordinated U.S. and Israeli military strikes in Iran resulted in the death of Supreme Leader Ayatollah Ali Khamenei, triggering immediate retaliatory missile attacks by Iran. The escalation has raised concerns about a surge in state-aligned and ideologically motivated cyber threats, particularly from Iran-linked actors. ### Threat Assessment Security researchers, including Sophos X-Ops Counter Threat Unit (CTU), warn of an elevated risk of disruptive cyber operations in the near term (days to weeks). Likely targets include: - Government agencies - Critical infrastructure - Financial services - Defense-adjacent commercial entities ### Anticipated Attack Methods Historically, Iran-backed groups have employed: - Website defacements (e.g., propaganda-driven messaging) - DDoS attacks (disrupting services) - Ransomware & wiper malware (destructive payloads) - Hack-and-leak operations (data theft extortion) - Phishing & password spraying (credential-based attacks) - Exploitation of internet-exposed systems (unpatched vulnerabilities) Notable threat actors include: - "HomeLand Justice" – Linked to wiper and hack-and-leak operations against Albanian government entities (2022–present). - "Handla Hack" – A hacktivist persona tied to Iran’s Ministry of Intelligence and Security (MOIS), which claimed attacks in Jordan on February 28 and has threatened further regional targets. ### Historical Context & MITRE ATT&CK Techniques Iran-aligned groups have previously conducted multi-stage attacks, combining: - Initial access (phishing, exploiting public-facing apps, VPN breaches) - Credential theft (password spraying, OS credential dumping) - Lateral movement (process injection, account manipulation) - Defense evasion (disabling security tools, obfuscating files) - Impact (ransomware, wiper malware, defacement, data destruction) ### Defensive Recommendations Organizations are advised to prioritize: - Identity & access controls (MFA enforcement, least-privilege access) - Exposure reduction (patching vulnerabilities, minimizing attack surfaces) - Detection & response (EDR/XDR monitoring, phishing alert triage) - Resilience & recovery (validating backups, incident response playbooks) Cyber activity tied to geopolitical tensions may persist beyond immediate news cycles, requiring sustained vigilance. Security teams should monitor for MITRE ATT&CK techniques associated with Iran-linked operations, particularly around identity infrastructure, exposed services, and backup systems. Further updates will be provided as the situation evolves.
INCIDENT DETAILS -
TYPE
Cyber Threat AlertGeopolitical Cyber Escalation
MOTIVATION
RetaliationDisruptionPropagandaData theft extortion
IMPACT
Operational Impact: Disruptive cyber operations
FEBRUARY 2026
504Before Incident
JANUARY 2026
555Before Incident
Breach
07 Jan 2026UDHS
U.S. Department of Homeland Security, U.S. Customs and Border Protection and U.S. Immigration and Customs Enforcement: ICE Agent Doxxing Platform was Crippled After Coordinated DDoS Attack

Cyberattack Targets ICE List Wiki Ahead of Federal Agent Data Leak

498After Incident
CRITICAL-57
US-CUSU-S1768592906
Cyberattack Targets ICE List Wiki Ahead of Federal Agent Data Leak A major cyberattack disrupted the ICE List Wiki a Netherlands-based activist platform just as it prepared to publish the identities of thousands of U.S. federal agents, primarily from Immigration and Customs Enforcement (ICE). The site, run by activist Dominick Skinner, was hit by a sustained distributed denial-of-service (DDoS) attack last Tuesday evening, flooding its servers with malicious traffic and forcing it offline. The leaked data, provided by a Department of Homeland Security (DHS) whistleblower, includes names, personal phone numbers, and work histories of approximately 4,500 ICE and Border Patrol employees. The whistleblower’s decision to release the information was reportedly triggered by the fatal shooting of 37-year-old Renee Nicole Good by an ICE agent in Minneapolis on January 7, 2026. Activists quickly identified the officer involved as Jonathan E. Ross, with the incident described as the "last straw" for the whistleblower. While the site has since resumed operations, Skinner noted that much of the attack traffic appeared to originate from a Russian bot farm, though the true source remains obscured by proxy networks. The sophistication of the assault suggests a coordinated effort to suppress the leak. Despite the disruption, Skinner’s team operating from the Netherlands to avoid U.S. jurisdiction plans to proceed with publishing the data, though they intend to exclude certain personnel, such as medical and childcare staff. The group is also migrating to more secure servers to prevent future disruptions.
INCIDENT DETAILS -
TYPE
DDoS
MOTIVATION
Suppression of leaked data
IMPACT
Data Compromised: Names, personal phone numbers, and work histories of ~4,500 ICE and Border Patrol employeesSystems Affected: ICE List Wiki serversDowntime: Temporary (site resumed operations)Operational Impact: Disruption of planned data leak publicationIdentity Theft Risk: High (personal information of federal agents exposed)
DATA BREACH
Type Of Data Compromised: Personal and professional information of federal agentsNumber Of Records Exposed: 4,500Sensitivity Of Data: High (personally identifiable information, work histories)Personally Identifiable Information: Names, personal phone numbers
JANUARY 2026
570Before Incident
Cyber Attack
05 Jan 2026UDHS
FBI, CISA, U.S. Department of Homeland Security and Defense Department's Cyber Crime Center: US Homeland Security warns of escalating Iranian cyberattack risks

DHS Warning of Escalating Cyberattack Risks by Iran-Backed Hacking Groups

555After Incident
CRITICAL-15
FBICISUS-UNI1767786135
DHS Warns of Escalating Cyber Threats from Iran-Backed Hackers Amid Rising Tensions The U.S. Department of Homeland Security (DHS) issued a National Terrorism Advisory System (NTAS) bulletin on Sunday, warning of heightened cyberattack risks from Iran-backed hacking groups and pro-Iranian hacktivists following recent geopolitical escalations. The advisory highlights a "heightened threat environment" in the U.S., with low-level cyberattacks likely targeting vulnerable networks. The DHS cautioned that violent extremists within the U.S. could mobilize in response to the Israel-Iran conflict, particularly if Iranian leadership issues a religious ruling calling for retaliatory violence. The bulletin also noted that anti-Semitic and anti-Israel sentiment has already motivated recent domestic attacks, raising concerns about further violence. The warning follows a pattern of Iranian state-affiliated hackers and hacktivists exploiting poorly secured U.S. networks. In October, authorities in the U.S., Canada, and Australia reported that Iranian hackers were acting as initial access brokers, breaching organizations in healthcare, government, IT, engineering, and energy sectors through brute-force attacks, password spraying, and MFA fatigue (push bombing). A separate August advisory from CISA, the FBI, and the Defense Department’s Cyber Crime Center (DC3) identified Br0k3r (also known as Pioneer Kitten, Fox Kitten, and other aliases) as a state-sponsored Iranian threat group involved in selling access to compromised networks to ransomware affiliates in exchange for a share of profits. While the DHS did not explicitly link the NTAS bulletin to recent events, the warning comes after U.S. strikes on Iranian nuclear facilities—including Fordow, Natanz, and Isfahan—on Saturday, just over a week after Israel targeted Iranian nuclear and military sites on June 13. Iran’s Foreign Minister, Abbas Araghchi, responded by warning of "everlasting consequences" and asserting Iran’s right to defend its sovereignty.
INCIDENT DETAILS -
TYPE
Cyberattack, Initial Access Brokerage, Ransomware
MOTIVATION
Retaliation for U.S. attacks on Iranian nuclear facilitiesFinancial gain (ransomware payments)Political/ideological (anti-Semitic or anti-Israel sentiment)
JANUARY 2026
573Before Incident
Vulnerability
31 Dec 2025UDHS
U.S. federal agencies: CISA Orders Federal Agencies to Patch Critical MongoDB Vulnerability Called MongoBleed

MongoBleed Vulnerability Exploitation

570After Incident
CRITICAL-3
US-1767173563
CISA Issues Emergency Directive for MongoBleed Vulnerability in MongoDB The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch a critical vulnerability in MongoDB, dubbed MongoBleed, following active exploitation by cyber attackers. The flaw enables threat actors to extract credentials, API keys, and other sensitive data from vulnerable databases, posing severe risks to data integrity and confidentiality. MongoBleed exploits default or misconfigured security settings, allowing unauthorized access, data theft, manipulation, or deletion. Attackers may also intercept network traffic in poorly secured environments. The vulnerability underscores persistent risks in database systems with inadequate hardening. CISA’s directive requires immediate patch deployment to mitigate potential breaches, which could lead to operational disruptions, reputational damage, and legal consequences. Agencies must also enforce stronger password policies, implement continuous monitoring, and conduct security audits to address misconfigurations. Additional measures include personnel training and advanced threat detection to bolster defenses. The alert highlights the urgency of maintaining up-to-date cybersecurity protocols to protect national data infrastructure from evolving threats.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data theft, credential harvesting, potential data manipulation/deletion
IMPACT
Data Compromised: Credentials, API keys, sensitive dataSystems Affected: MongoDB databasesOperational Impact: Potential operational disruptions due to data manipulation or deletionBrand Reputation Impact: Potential reputational harm due to data breachesLegal Liabilities: Possible legal and regulatory consequencesIdentity Theft Risk: High (due to exposure of sensitive data)
DATA BREACH
CredentialsAPI keysSensitive dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Potentially
DECEMBER 2025
569Before Incident
NOVEMBER 2025
567Before Incident
OCTOBER 2025
562Before Incident
SEPTEMBER 2025
565Before Incident
Cyber Attack
01 Sep 2025UDHS
U.S. federal agency: CISA: US agency breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March

U.S. Government Agency Breached via Cisco Firewall Vulnerabilities, Persistent Malware Detected

550After Incident
CRITICAL-15
US-1776976007
U.S. Government Agency Breached via Cisco Firewall Vulnerabilities, Persistent Malware Detected In September 2025, a U.S. federal agency was compromised by sophisticated hackers exploiting vulnerabilities in Cisco Adaptive Security Appliances (ASA). The Cybersecurity and Infrastructure Security Agency (CISA) revealed that attackers deployed FIRESTARTER, a malware strain allowing persistent access to compromised Cisco Firepower devices without re-exploiting the original flaws. The breach was discovered through CISA’s continuous monitoring, which detected suspicious connections on an agency’s Cisco Firepower device running ASA software. Forensic analysis uncovered FIRESTARTER, installed before September 25, 2025, enabling hackers to regain access in March 2026. Additionally, attackers used Line Viper, a secondary malware, to establish unauthorized VPN sessions, bypass authentication, and extract administrative credentials, certificates, and private keys. The vulnerabilities CVE-2025-30333 and CVE-2025-20362 were first flagged by CISA in September 2025, with federal agencies ordered to patch them. However, CISA later confirmed that patched systems remained vulnerable due to FIRESTARTER’s persistence mechanism. The agency also noted that attackers exploited dormant federal accounts to maintain access. While CISA has not attributed the attack, reports suggest alignment with China-linked state interests, consistent with previous campaigns like ArcaneDoor (2024). Cisco’s analysis supports this assessment, linking the activity to the same threat actors. In response, CISA issued updated directives requiring federal agencies to: - Conduct malware checks by May 1, 2026, with initial confirmations due by midnight on Friday. - Submit an inventory of all Cisco Firepower devices by May 1. - Follow CISA’s guidance for physical disconnection of infected devices if necessary. CISA emphasized that standard patching is insufficient to remove FIRESTARTER, warning agencies to avoid unplugging devices without explicit instructions. The agency will compile a report on the campaign for the National Cyber Director and White House by August 1, 2026. The incident underscores the risks of persistent malware in critical security infrastructure, particularly in widely used Cisco ASA and Firepower Threat Defense (FTD) systems.
INCIDENT DETAILS -
TYPE
Data Breach, Persistent Malware, Unauthorized Access
MOTIVATION
Cyber espionage, Persistent access
IMPACT
Data Compromised: Administrative credentials, certificates, private keysSystems Affected: Cisco Firepower devices running ASA softwareOperational Impact: Unauthorized VPN sessions, bypassed authentication, persistent accessBrand Reputation Impact: High (U.S. federal agency)Identity Theft Risk: High (credentials and PII exposure)
DATA BREACH
Administrative credentialsCertificatesPrivate keysSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Likely (credentials)
AUGUST 2025
565Before Incident
JULY 2025
694Before Incident
Ransomware
24 Jul 2025UDHS
Government entities: BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement

BlackSuit Ransomware Infrastructure Disrupted in Coordinated Global Takedown

558After Incident
CRITICAL-136
US-1771976815
BlackSuit Ransomware Infrastructure Disrupted in Coordinated Global Takedown On July 24, 2026, a multinational law enforcement operation led by the U.S. Department of Homeland Security’s Homeland Security Investigations (HSI) dismantled key infrastructure tied to the BlackSuit (Royal) ransomware group, a persistent threat targeting critical U.S. sectors since 2022. The effort, which included the FBI, U.S. Secret Service, IRS Criminal Investigation (IRS-CI), and international partners from the UK, Germany, Ireland, France, Canada, Ukraine, and Lithuania, resulted in the seizure of four servers, nine domains, and over $1 million in cryptocurrency. BlackSuit, known for its high-impact attacks, has compromised more than 450 U.S. victims, including schools, hospitals, energy providers, and government entities. The group’s operations have drawn scrutiny for their direct threat to public safety and critical infrastructure. While officials hailed the takedown as a significant step in disrupting ransomware operations, cybersecurity experts cautioned that the impact may be temporary. Craig Jones, Chief Security Officer at Ontinue, noted that without arrests, the group’s operators retain the skills, funding, and infrastructure to reemerge under a new identity a pattern observed with other ransomware crews. The operation reflects a proactive, disruption-first approach by U.S. agencies, with officials emphasizing that accountability for cybercriminals remains a priority. Deputy Assistant Director Michael Prado of HSI’s Cyber Crimes Center (C3) underscored the need to dismantle the entire ecosystem enabling ransomware, while U.S. Attorney Erik S. Siebert reaffirmed law enforcement’s commitment to aggressive action against such threats. Though the takedown neutralized only a portion of BlackSuit’s infrastructure, it marks a broader effort to curb ransomware’s global reach. Authorities continue to pursue further measures to hold operators accountable and prevent future resurgences.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $1 million in cryptocurrency seizedOperational Impact: Disruption to critical U.S. sectors including schools, hospitals, energy providers, and government entities
DATA BREACH
Data Encryption: Yes
JULY 2025
709Before Incident
Cyber Attack
11 Jul 2025UDHS
Nozomi Networks, CyberAv3ngers and Homeland Justice: Nozomi finds 133% surge in Iranian cyberattacks targeting US, as transportation and manufacturing most affected

Iranian Cyberattacks Surge 133% Amid Geopolitical Tensions, Targeting U.S. Critical Infrastructure

693After Incident
CRITICAL-16
US-NOZTRE1774333876
Iranian Cyberattacks Surge 133% Amid Geopolitical Tensions, Targeting U.S. Critical Infrastructure Nozomi Networks Labs reported a sharp escalation in cyberattacks linked to Iranian threat groups, with a 133% increase in incidents during May and June 2024 compared to the previous two months. The surge peaking at 18 attacks in May before declining to 10 in June coincided with heightened regional conflicts involving Iran, with U.S. organizations as the primary targets. At least 28 confirmed attacks were attributed to six Iranian state-sponsored or affiliated groups: MuddyWater, APT33, OilRig, CyberAv3ngers, FoxKitten, and Homeland Justice. The transportation and manufacturing sectors bore the brunt of the activity, though critical infrastructure, energy, and government entities were also heavily targeted. ### Key Threat Actors & Their Campaigns - MuddyWater emerged as the most active, compromising at least five U.S. companies in transportation and manufacturing. The group, operational since 2017, has historically focused on the Middle East but expanded its reach to North America, Europe, Asia, and the Middle East, targeting government, telecommunications, and energy sectors. - APT33 conducted attacks against three U.S. firms, with infrastructure traced to operations spanning North America, Europe, the Middle East, and Asia, including Germany, France, Saudi Arabia, and Japan. The group’s focus on strategic geopolitical and economic hubs suggests intelligence-gathering and disruption objectives. - OilRig maintained its long-standing campaign against Gulf region targets, including energy, government, and telecommunications sectors, but also extended operations to the U.S., Spain, and Turkey. Attack paths originating from Iran indicate a broader geopolitical and intelligence-driven agenda. - CyberAv3ngers, known for targeting operational technology (OT), reused an IP address from a prior attack and deployed the OrpaCrab (IOCONTROL) malware, first identified in December 2023. The group’s recent activity targeted the U.S., Ukraine, Iraq, and Cyprus, with a focus on critical infrastructure and industrial sectors. - FoxKitten concentrated on Israel, Greece, and North Macedonia, aligning with its history of espionage and long-term access within government and critical infrastructure networks in the Eastern Mediterranean and Middle East. - Homeland Justice, a hacktivist collective, demonstrated a global reach, striking targets in the U.S., Canada, Saudi Arabia, India, and Australia. The group’s politically motivated attacks spanned critical infrastructure and government entities, reflecting a broad disruption strategy. ### Geopolitical Context & U.S. Response The surge in Iranian cyberactivity follows escalating regional tensions, prompting U.S. security agencies to issue warnings last week. Critical infrastructure operators were advised to monitor for threats and isolate OT/ICS assets from public internet access, particularly those with ties to Israeli defense or research entities. The agencies emphasized the heightened risk to the defense industrial base (DIB) and other high-value sectors in the near term. Nozomi Networks confirmed that its threat intelligence feeds including a Mandiant TI Expansion Pack already contain signatures to detect these groups, though the broader threat landscape underscores the expanding scope and sophistication of Iranian cyber operations.
INCIDENT DETAILS -
TYPE
Cyber EspionageDisruptionHacktivism
MOTIVATION
Geopolitical TensionsIntelligence GatheringDisruptionEspionage
IMPACT
TransportationManufacturingCritical InfrastructureEnergyGovernmentTelecommunicationsOperational Impact: Disruption of critical infrastructure and industrial sectors
DECEMBER 2024
697Before Incident
Vulnerability
01 Dec 2024UDHS
Department of Homeland Security

Commercial Drone Threats to National Security

694After Incident
CRITICAL-3
US-001010525
The DHS encountered growing threats from commercial drones being modified to carry hazardous payloads, impacting national security. Attempted mitigations include improved detection and response capabilities through local law enforcement training and technology deployment. These clandestine drone activities pose a significant risk, requiring urgent action and cooperation between federal and local agencies to ensure public safety and preserve critical infrastructure.
INCIDENT DETAILS -
TYPE
Physical Security Threat
MOTIVATION
Impact national security and critical infrastructure
IMPACT
Operational Impact: High
MAY 2023
728Before Incident
Breach
01 May 2023UDHS
U.S. Department of Homeland Security (DHS)

DHS Data Hub Misconfiguration Exposes Sensitive Intelligence to Unauthorized Users

650After Incident
CRITICAL-78
US-4641646100525
In March–May 2023, a misconfigured DHS Homeland Security Information Network (HSIN-Intel) platform exposed sensitive but unclassified intelligence data—including investigative leads shared with the FBI, National Counterterrorism Center, and local law enforcement—to tens of thousands of unauthorized users. The access controls were incorrectly set to 'everyone,' granting visibility to non-intelligence government workers (e.g., disaster response teams), private contractors, and foreign government personnel. The breach stemmed from poor access management and lack of segmentation, highlighting systemic failures in cloud security governance. While no classified data was compromised, the exposure risked operational security, counterterrorism efforts, and trust in interagency intelligence-sharing. The incident underscored how human error and process gaps—rather than sophisticated cyberattacks—remain a dominant cause of high-impact breaches in critical infrastructure.
INCIDENT DETAILS -
TYPE
Data ExposureUnauthorized AccessMisconfiguration
IMPACT
Sensitive Intelligence (DHS)184M User Records (2025 Breach)Plain-Text Credentials (Apple, Google, Meta, etc.)Bank AccountsHealth PlatformsGovernment PortalsHSIN-Intel Platform (DHS)Unsecured Database (2025 Breach)Unauthorized Access to Restricted IntelligenceIncreased Risk of Identity Theft/Phishing (2025 Breach)Credential Stuffing AttacksErosion of Trust in DHS/Federal AgenciesReputation Damage for Affected Platforms (Apple, Google, etc.)High (184M Records Exposed in Plain Text)High (Bank Account Details Exposed in 2025 Breach)
DATA BREACH
Intelligence Reports (DHS)User Credentials (Plain Text)Bank Account DetailsHealth DataGovernment Portal AccessUndisclosed (DHS)184 million (2025 Breach)High (Intelligence/National Security)Critical (Financial/Health Data)Likely (2025 Breach)Unconfirmed (DHS)None (Plain-Text Records in 2025 Breach)Database RecordsAuthorization URLsCredentialsUsernamesPasswordsBank Account DetailsHealth Records
JUNE 2020
746Before Incident
Ransomware
16 Jun 2020UDHS
US Federal Agencies

Russian Basketball Player Arrested for Ransomware Negotiation

656After Incident
CRITICAL-90
US-341071125
Daniil Kasatkin, a 26-year-old Russian professional basketball player, was arrested at Charles de Gaulle Airport in Paris on June 21, 2023, for his alleged involvement in a ransomware gang that operated between 2020 and 2022. The gang is accused of targeting around 900 organizations, including two US federal agencies. Kasatkin is facing charges of 'conspiracy to commit computer fraud' and 'computer fraud conspiracy.' His lawyers deny the allegations, claiming he is not tech-savvy and was unaware of any unlawful activities. The US has not yet released any statements or evidence regarding the crimes.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
JANUARY 2018
766Before Incident
Breach
01 Jan 2018UDHS
U.S. Department of Homeland Security

DHS Data Breach Incident

702After Incident
HIGH-64
USD331181223
DHS had a privacy incident that resulted in the exposure of information for 247,167 active and retired federal employees. The database utilised by the DHS Office of the Inspector General (OIG) and kept in the Department of Homeland Security OIG Case Management System was compromised by a data breach. Employee names, Social Security numbers, dates of birth, jobs, grades, and duty locations are among the data that has been made public. In addition to putting additional security measures in place to restrict access to this kind of information, the Department of Homeland Security notified those who were impacted through notification letters.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Employee namesSocial Security numbersDates of birthPositionsGradesDuty locationsDHS OIG Case Management System
DATA BREACH
Personally Identifiable InformationSensitivity Of Data: HighEmployee namesSocial Security numbersDates of birthPositionsGradesDuty locations
FEBRUARY 2016
810Before Incident
Data Leak
01 Feb 2016UDHS
U.S. Department of Homeland Security

Department of Justice Email Account Compromise

744After Incident
CRITICAL-66
USD181261023
A Department of Justice employee's email account was compromised by a hacker, who took 200GB of data, including records of 20,000 FBI workers and 9,000 DHS employees. Delving deeper into the archive, one finds information about DHS security experts, programme analysts, IT, infosec, and security, as well as 100 individuals who hold the title of intelligence. Motherboard claims that a hacker gained access to a Department of Justice employee's email account. As evidence, the hacker used the hacked account to send the email directly to Motherboard contributor Joseph Cox. The apparent job titles, names, phone numbers, and email addresses of over 9,000 purported Department of Homeland Security (DHS) workers and over 20,000 purported FBI employees.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
200GB of data, including records of 20,000 FBI workers and 9,000 DHS employeesInformation about DHS security experts, programme analysts, IT, infosec, and security, as well as 100 individuals who hold the title of intelligenceBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Personally Identifiable Information (PII)Job TitlesPhone NumbersEmail AddressesNumber Of Records Exposed: 29,000Sensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for UDHS ?
?
What was UDHS's A.I Rankiteo Cyber Score in June 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was UDHS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was UDHS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was UDHS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was UDHS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was UDHS's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on UDHS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with UDHS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view UDHS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
U.S. Department of Homeland Security Cyber Scoring History | Rankiteo