FOIA Documents Reveal DHS Portal Exposed Americans' Sensitive Data to Foreign Governments for Two Months
Newly released documents show a Department of Homeland Security intelligence-sharing platform inadvertently granted 14 foreign nations unrestricted access to the private communications and financial data of U.S. citizens. The two-month exposure has triggered bipartisan congressional probes and outrage from civil liberties groups.
By Factlen Editorial Team
- Privacy Advocates
- Argue this breach proves that massive domestic surveillance databases are inherently dangerous and violate the Fourth Amendment.
- Congressional Critics
- Focus on the lack of internal DHS auditing that allowed the breach to persist for two months unnoticed, demanding strict accountability.
- National Security Establishment
- Emphasize the necessity of the intelligence portal for counter-terrorism and frame the exposure as a regrettable but fixable IT error.
What's not represented
- · Foreign intelligence agencies whose access to the portal was disrupted
- · The IT contractors responsible for the April 12 software update
Why this matters
This breach bypasses fundamental constitutional protections by allowing foreign intelligence services to view domestic financial, travel, and communication records without a U.S. warrant. If your data was swept up in routine DHS monitoring, it may now reside permanently on the servers of over a dozen foreign governments.
Key points
- A DHS software error exposed unredacted data on 4.2 million Americans to 14 foreign governments.
- The exposure lasted for 61 days before a foreign intelligence partner flagged the issue.
- Exposed data included financial records, travel logs, and communication metadata.
- Bipartisan lawmakers are demanding accountability and a review of intelligence-sharing protocols.
A newly declassified batch of Freedom of Information Act (FOIA) documents has revealed that a Department of Homeland Security (DHS) intelligence-sharing portal inadvertently granted 14 foreign governments unrestricted access to the sensitive personal data of millions of American citizens. The exposure, which lasted for exactly 61 days between April and June 2026, bypassed standard constitutional safeguards that require warrants for domestic surveillance. The documents were obtained and published by the Electronic Frontier Foundation following a protracted legal battle over the agency's data-sharing practices.[1][5]
The breach centered on the Homeland Intelligence Exchange (HIE), a cloud-based platform designed to share counter-terrorism threat indicators with allied nations. According to internal emails obtained in the FOIA request, a software update deployed on April 12 accidentally stripped the "U.S. Person" masking filters from the database. These filters are legally mandated to automatically redact the identifying information of American citizens before intelligence is shared with foreign entities.[2]
As a result of the coding error, foreign intelligence analysts logging into the portal could view raw, unredacted files on approximately 4.2 million Americans. The exposed data included domestic travel logs, financial transaction metadata, border crossing records, and in some cases, intercepted communications metadata collected under controversial domestic surveillance programs. Because the system was designed for bulk analysis, foreign agencies were able to query this data seamlessly alongside international threat metrics.[1][4]

Alarmingly, the DHS did not detect the vulnerability internally. The exposure was only flagged on June 12 when a British intelligence liaison contacted the agency to inquire why they were suddenly receiving unmasked financial records of U.S. citizens who were not linked to any active investigations. Upon receiving the notification, DHS administrators immediately took the portal offline for emergency patching and initiated an internal audit.[2][3]
Alarmingly, the DHS did not detect the vulnerability internally.
While the DHS has refused to publicly name all 14 countries that had access to the unmasked data, congressional sources confirm the list includes the "Five Eyes" intelligence alliance—the U.K., Canada, Australia, and New Zealand—alongside several Middle Eastern and European partners. Civil liberties advocates have expressed deep alarm that nations with differing human rights and privacy standards had unfettered access to American domestic data, warning of the potential for transnational repression.
In a statement released Wednesday morning, the DHS characterized the incident as a "technical misconfiguration rather than a targeted exploit," emphasizing that there is no evidence the data was downloaded in bulk by foreign adversaries. "We have secured the platform and are working closely with our international partners to ensure any inadvertently accessed U.S. person data is permanently purged from their systems," a spokesperson said, though they declined to answer questions about how such a purge could be verified.[1]

The revelation has triggered immediate bipartisan outrage on Capitol Hill, uniting lawmakers who rarely agree on national security policy. Republican lawmakers have accused the administration of gross negligence regarding the protection of American citizens, while progressive Democrats are renewing calls to dismantle the HIE portal entirely, arguing it serves as a backdoor for warrantless surveillance that inevitably leads to abuse.[3][4]
The House Homeland Security Committee has subpoenaed the DHS's chief information officer to testify in an emergency closed-door hearing next week. Meanwhile, legal experts warn that retrieving the exposed data is practically impossible; once digital records cross international borders and enter foreign intelligence databases, U.S. authorities have no technical mechanism to verify their deletion, leaving millions of Americans permanently exposed to foreign monitoring.[2][5]
How we got here
April 12, 2026
A software update to the Homeland Intelligence Exchange accidentally disables 'U.S. Person' privacy filters.
June 12, 2026
A British intelligence liaison notifies DHS of the unmasked data; the portal is taken offline.
July 14, 2026
The Electronic Frontier Foundation publishes the internal DHS emails obtained via FOIA request.
July 15, 2026
Bipartisan congressional committees announce emergency hearings into the breach.
Viewpoints in depth
Privacy Advocates
Civil liberties groups argue the breach highlights the inherent dangers of mass surveillance.
Organizations like the Electronic Frontier Foundation argue that this exposure is exactly why massive, centralized databases of domestic information are a threat to constitutional rights. They contend that 'U.S. Person masking' is merely a software band-aid on an architecture that fundamentally violates the Fourth Amendment. By collecting the data in the first place, advocates argue, the DHS created an unacceptable risk that it would eventually be leaked, hacked, or inadvertently shared with regimes that do not respect privacy rights.
National Security Establishment
Intelligence officials maintain the portal is vital for global security despite the technical error.
Current and former national security officials emphasize that platforms like the Homeland Intelligence Exchange are critical for tracking transnational terrorism and organized crime. They frame the exposure as a severe but fixable IT failure rather than a reason to dismantle intelligence-sharing agreements. From this perspective, isolating U.S. databases from allied nations would create dangerous blind spots, and the focus should be on implementing stricter automated audits rather than halting international cooperation.
Congressional Oversight
Lawmakers are focusing on the failure of internal DHS audits to catch the two-month exposure.
Bipartisan members of the House Homeland Security Committee are directing their anger at the agency's lack of internal safeguards. Lawmakers are questioning how a massive data pipeline could flow unredacted for 61 days without triggering a single internal alarm or compliance flag. The fact that a foreign government had to notify the U.S. of its own data breach is being cited by congressional critics as evidence of systemic mismanagement within the DHS's IT and compliance divisions.
What we don't know
- Which specific non-allied nations had access to the unmasked data.
- Whether any foreign intelligence services downloaded or weaponized the information before the portal was secured.
- If affected U.S. citizens will be individually notified by the government.
Key terms
- Homeland Intelligence Exchange (HIE)
- A cloud-based platform used by the DHS to share counter-terrorism threat indicators with allied foreign governments.
- U.S. Person Masking
- A legal and technical requirement to redact the identifying information of American citizens in intelligence reports before they are shared.
- Five Eyes
- An intelligence alliance comprising the United States, United Kingdom, Canada, Australia, and New Zealand.
Frequently asked
Was my personal data exposed in this breach?
The DHS has not released a tool for citizens to check if their data was exposed, but it primarily affects individuals whose travel or financial metadata was already swept up in DHS monitoring systems.
Can the U.S. force foreign governments to delete the data?
While the DHS is requesting that partner nations purge the inadvertently shared files, U.S. authorities have no technical or legal mechanism to verify that foreign intelligence services actually delete the data.
Was this a cyberattack by a foreign adversary?
No. Internal documents indicate the exposure was caused by a domestic software misconfiguration during a routine system update, not a malicious hack.
Sources
[1]ReutersNational Security Establishment
DHS portal exposed U.S. citizen data to foreign allies, FOIA reveals
Read on Reuters →[2]The Washington PostCongressional Critics
A DHS coding error gave 14 countries access to Americans' private data
Read on The Washington Post →[3]PoliticoCongressional Critics
Bipartisan fury as DHS admits to two-month intelligence portal leak
Read on Politico →[4]The Wall Street JournalNational Security Establishment
DHS data exposure prompts congressional investigation into intelligence sharing
Read on The Wall Street Journal →[5]Electronic Frontier FoundationPrivacy Advocates
EFF FOIA Victory: DHS Admits to Unlawful Data Sharing With Foreign Governments
Read on Electronic Frontier Foundation →
More in news politics
See all 8 stories →Climate Policy
EPA Finalizes Repeal of Greenhouse Gas Endangerment Finding and Federal Vehicle Emission Standards
4 sources
Immigration Law
Justice Department Activates Untested 'Alien Terrorist Removal Court' for First-Ever Deportation Proceedings
8 sources
Education Policy
House GOP Advances Bill to Permanently Dismantle Education Department
4 sources
Higher Ed Policy
Trump Administration Drafts Sweeping Rule to Exert Ideological Control Over U.S. Higher Education and Research
8 sources
Every angle. Every day.
Get news politics stories with full source coverage and perspective breakdowns delivered to your inbox.










