Hold Fast : Cybersecurity and the Ordinary Voter

By Mary Ellen Callahan

What to Know About Cybersecurity Threats, Scams, and Infrastructure Risk in Elections

In the United States, voter registration information and election results are secure. No cyberattack has ever changed a vote total in a U.S. election. Voting systems are not connected to the internet, paper receipts are common, and dedicated federal, state, and local election officials work hard to keep U.S. elections secure, as they do in every election.

However, decreased federal funding, the loss of many election security advisors at the Cybersecurity and Infrastructure Security Agency (CISA), and a push to share voter information more widely with federal officials have made election information more vulnerable.

While cyberattacks could disrupt voter registration or in-person voting, we all should remain confident that our votes will remain secure. Disrupting an election is not the same as changing the vote count.

Votes and Voter Information

Cybersecurity risks fall into two primary categories: the votes that have been cast, and the voter registration information behind them.

Your vote is well protected because voting machines and counting equipment operate completely offline. While some counties still use cellular modems to transmit unofficial election-night totals, a practice that should end, these transmissions never affect the official count. Looking ahead, AI-fueled threats could increase security risks for voting systems, underscoring why local election officials urgently need more funding and support.

A paper trail for electronic voting systems is the most important safeguard against manipulation. Over 99 percent of U.S. registered voters now use hand-marked paper ballots or ballot-marking devices that produce a human-readable paper record, a relatively recent, and significant, upgrade. That paper is what allows a post-election audit to detect and, if needed, correct a cyber compromise.

Voter registration databases are a significant target for bad actors. Russian and Iranian operatives have tried to infiltrate several states’ voter registration databases over the last few election cycles. These databases often hold sensitive personal information, including driver’s license or Social Security numbers, making them attractive targets for breaches. But none of these hacking attempts on voter databases have resulted in impacts on anyone’s right to vote or otherwise disrupted an election.

It should be noted that personal information in voter registration systems is not uniquely sensitive; if there was a breach of the information, the impact on individual voters would be similar to the widespread data breaches of commercial databases.

The current federal administration is seeking access to state voter registration databases, ostensibly to look for noncitizen voters, despite scant evidence that noncitizen voting is widespread. Sharing this personal information more broadly and cross-referencing it against unrelated databases increases the risk of both data breaches and name mistakes or confusion.

Share

Information Sharing About Cybersecurity Threats

Election officials nationwide are preparing for potential disruptions in elections, including cybersecurity attacks and demands for voter information (According to a recent survey, at least 71 percent of election officials have done some preparation or planning for scenarios that could disrupt election administration). This resiliency planning aims to ensure attacks do not impede voters or prevent a complete, accurate vote count. Many states also require cybersecurity testing of election systems to limit these cyber vulnerabilities.

Cybersecurity attacks could take voter registration portals offline or slow down voter check-in systems on election day, which is why state and local officials must be ready to detect and deter such attacks — and why timely threat information matters so much.

Information sharing between federal, state, and local election agencies has waned over the past two years because of the federal election employee shortage and decreased focus on helping state election officials. If a cyber threat occurs during election season, some jurisdictions may not learn about it in time to respond, which is both a resource problem and a security one.

Misinformation and Disinformation Threaten Voter Confidence

Foreign governments look to influence election results with misinformation and disinformation, even as they cannot compromise election infrastructure directly. AI-generated content has made this material faster and cheaper to produce, so the risk to voter confidence is higher this year and will keep climbing. Voters, not voting systems, are the real target of AI-fueled manipulation.

As an informed voter, learn to recognize false rumors and misconceptions about elections, and check the sources behind what you read. Get your facts from primary sources, and watch for AI-generated disinformation such as deepfake robocalls, videos, and audio impersonating candidates or officials.

What Can You Do to Protect Your Vote and Voter Information

Understand these risks and check now that your voter registration information is correct. Even small discrepancies can cause confusion, and errors are more likely to cause problems if your records are cross-checked against other databases.

  • Fix any name discrepancies well before Election Day. You can check and update your registration at the official federal voter registration site, Vote.Gov

  • Plan extra time at the polls in case cybersecurity issues delay voter check-in.

  • Report suspected election-related scams or disinformation to your state/local election office, or the FBI, and/or CISA.

Leave a comment

Mary Ellen Callahan served as a senior political appointee in the Department of Homeland Security for eight years, most recently as the Assistant Secretary for the Countering Weapons of Mass Destruction Office from 2023-2025. In 2025, she was awarded the Order of the Dragon, Legionnaire Award by the U.S. Army Chemical Corps Regimental Association. She is a member of The Steady State

Founded in 2016, The Steady State is a nonprofit 501(c)(4) organization of more than 400 former senior national security professionals. Our membership includes former officials from the CIA, FBI, Department of State, Department of Defense, and Department of Homeland Security. Drawing on deep expertise across national security disciplines, including intelligence, diplomacy, military affairs, and law, we advocate for constitutional democracy, the rule of law, and the preservation of America’s national security institutions.

Powered by WPeMatico