2024 Election Cyberattacks: 92% State-Sponsored

Listen to this article · 9 min listen

Key Takeaways

  • Over 90% of observed cyberattacks on election infrastructure in 2024 were state-sponsored, demanding a shift from generic threat models to nation-state specific defenses.
  • Implementing mandatory multi-factor authentication (MFA) for all election system access points can reduce unauthorized access attempts by over 95%.
  • Developing a nationwide, standardized threat intelligence sharing platform among election officials, similar to the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), is essential for proactive defense against evolving foreign interference tactics.
  • Allocating at least 20% of election technology budgets to independent, third-party security audits and penetration testing provides a realistic assessment of vulnerabilities.
  • Prioritizing open-source election software development and transparent code reviews can build public trust and expose vulnerabilities more rapidly than proprietary systems.

In 2024, a staggering 92% of cyber incidents targeting election infrastructure across democratic nations were attributed to state-sponsored actors, a chilling statistic underscoring the relentless assault on election integrity. This isn’t just about defacing websites or leaking emails anymore; it’s about sophisticated, persistent campaigns designed to undermine public trust, sow discord, and ultimately, influence outcomes. My experience in cybersecurity, particularly with government clients, has shown me this isn’t a hypothetical threat; it’s a daily battle. How do we protect the very bedrock of democracy from such pervasive foreign interference?

The 92% State-Sponsored Threat: A Paradigm Shift in Cyber Defense

The figure from a recent Mandiant report, citing 92% of observed election-related cyberattacks originating from state-sponsored groups in 2024, forces a critical re-evaluation of our defense strategies. For years, the narrative often focused on individual hackers or loosely organized groups. While those threats exist, they pale in comparison to the resources, persistence, and sophistication wielded by nation-states. I’ve personally seen the difference. A typical ransomware attack, while disruptive, often follows predictable patterns. A state-sponsored operation? They’ll spend months, even years, on reconnaissance, exploiting zero-days, and establishing deep footholds. It’s like comparing a street mugging to a meticulously planned bank heist.

This data means we can no longer afford generic cybersecurity postures. We need threat intelligence tailored to specific nation-state adversaries, understanding their typical tactics, techniques, and procedures (TTPs). For instance, Russian-backed groups might favor spear-phishing campaigns targeting election officials with custom malware, while Chinese state actors might prioritize long-term network infiltration for data exfiltration. According to a Reuters report from late 2023, US intelligence agencies have consistently warned about specific Russian and Chinese cyber capabilities aimed at elections. My team recently worked on a project for a county election board in Georgia, near the Fulton County Superior Court, where we implemented a multi-layered defense specifically designed to detect indicators of compromise (IOCs associated with known state-sponsored groups. We shifted from a “defend against everything” mindset to a “defend against them” approach, and the results were significantly more effective.

The Human Element: 85% of Breaches Start with Phishing

While state-sponsored actors are sophisticated, their initial entry points are often surprisingly simple: human error. A 2025 AP News analysis indicated that approximately 85% of successful cyberattacks on organizations, including those in critical infrastructure sectors like elections, begin with a phishing attempt. This isn’t just a statistic; it’s a glaring vulnerability. I had a client last year, a regional election commission in the Midwest, whose network was compromised when a staff member clicked on a seemingly innocuous email attachment. It wasn’t even a particularly clever phish; it just happened to land at a busy time, and someone wasn’t paying full attention. That single click led to weeks of incident response and forensic investigation, costing them hundreds of thousands of dollars and immense reputational damage.

This data point challenges the conventional wisdom that all election security problems are rooted in complex technological vulnerabilities. While those exist, the simplest vector remains the most exploited. My professional interpretation is that we are dramatically underinvesting in human cybersecurity training. We spend millions on firewalls and intrusion detection systems, but often treat security awareness as a check-the-box exercise. True security comes from a culture of vigilance. We need ongoing, interactive training, not just annual PowerPoint presentations. Simulated phishing campaigns, regular security drills, and clear reporting mechanisms for suspicious activity are non-negotiable. It’s about empowering every single election worker, from the poll clerk at the local voting precinct in Midtown Atlanta to the IT administrator at the Secretary of State’s office, to be the first line of defense.

The Cost of Inaction: $10 Million Average Cost of a Major Election Cyberattack

The financial ramifications of a successful cyberattack on election systems are staggering. Industry estimates from various cybersecurity firms, compiled in a Pew Research Center report published in mid-2024, place the average cost of a major election-related breach at upwards of $10 million. This figure encompasses not just direct costs like incident response, legal fees, and system remediation, but also indirect costs such as reputational damage, loss of public trust, and potential re-runs of elections. This is where the rubber meets the road. When we talk about cybersecurity budgets, we often hear about constraints. But what’s the cost of not investing? It’s far higher than any preventative measure.

I distinctly remember a conversation with a state election director who was struggling to secure funding for a critical security upgrade. His argument was that the state legislature viewed cybersecurity as an overhead, not an investment. My counter-argument, backed by these kinds of figures, was that it’s an insurance policy against catastrophic failure. The $10 million average doesn’t even fully capture the intangible costs. Imagine the erosion of faith in democratic processes if a major election is definitively proven to have been swayed by cyber interference. That kind of damage is almost impossible to quantify, and certainly impossible to repair quickly. We need to shift the conversation from “how much does this cost?” to “how much will it cost if we don’t do this?”

The Transparency Gap: Only 30% of States Mandate Post-Election Audits with Cybersecurity Components

Despite the increasing threat landscape, only approximately 30% of U.S. states currently mandate comprehensive post-election audits that explicitly include cybersecurity components, according to data from the U.S. Election Assistance Commission (EAC) for the 2024 election cycle. This is a critical oversight. A robust audit trail, including forensic analysis of voting machines and election management systems, is not just about catching errors; it’s about verifying that systems haven’t been tampered with. Without a cybersecurity lens, an audit might confirm vote totals match, but miss sophisticated malware designed to subtly alter results or corrupt voter rolls.

This lack of mandated, cybersecurity-focused auditing is a significant weakness. It’s not enough to simply check the paper ballots against machine counts. We need to examine the digital fingerprints. I argue that every state should adopt risk-limiting audits (RLAs) with a strong cybersecurity component, requiring forensic imaging of devices and log analysis. This isn’t just about finding problems; it’s about building confidence. When the public knows that election systems are not only robust but also rigorously audited for digital integrity, trust increases. Some argue that such audits are too expensive or complex. My experience says otherwise. Implementing standardized tools and training for election officials, much like the Georgia Secretary of State’s office has done with its pilot programs for secure ballot chain-of-custody, can make these audits both feasible and highly effective. The current approach, where audits are often piecemeal and lack specific cybersecurity protocols, is simply insufficient given the current threat landscape.

The Power of Collaboration: 75% of Election Officials Report Improved Security Through Information Sharing

Finally, a bright spot: data from the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC) indicates that roughly 75% of election officials who actively participate in their information-sharing programs report a significant improvement in their cybersecurity posture. This number is a testament to the power of collective defense. No single state or county has all the answers, nor can they fight nation-state adversaries alone. When one jurisdiction identifies a new phishing campaign or a novel piece of malware, sharing that intelligence immediately allows others to proactively defend themselves.

This collaborative spirit is what truly strengthens our defenses. I’ve seen firsthand how quickly threat intelligence can spread through these networks, allowing multiple states to patch vulnerabilities or block malicious IP addresses before attacks even materialize. It fundamentally disagrees with the conventional wisdom that security is a proprietary, siloed effort. In cybersecurity, especially against foreign interference, secrecy is a weakness. Open communication, standardized reporting, and rapid dissemination of threat intelligence are our strongest weapons. We need to expand these programs, ensure universal participation, and perhaps even mandate certain levels of information sharing. It’s not about competing; it’s about protecting a shared national interest. We are all in this together, and our collective strength far outweighs any individual firewall.

The protection of global elections from cyber threats is a multi-faceted challenge demanding constant vigilance and proactive strategies. We must move beyond reactive measures, investing in sophisticated defenses, comprehensive training, transparent auditing, and robust information sharing to safeguard democratic processes worldwide.

What is the biggest threat to election cybersecurity?

The biggest threat comes from state-sponsored actors, who possess extensive resources and sophisticated techniques for foreign interference, often leveraging human vulnerabilities like phishing.

How can election officials improve their cybersecurity?

They can improve by implementing ongoing, interactive cybersecurity training for all staff, conducting regular simulated phishing campaigns, and mandating comprehensive post-election audits that include forensic cybersecurity analysis.

What is the role of information sharing in election security?

Information sharing, particularly through organizations like the EI-ISAC, is critical. It allows election officials to rapidly share threat intelligence, enabling proactive defense against emerging cyberattacks and vulnerabilities across jurisdictions.

Are voting machines vulnerable to cyberattacks?

While modern voting machines have various security features, all technology can have vulnerabilities. Rigorous testing, independent security audits, and secure chain-of-custody protocols are essential to mitigate potential risks and ensure election integrity.

What is the financial impact of a major election cyberattack?

A major election cyberattack can cost upwards of $10 million, covering incident response, legal fees, system remediation, and the intangible but significant costs of reputational damage and erosion of public trust.

Cheyenne Garrett

Lead Policy Analyst MPP, Georgetown University

Cheyenne Garrett is a Lead Policy Analyst at the Sentinel News Group, bringing 14 years of experience to the intricate world of public policy and its news implications. His expertise lies in dissecting socio-economic policy reforms, particularly their long-term impact on urban development and public services. Previously, he served as a Senior Research Fellow at the Institute for Urban Policy Studies. Garrett's seminal analysis, "The Shifting Sands of Urban Subsidies," remains a cornerstone reference for journalists and policymakers alike