Election Officials Warn of Widespread Suspicious Email Campaign
Security officials worry that local election representatives might be susceptible to online trickery
Local U.S. election officials have been receiving suspicious emails that appear to be part of a widespread and potentially malicious campaign targeting several states, according to a private alert about the activity.
In some of the emails, the sender impersonated state election directors and asked that the voting officials click on a link to receive special two-factor authentication hardware, the Elections Infrastructure Information Sharing and Analysis Center, an information sharing group for election officials, said in the alert Friday.
While tricking users into clicking malicious links is a technique commonly used to hack into computer systems, the group, known as the EI-ISAC, didn’t find malicious links or attachments in most of the email samples it analyzed.
Other emails deemed suspicious by the EI-ISAC purported to be from people with disabilities looking for ways to vote from home. “Some of these emails were designed to mimic standard correspondence that election officials would expect to receive…which increases the risk that an official might click a malicious link,” the alert said.”
Election officials began reporting the messages to the EI-ISAC, a partnership launched in early 2018 to help the federal government quickly communicate with all 50 states and thousands of election jurisdictions across the country, on Oct. 15, according to the alert, which was viewed by The Wall Street Journal.
“While these phishing messages appear to be part of a widespread campaign, the source and motive remain unclear,” the alert said.
The email campaigns described in the alert haven’t been linked to any nation-state activity and didn’t appear to be especially coordinated or sophisticated, a person familiar with the matter said.
The EI-ISAC sent the alert as a reminder to local election officials to be hypervigilant about cybersecurity, the person said. The group, the person said, decided it was a prudent step after some states observed officials clicking on suspicious emails when they should be more alert to such threats this close to the election.
“Some states are reporting that they are seeing their locals [are] less aware of these threats,” the person said.
In July, the security vendor Area 1 Security Inc. examined the email security of more than 12,000 local officials and found that more than half of them used email systems with limited protection from phishing attacks.
Cybersecurity alerts such as the one sent Friday are regularly delivered to the EI-ISAC, which is run by the Center for Internet Security, which receives funding from the Department of Homeland Security. The group has grown quickly since formally launching in 2018 and boasts thousands of members.
The Cybersecurity and Infrastructure Security Agency, which coordinates election security with the EI-ISAC, didn’t immediately respond to a request for comment. A spokesman for the EI-ISAC said the group doesn’t discuss specific cases or members.
Last week, John Ratcliffe, the director of national intelligence, said that Iran was responsible for a barrage of emails sent to Democratic voters in multiple states that purported to be from a far-right group and were intended to intimidate voters and incite social unrest ahead of the presidential election. The disclosure refocused attention on how foreign adversaries are attempting to interfere in U.S. politics after Russia disrupted the 2016 election. Iran denied the allegations.
U.S. security officials have said states have improved their cyber defenses since Russian hackers probed election systems across the country four years ago.
Over the past few weeks, U.S. officials have issued a steady drumbeat of security alerts designed to share information about attackers and warning officials of emerging threats.