Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

States are building their own election defense networks as federal support evaporates 

By: djohnson
13 July 2026 at 16:59

The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new legal peril for officials who run, administer and secure elections.

The EAC is an obscure but important agency that oversees testing and standards for voting machines, including around security. While federal certification is voluntary, states have until now relied upon their stamp of approval when purchasing voting machines. 

On July 10, Democratic Commissioners Ben Hovland and Thomas Hicks were fired by the White House, while reports indicate that a third Commissioner, Republican Christy McCormick, resigned. While Congress mandated the commission be bipartisan, the Supreme Court has recently given the President broad authority to fire executive branch officials at will.

In an interview with NPR, Hovland said he worried the firings would further erode trust that the commission was working in a bipartisan manner.

“And as you eliminate things – or if you get rid of commissioners, for example – or as you eliminate some of these other sort of safeguards or norms, it certainly strains the system,” said Hovland. “And it certainly also likely causes people to lose faith in our democracy and in the process and their confidence in our elections. And that’s very concerning.”

A letter also sent last week to all 50 states by the DOJ said the department will investigate and prosecute any election official “who knowingly retains non-citizens on the state’s voter registration list or facilitates noncitizens in receiving and casting ballots.”

CyberScoop spoke with several Secretaries of State who said that the number one threat facing elections in their state is not from a foreign country or AI but their own federal government. 

Tobias Read, the Democratic Secretary of State for Oregon, told CyberScoop that his office is focused on providing the state’s 36 county clerks with the resources and support they need to carry out a smooth election. But he acknowledged that his office is “playing defense in a lot of ways [from] the intrusion from the federal government” that continues to assert its authority over local elections.

“If the president were actually serious about election security, he would be sending more resources to local election officials and bolstering the system rather than cutting it,” said Read.

This year, several counties in Oregon will offer voters access to a new ballot tracking system that provides text or email updates when a voter’s ballot is moving through mail and has been certified.  Reed estimated at “pennies per voter per election” and called it a good option for cash-strapped counties to assure voters their ballots are secure and properly tracked.

At the same time, Read said federal agencies like the Cybersecurity and Infrastructure Security Agency – which once regularly deployed cybersecurity and technical expertise to help states fix vulnerabilities and share threat intelligence – have largely gone quiet.

Oregon ranks in the top ten states for voter participation and relies heavily on mail-in voting.  However, state officials like Read lack confidence in the US Postal Service. Though a recent Supreme Court decision blocked an executive order giving the service control over mail-in ballot distribution, officials like Read are urging voters to take other measures to use drop boxes instead as a  safer alternative to ensure their vote is counted.

Adrian Fontes, Arizona’s Secretary of State and a Democrat running for reelection, said his office is focused on primary elections and processing the mail ballots that have been arriving “for a while.”

After Iranian hackers defaced Arizona’s candidate bio portal last year, Fontes moved to fill a widening gap: the Trump administration’s withdrawal of federal foreign interference training and support. His office is now directly supporting local jurisdictions on election security while coordinating more closely with state law enforcement, intelligence agencies, and other states.

But it’s being done with a fraction of the resources and coordination that the federal government brought to bear under both the Biden and first Trump administrations. While Fontes said he maintains positive personal relationships within the Department of Homeland Security, his office does not have a formal relationship with CISA.

“We’ve hobbled together a loose and often informal network of information sharing – that doesn’t violate any rules, it doesn’t break any laws – but it is certainly not anywhere near as robust as it would be if we had a responsible federal agency that was interested in the security of American elections,” said Fontes.

He said even if CISA offered such services today, he wouldn’t accept it, citing the lack of trust between states and the Trump administration.

“They have proven through their actions that they don’t want to be effective partners in protecting the American electorate and protecting American voters,” said Fontes. “Because of that, the clear answer, the only sensible answer for someone like me, would be to say ‘No, I don’t want the help of people I cannot trust.’ People who have demonstrably and explicitly threatened me and local election administrators of all political stripes with criminal prosecution.”

After this story’s initial publication, CISA acting director Nick Andersen said the agency remains committed working with “with critical infrastructure owners and operators to assist them in securing both the physical security and cybersecurity of the systems and assets that support the nation’s election process.”

“We provide state and local election officials, upon request, no-cost voluntary services such as the sharing of threat information, technical expertise, vulnerability scanning, and resilience-building support,” said Andersen in a statement sent to CyberScoop. “Our regional teams assist partners across the country by assessing risks, helping entities bolster defenses and improve resilience, and responding promptly to threats. We are committed to supporting state and local elections officials to protect election infrastructure and safeguard our democracy.”

Secretaries of State in Colorado, Nevada, Minnesota, Rhode Island, and others have also called the DOJ letters an attempt at federal intimidation of election officials. 

Others, like West Virginia Republican Secretary of State Kris Warner, have reiterated their refusal to hand over state voter data. On Monday, a federal judge upheld his right to do so. 

Warner wrote to the DOJ in response to say the state was “available to discuss our existing voter registration list maintenance” but “West Virginia law prohibits the disclosure of sensitive personally identifiable information contained in voter registration records.”

It’s leading some states to take new precautions. 

Read said he was working with Oregon county officials to make sure “county clerks have the number of their county counsel on speed dial” and know how to distinguish between a legitimate and illegitimate federal warrant or subpoena.

Additionally, FBI raids of election offices around the country to seize ballots records related to the 2020 and 2024 elections have been a cause for Read’s concern. By state law, Oregon and other states must keep copies of the ballot records and other election data they receive from counties for a certain time according to state law, after which they must eventually archive or destroy them according to ballot retention schedules.

Read emphasized that “it’s important to destroy those ballots at the appropriate time,”  The Trump administration has used the raids to further the impression of electoral fraud, despite the absence of credible evidence. 

“We can see when people are not on top of that, then you expose yourself to other vulnerabilities like the federal government seizing those ballots in Maricopa County [Arizona] and Fulton County [Georgia] as well,” said Read.

A former CISA official estimated that on Election Day in 2024, more than 1,000 representatives from federal, state and local governments, election technology vendors and other election stakeholders sat together in a room to communicate and coordinate.

Less than two years later, Read called his office’s interactions with CISA “minimal.” He recalled that upon taking office as Secretary of State in Jan 2025, one of his first conversations was with one of CISA’s regional advisors. A week later, those advisors were summarily fired by the Trump administration.

UPDATE: 7/14/2026, 11:15 a.m.: Updated with comments from CISA acting director Nick Andersen.

The post States are building their own election defense networks as federal support evaporates  appeared first on CyberScoop.

DOJ releases legal rationale for nationwide voter data collection

By: djohnson
13 May 2026 at 16:10


The Trump administration released a legal opinion outlining the legal rationale behind its nationwide voter data collection efforts, justifying an aggressive federal role in vetting voter eligibility, a position courts have repeatedly rejected in related litigation.

The memo, released Tuesday by the Department of Justice Office of Legal Counsel, concedes that while election administration is “primarily the purview of the states,” the administration’s efforts are a lawful exercise of federal oversight. 

The Justice Department grounds that rationale in a provision of the 1960 Civil Rights Act, requiring election officials to keep voter records for 22 months after an election so it can investigate potential civil rights violations. Under the memo’s reading, that retention rule also gives the Attorney General authority to obtain copies of those records “upon demand in writing.” 

The memo also cites several other federal election laws – like the Help America Vote Act, the National Voter Registration Act and the Voting Rights Act – as support for the executive branch’s efforts. It argues that those statutes have long required states to modernize and secure voting systems (including accessibility upgrades) and maintain accurate voter rolls by removing ineligible voters.

The memo further argues that the potential presence of one or more non-citizens on state voter rolls is enough to trigger the federal government’s nationwide data collection and sharing efforts with immigration authorities.

“Because illegal aliens are ineligible to vote, these generally applicable laws are also implicated by an illegal alien’s presence on a state’s voter rolls,” the memo states.

Multiple federal courts have come to the opposite conclusion, dismissing half a dozen lawsuits from DOJ and the Department of Homeland Security that would force states to comply. Further, states have repeatedly confirmed through recounts, audits, investigations and lawsuits that the number of non-citizens registered to vote (and who end up actually casting ballots) in U.S. elections is infinitesimal.

David Becker, executive director of the Center of Election Innovation and Research, noted in a post on BlueSky that “6 courts, including 2 judges appointed by the current president, think this ‘opinion’ isn’t worth the paper it’s written on.” Becker, a former DOJ senior trial attorney in the voting section of the Civil Rights Division, has consistently argued that the executive branch and White House have no legal or constitutional role to play in vetting state voter registration. 

Sarah Copeland Hanzas, Secretary of State for Vermont, gave a similar reaction when CyberScoop reached out for comment.

“It’s not worth the paper it’s printed on,” Hanzas said in a statement. “Or the electrons it takes to store and transmit 41 pages of fantasy.”

Election officials have largely resisted the federal government’s demands. Earlier this year, West Virginia Secretary of State Kris Warner told CyberScoop he had no intentions of handing over more information than is already publicly available.

“If they want it, they can have it: $500 dollars for [anyone to buy] the statewide list, but they’re not getting personal information,” Warner said in a January interview. “State law says we’re not sharing that and my job is to carry out the law laid out by the West Virginia legislature.”

The inability of the federal government to point to serious evidence of mass voter fraud or non-citizen voting has led states to rebuff attempts to collect sensitive data on every voter in their state, including names, social security numbers, home addresses, voter history and other details.

The administration says it intends to cross-check state data against immigration records, share that data with DHS and immigration enforcement agencies and ultimately create its own list of eligible voters. An executive order issued by the White House earlier this year sought to deny federal funding to states that did not accept voter lists from the federal government and directed the Attorney General to investigate state election officials for voter roll discrepancies. Voting groups have challenged the order’s legality, and a previous election-related executive order was largely ruled unconstitutional by the courts.

The administration has sued dozens of states who have refused to hand such data over, though it has yet to convince courts of the merit. One judge called the administration’s efforts “unprecedented and illegal” and accused the administration of twisting the Civil Rights Act and other federal laws that were passed “to protect hard won civil rights victories allowing access to the ballot box” in order to obtain unfettered access to state voter data.

The post DOJ releases legal rationale for nationwide voter data collection appeared first on CyberScoop.

Potential Cybersecurity Threats to the 2024 U.S. Election: Voter Database Leaks

5 November 2024 at 12:02

As the 2024 U.S. presidential election takes place, cybersecurity analysts are on high alert, warning of voter database leaks. They are warning of an increasingly complex landscape that could jeopardize voter data security and election integrity due to voter database leaks. The face-off between Kamala Harris and Donald Trump has intensified the focus on ensuring that electoral systems remain secure and resilient against potential cyberattacks.

It is crucial to protect against breaches, leaks, and disinformation campaigns that could influence public trust and democratic outcomes. Drawing insights from Constella Intelligence, this analysis examines the specific risks and incidents shaping the current election season.

U.S. Voter Data Leaks: A Persistent Threat

The United States has become a major target for voter data leaks, experiencing significant breaches that expose a wide range of personal information. Moreover, voter data from these breaches is being actively traded on deep and dark web forums, posing an ongoing risk to voter privacy and security.

Constella Intelligence’s findings show that U.S. voter data leaks account for approximately 78% of all voter data circulating on the dark web, underscoring the nation’s unique vulnerabilities stemming from its decentralized electoral system and vast voter data infrastructure. In the U.S. alone, 23 states have suffered data breaches, impacting regions nationwide and exposing significant weaknesses in the protection of sensitive voter information.

Key examples include Florida, Texas, Michigan, and Wisconsin. Given that there are 50 states in the United States, this means that approximately 46% of states have been affected by voter data breaches, reflecting the widespread and systemic nature of these vulnerabilities.

Notable incidents since 2020 illustrate the scope of these breaches:

  • Oklahoma: As shown in the previous image, a dark web forum post offered the 2024 Oklahoma voter list, including absentee voters, with instructions for accessing sensitive information for political purposes.
  • Florida: Multiple significant leaks have affected Florida, including incidents in April 2020 and March 2022. These repeated exposures highlight the challenges in securing voter information in large states with complex voter registration systems and higher volumes of data, which increase their vulnerability to breaches.
  • Wisconsin: A 2020 data leak compromised millions of voters, including such personal information as emails, names, phone numbers, and full addresses, showing how even isolated breaches can undermine public trust and voter security.
  • Other States: States like Oklahoma, North Carolina, Pennsylvania, Michigan, Delaware, Texas, and Alaska have also reported leaks, some of which date back as far as 2013. These incidents highlight the systemic difficulties in securing voter data across state lines.

Of the 23 affected states, voter data breaches have impacted both Democratic and Republican strongholds, as well as crucial swing states, highlighting the widespread nature of the threat regardless of political affiliation or regional importance.

  • Approximately 45% of Democratic-leaning states and 50% of Republican-leaning states have experienced data breaches.
  • Key swing states (5%) such as Florida, Georgia, or Pennsylvania have also been impacted. Swing states are particularly important because they often decide the overall outcome of elections, making any breach in these regions potentially more impactful.

This broad geographic spread means that voters from both parties, along with undecided voters, could be affected, potentially impacting voter turnout and election trust.

Emerging Cyber Threats and Manipulation Risks in the 2024 Election

In addition to voter data leaks, other cybersecurity threats could impact the 2024 U.S. election, such as disinformation campaigns, targeted voter suppression, and foreign interference. Constella Intelligence has identified several notable cases:

  • Campaign-Related Data Breaches (2024): A potential breach linked to Donald Trump’s campaign emails, allegedly involving foreign entities, exposed sensitive data. This underscores the risks posed by foreign influence operations.
  • National Public Data Leak (2024): A 2024 incident exposed million records, including sensitive information of million U.S. voters, highlighting ongoing vulnerabilities in protecting voter data.
  • RNC Leak (2017): This breach affected millions of voters, exposing personal details like birth dates and political affiliations. The data was used in predictive models, suggesting a risk of similar information being exploited to manipulate voter perceptions in the 2024 race.

These breaches illustrate the persistent risks of data misuse, identity theft, and election manipulation, each capable of eroding public trust in the democratic process.

Global Perspective: Voter Data Leaks Beyond the United States

Although U.S. voter data leaks are the most prevalent, other nations have also experienced significant breaches, especially during election cycles. Notable examples include:

  • Mexico: High-profile breaches occurred in 2017 and 2021, including targeted attacks on political organizations like the Partido Acción Nacional (PAN).
  • Israel: The 2020 elections saw a significant voter data breach, illustrating vulnerabilities even in nations with advanced cybersecurity frameworks.
  • The Philippines and India: The Philippines experienced a leak in 2016, and India faced a breach in 2024, demonstrating that populous democracies remain attractive targets for cybercriminals.
  • Other Nations: Countries like Iraq, Honduras, and Ukraine have also reported voter data breaches, underscoring the global nature of these threats.

Impact and Risks: Manipulating Election Outcomes Through Exposed Voter Databases

Beyond data leaks, the risks extend to manipulation tactics that leverage this exposed information. When voter databases are exposed, the personal and political information they contain can be weaponized to manipulate election outcomes in various ways:

  1. Targeted Disinformation: Threat actors can use leaked data to send misleading messages, such as false voting locations or procedures, potentially causing voters to miss their opportunity to vote.
  2. Voter Suppression Tactics: Leaked data allows cyber actors to discourage specific voters from participating by sending intimidating or misleading messages.
  3. Identity Manipulation for Fraudulent Voting: Using personal details from leaked databases, malicious actors could impersonate registered voters to submit fraudulent ballots or alter voter rolls, causing confusion at polling stations.
  4. Amplifying Polarization: By leveraging insights into voter preferences, cyber actors can create messages that heighten political divisions, influencing voters through emotional manipulation rather than factual discourse.

These tactics threaten not only individual privacy but also the integrity of the election process. When personal information is exposed, it can be used to manipulate voters, distort their perceptions, and ultimately undermine the fairness of the election. This direct impact on voter behavior erodes confidence in democratic institutions and the legitimacy of the results.

Threat Narratives: Misinformation and Disinformation Linked to Voter Data Leaks

Disinformation narratives pose significant threats because they can manipulate public perceptions and erode trust in democratic institutions. Constella Intelligence has identified several such narratives that could shape public opinion on the Dark Web:

  • Electoral Fraud: We have uncovered several threads discussing how leaked voter data could be used to manipulate voter intentions. Some threat actors allege the presence of ‘fake election officials’ in Pennsylvania, the removal of mailboxes in Luzerne County, and reports of ‘a box full of ballots’ discovered in Dade County, Florida. Additionally, claims about the purging of ineligible voters in Oklahoma, including deceased individuals, coupled with a previous voter list leak in the state, raise concerns about potential manipulation of the electoral system. These posts reflect the growing polarization among citizens and contribute to speculation around voter manipulation. However, we have not conducted further investigation into these claims.
  • Political Corruption: False narratives also target political figures, especially Kamala Harris and the Obamas. Harris is accused of plagiarism in her criminal justice book and collaborating with foreign countries to spy on Trump.
  • Russian Disinformation Campaign: The U.S. intelligence community has reported that Russian actors could be actively spreading false information to undermine public confidence in the integrity of U.S. elections, especially in key swing states. This includes creating fake videos and articles suggesting election fraud, ballot stuffing, and cyber attacks in places like Arizona, targeting specific candidates such as Kamala Harris.
  • Deep State: The idea of a ‘deep state’ aiming to control the country and silence opposition is frequently repeated. Steve Bannon, for example, is portrayed as a ‘political prisoner.’ Claims also suggest that this ‘deep state’ controls the media and censors information that could expose its actions.
  • QAnon Conspiracy Theories: Some narratives align with QAnon conspiracy theories, such as mentions of ‘Agenda 47’ and references to Q. These theories, which speak of a satanic cabal controlling the world, are popular among some right-wing groups in the U.S. and often intersect with narratives about electoral fraud and political corruption.

These narratives significantly threaten democratic stability by promoting misinformation, eroding public trust, and influencing voter behavior. Data from voter databases could further be used to create targeted misinformation campaigns, aimed at voters who are already inclined to believe these narratives, thus deepening their impact on democratic processes.

Recommendations for Securing Voter Data and Upholding Electoral Integrity

In response to the rise in voter database breaches, Constella Intelligence recommends proactive measures for citizens to safeguard their data:

  1. Understand Your Digital Footprint: Stay informed about the personal information that is publicly accessible, including voter data and details from breaches like the NPD leak. By being aware of what information is exposed, you can take steps to protect yourself from threat actors who may attempt to exploit this data, especially during sensitive periods like Election Day.
  • Enable Two-Factor Authentication (2FA): Strengthen account security by using 2FA, which makes unauthorized access more difficult.
  • Be Mindful of Social Media Posts: Exercise caution with what you share or read on social media, as AI tools now make it easier than ever to create convincing fake content. Threat actors can exploit personal information or posts to manipulate narratives, spread disinformation, or target individuals during critical times like Election Day.
  • Be Cautious of Phishing Attempts: On Election Day, be especially wary of unsolicited messages claiming to provide election updates or voter information. Avoid clicking on links or downloading attachments, as scammers frequently use these tactics to steal personal data or spread disinformation during critical events like elections.

Stay vigilant against potential threats, from voter data breaches to disinformation, and take steps to protect your personal information. As you head to the polls, remember the importance of safeguarding our democratic process. Enjoy your Election Day, and best wishes to you all, America!

❌
❌