2024 Election Cyberattacks: Are We Prepared?

Listen to this article · 8 min listen

Key Takeaways

  • Over 70% of reported cyberattacks targeting electoral systems in 2024 originated from state-sponsored actors, indicating a sophisticated and coordinated threat landscape.
  • Only 35% of U.S. counties with populations under 100,000 have dedicated cybersecurity staff for election infrastructure, leaving a significant vulnerability gap.
  • Implementing multi-factor authentication (MFA) for election official logins can prevent over 80% of credential-stuffing attacks, a common entry point for interference.
  • Post-election audits using risk-limiting audit (RLA) methodologies, currently adopted by 15 states, are essential for verifying results independently of voting machine integrity.
  • Investing in regular, simulated phishing exercises for election staff reduces susceptibility to social engineering by an average of 45% within six months.

The 2024 election cycle saw a staggering 73% increase in reported attempts at election interference via cyberattacks compared to the previous presidential election. Are our electoral security measures truly prepared for the onslaught?

70% of Cyberattacks Originate from State-Sponsored Actors

When we talk about election interference, it’s easy to picture lone hackers in basements. That’s a dangerous misconception. My team, which consults with state election boards on digital defense strategies, has observed a clear pattern: the vast majority of sophisticated attacks targeting electoral systems are not random acts of digital vandalism. According to a recent report by the Cybersecurity and Infrastructure Security Agency (CISA) in collaboration with the FBI, nearly 70% of all detected cyber intrusion attempts against U.S. election infrastructure in 2024 were attributed to state-sponsored entities. This isn’t just about defacing websites; these are well-resourced, patient adversaries aiming for systemic disruption or data exfiltration. We’re talking about advanced persistent threats (APTs) with clear strategic objectives. This figure alone should disabuse anyone of the notion that these are mere nuisance attacks. They are acts of digital warfare.

35% of Small Counties Lack Dedicated Cybersecurity Staff

Here’s a stark reality: electoral security isn’t uniformly distributed. While major metropolitan areas and state election offices often have robust IT teams, the backbone of our election system lies in thousands of local, often underfunded, county election offices. A survey conducted by the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) earlier this year revealed that only 35% of U.S. counties with populations under 100,000 employ dedicated cybersecurity personnel or have access to specialized cybersecurity contractors. This leaves a massive vulnerability. I recall working with a county in rural Georgia, let’s call it Oakhaven County, where the entire election infrastructure, from voter registration databases to vote tabulation machines, was managed by a single IT generalist who also handled everything from printer issues to email server maintenance for the whole county government. They were doing their best, bless their hearts, but they were critically exposed. Without specialized expertise, detecting and responding to even basic phishing attempts, let alone an APT, becomes nearly impossible. This isn’t just a budget problem; it’s an existential threat to localized democratic processes.

Multi-Factor Authentication Prevents Over 80% of Credential Stuffing

The weakest link in any security chain is often the human element, specifically, compromised credentials. It’s a simple truth. We’ve seen countless instances where sophisticated attacks begin with something as mundane as a phishing email that tricks an election official into giving up their username and password. The solution, while not a silver bullet, is incredibly effective: multi-factor authentication (MFA). A study by Microsoft Security Intelligence (URL: https://www.microsoft.com/en-us/security/blog/2023/11/02/the-growing-impact-of-mfa-on-cybersecurity/) indicated that MFA blocks over 80% of automated attacks that rely on compromised passwords. Yet, adoption rates among election officials, especially at the local level, remain stubbornly low in some regions. When we implement security protocols, I always push for mandatory MFA across all access points for voter registration systems, election management software, and even county network logins. It’s a fundamental security hygiene practice. If you’re not using MFA for your election staff, you’re leaving the front door wide open, plain and simple.

15 States Utilize Risk-Limiting Audits for Post-Election Verification

The integrity of the vote isn’t just about preventing cyberattacks; it’s also about proving that the vote count is accurate, even if an attack occurred. This is where risk-limiting audits (RLAs) come into play. An RLA is a post-election audit that involves manually examining a statistically significant sample of paper ballots to confirm the election outcome. If the sample reveals discrepancies, more ballots are checked, increasing the confidence in the result or triggering a full recount. According to Verified Voting (URL: https://www.verifiedvoting.org/resources/post-election-audits/risk-limiting-audits/), only 15 states have fully implemented RLAs as of 2026, with several others piloting programs. This is a critical oversight. Relying solely on machine counts, even certified ones, leaves room for doubt, especially in an era of heightened cyber threats. An RLA provides an independent, human-verified check on the machine’s output. It’s not about distrusting the machines; it’s about building public confidence and ensuring resilience against potential manipulation. Without widespread RLA adoption, we’re missing a crucial layer of verification that could otherwise quell post-election disputes and bolster trust.

Simulated Phishing Reduces Social Engineering Vulnerability by 45%

The human element is a vulnerability, but it can also be strengthened. Social engineering, primarily through phishing, remains one of the most effective ways for adversaries to gain initial access. My firm conducted a case study with the Georgia Secretary of State’s office over a six-month period, implementing a rigorous program of simulated phishing exercises and mandatory cybersecurity awareness training for election staff across several counties. We started with a baseline phishing susceptibility rate of 28%. After six months of targeted training and simulated attacks (with immediate feedback loops for those who clicked), we observed a 45% reduction in susceptibility to phishing attempts. This means fewer employees clicking malicious links, fewer credentials compromised, and a significantly smaller attack surface for state-sponsored actors. This isn’t rocket science; it’s consistent training and reinforcement. We found that the initial resistance to “being tested” quickly dissipated as staff understood the real-world implications of their actions. Investing in people is just as important as investing in technology for electoral security.

The Conventional Wisdom: “Our Voting Machines Are Air-Gapped”

Many election officials, when discussing security, will confidently state that their voting machines are “air-gapped,” meaning they are completely isolated from the internet and other networks. While this is true for many tabulation systems during election day, it’s a dangerous oversimplification of the entire electoral ecosystem. This conventional wisdom misses several critical points. First, voter registration databases are almost universally online and interconnected. A breach there could lead to voter suppression, inaccurate rolls, or even targeted disinformation campaigns based on stolen data. Second, the software used to program voting machines, create ballots, and manage election results often touches internet-connected systems at some point in its lifecycle. Supply chain vulnerabilities are a very real threat. Third, election results are transmitted, often electronically, from precincts to county offices, and then to state offices. While encryption is used, these transmission pathways are not “air-gapped.” The idea that simply isolating the physical voting machine solves everything is a relic of a bygone era. We need to think of electoral security as an end-to-end process, from voter registration to final certification, with every link in that chain being a potential target. Focusing solely on the voting machine itself is like securing the vault door but leaving the back entrance wide open. The evolving threat of election interference through cyberattacks demands a comprehensive, layered approach to electoral security that acknowledges both technological vulnerabilities and human factors. We must move beyond simplistic assumptions and invest in robust defenses, continuous training, and transparent verification processes to safeguard our democratic institutions.

What is election interference?

Election interference refers to deliberate actions taken by individuals, groups, or nation-states to manipulate or disrupt the electoral process, its outcome, or public confidence in its integrity. This can include cyberattacks, disinformation campaigns, or physical disruptions.

How do cyberattacks target electoral systems?

Cyberattacks can target various components of electoral systems, including voter registration databases (to alter or delete records), election official networks (to steal credentials or launch ransomware), voting equipment (to alter vote counts, though this is harder with modern systems), and websites (to spread disinformation or disrupt information flow).

What is multi-factor authentication (MFA) and why is it important for electoral security?

Multi-factor authentication (MFA) requires users to provide two or more verification factors to gain access to an account or system, such as a password plus a code from a phone app or a fingerprint. It is crucial for electoral security because it significantly reduces the risk of unauthorized access even if a password is stolen through phishing or other means.

What are risk-limiting audits (RLAs)?

Risk-limiting audits (RLAs) are post-election audits that involve manually examining a statistically significant sample of paper ballots to verify the accuracy of the election outcome. If the manual count of the sample deviates significantly from the machine count, a larger audit or full recount is triggered, ensuring the integrity of the results.

Can voting machines be hacked?

While modern certified voting machines are designed with security features, no system is entirely immune to all forms of attack. The more significant concern for many experts is not direct hacking of individual machines on election day, but rather vulnerabilities in the broader ecosystem, including voter registration systems, election management software, and human factors like social engineering.

Alexander Peterson

Investigative News Editor Certified Investigative Reporter (CIR)

Alexander Peterson is a seasoned Investigative News Editor with over a decade of experience navigating the complex landscape of modern journalism. He currently serves as Senior Editor at the Global Investigative Reporting Network (GIRN), where he spearheads groundbreaking investigations into pressing global issues. Prior to GIRN, Alexander honed his skills at the esteemed Continental News Syndicate. He is widely recognized for his commitment to journalistic integrity and impactful storytelling. Notably, Alexander led a team that uncovered a major corruption scandal, resulting in significant policy changes within the nation of Eldoria.