Heimdal Security Blog

Malicious Cyber Activity Targeting Election Systems: FBI Declares

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) declares in a public service announcement that cyber activity has been registered to try to compromise the infrastructure of the election. The attempt is unlikely to affect the voting result or cause any major disruption in the system.

The two institutions assessed the risks associated with the attempts over time, but neither of them has seen evidence of malicious interference having any significant impact.

The Situation Explained

In the PSA issued, the two institutions explain that the election officials have a variety of technological, physical, and procedural controls at their disposal, to mitigate the likelihood of malicious cyber activities (such as phishing, ransomware, denial of service, or domain spoofing) that may affect the integrity of the election infrastructure.

Some methods mentioned are failsafe measures, such as provisional ballots and backup pollbooks, and safeguards that protect against voting malfunctions (e.g. logic and accuracy testing, chain of custody procedures, paper ballots, and post-election audits).

Given the extensive safeguards in place and distributed nature of election infrastructure, the FBI and CISA continue to assess that attempts to manipulate votes at scale would be difficult to conduct undetected.

Source

BleepingComputer cites that physical access to the devices, access to the Election Management System (EMS), or the capability to conduct supply chain attacks to change the files before to the operating system images being loaded onto ImageCastX devices are all requirements for exploiting these weaknesses.

Cyberattack Attempts Blocked

FBI and CISA declared that any attempts have remained localized and were blocked or successfully mitigated with minimal or no disruption to the election processes.

As of the date of this report, the FBI and CISA have no reporting to suggest cyber activity has ever prevented a registered voter from casting a ballot, compromised the integrity of any ballots cast, or affected the accuracy of voter registration information.

Source

The FBI and CISA continue to believe that it would be challenging to carry out large-scale vote-rigging attempts covertly given the numerous safeguards in place and the scattered nature of election infrastructure.

Election systems that house voter registration information or manage non-voting election processes continue to represent an attractive target for threat actors, the FBI declares. Cyberattacks may also seek to spread or amplify false or exaggerated cybersecurity compromises to the election infrastructure, but these attempts would not impact the results of the vote.

Recommendations for Protection

In addition to continuing to swiftly react to any potential threats, the FBI and CISA will continue to warn stakeholders of threats and intrusion activity, provide recommendations to harden election infrastructure, and impose risks and consequences on cyber actors attempting to endanger U.S. elections.

If you liked this article, follow us on LinkedIn, Twitter, Facebook, Youtube, and Instagram for more cybersecurity news and topics.