Hackers Target Election Systems in 20 US States


The US government has formally accused Russia of hacking the Democratic party’s computer networks and said that Moscow was attempting to “interfere” with the US presidential election.

The Russians have every reason to sabotage the Democratic candidate. Her opponent, Donald Trump, is more pro-Russia than any previous presidential candidate.  

As far back as 2007, Trump was telling CNN that Russian President Vladimir Putin was doing a “great job.” In 2013, Trump tweeted: “Do you think Putin will be going to The Miss Universe Pageant in November in Moscow, if so, will he become my new best friend?” In 2015, Trump told MSNBC that Putin was a real leader, “unlike what we have in this country,” and that reports of Putin killing political opponents didn’t bother him, “Well, I think our country does plenty of killing also,” he said.

Trump repeatedly says he would “get along very well with” Putin. In return Putin has praised Trump as “bright and talented.” Trump positively glows as he repeats reports that “Putin likes me.”

The Trump-Russia links beneath the surface are even more extensive, as Franklin Foer has shown in Slate. Trump has sought and received funding from Russian investors for his business ventures, especially after most American banks stopped lending to him following his multiple bankruptcies. 

Trump’s de facto campaign manager, Paul Manafort, was a longtime consultant to Viktor Yanukovich, the Russian-backed president of Ukraine who was overthrown in 2014. Manafort also has done multimillion-dollar business deals with Russian oligarchs.

Hillary Clinton and US officials have blamed Russian hackers for stealing more than 19,000 emails from Democratic party officials, but this announcement marked the first time that the Obama administration has pointed the finger at Moscow.

Based on the scope and sensitivity of these efforts, that only Russia’s senior-most officials could have authorized these activities,” said the office of the director of national intelligence and the Department of Homeland Security (DHS) in a joint statement.

The accusation marked a new escalation of tensions with Russia and came shortly after the US secretary of state, John Kerry, called for Russia to be investigated for war crimes in Syria.

Vladimir Putin’s spokesman dismissed the accusation as “rubbish.”

“Every day Putin’s website gets attacked by several tens of thousands of hackers. A lot of these attacks are traced to the territory of the USA, but we do not blame the White House or Langley each time,” he told the Interfax news agency.

The White House declined to say whether the formal attribution would trigger sanctions against Russia.

The US agencies said that some US states had detected attempts to breach their election systems, and that most of those attempts originated from servers operated by a Russian company. “However, we are not now in a position to attribute this activity to the Russian Government,” the statement said.

The agencies said that the “decentralised nature” of the US voting systems, as well the lack of connectivity between voting machines themselves, would protect against Russian-sponsored electoral tampering. 

But they urged states across the country to seek additional cybersecurity aid from the DHS. Recently, the homeland security secretary, Jeh Johnson, said that 21 of the 50 states in the US had sought to improve cybersecurity at the voting booth thus far.

How does a Hack happen?

The question on the mind of many voting security experts is not whether hackers could disrupt a US election. Instead, they wonder how likely an election hack might be and how it might happen.

First of all, there are technology challenges, more than 20 voting technologies are used across the country, including a half dozen electronic voting machine models and several optical scanners, in addition to hand-counted paper ballots.

But the major difficulty of hacking an election is less a technological challenge than an organisational one, with hackers needing to marshal and manage the resources needed to pull it off, election security experts say. And a handful of conditions would need to fall into place for an election hack to work.

Many US voting systems still have vulnerabilities, and many states use statistically unsound election auditing practices, said Joe Kiniry, a long-time election security researcher.

The US Department of Homeland Security is urging state and local election officials to seek assistance from the federal government to fend off cyberattacks that could be used to manipulate the results of the November presidential elections.

The agency is ready to provide any assistance to help states secure their systems, if they request it, Jeh Johnson, the secretary of homeland security, said in a statement recently. Threats are rising that criminals will use cyberattacks to try to disrupt the administration of US elections, the agency said.

“These challenges aren’t just in the future, they are here today,” Johnson said in the statement. “In recent months, malicious Cyber-actors have been scanning a large number of state systems, which could be a preamble to attempted intrusions. In a few cases, we have determined that malicious actors gained access to state voting-related systems.”

There have been hacking attempts on election systems in more than 20 states, far more than had been previously acknowledged, a senior Department of Homeland Security official has told NBC News on late September.

The "attempted intrusions" targeted online systems like registration databases, and not the actual voting or tabulation machines that will be used on Election Day and are not tied to the Internet.

The DHS official described much of the activity as "people poking at the systems to see if they are vulnerable."

"We are absolutely concerned," the DHS official said. "The concern is the ability to cause confusion and chaos." 

Only two successful breaches have been disclosed, both of online voter registration databases, in Illinois and Arizona over the summer. While those two hacks were linked to hackers in Russia, the DHS official did not say who was responsible for the other failed attempts, noting that "we're still doing a lot of forensics.” Meanwhile, intelligence officials tell NBC News there is now "no doubt" the Russian government is trying to influence the election.

Classified material, prepared for briefings of Donald Trump and Hillary Clinton and examined by NBC News, reveals that officials have drawn "direct links" between Vladimir Putin's government and the recent series of hacks and leaks. The secret material confirms what lawmakers on the Senate and House Intelligence Committees said they had concluded recently, based on briefings they received.

"At the least, this effort is intended to sow doubt about the security of our election and may well be intended to influence the outcomes of the election, we can see no other rationale for the behavior of the Russians," Sen. Dianne Feinstein and Rep. Adam Schiff, said in a statement.

For weeks, American officials have been saying that Russian intelligence agencies were behind hacks into the DNC, state election databases and other political entities, but they weren't definitive about the motive since nations routinely hack into their adversaries' political organisations to gather information for spying purposes.

Here are three Election Hacking Scenarios:

1.    An attack on DREs that depends on physical access in the weeks leading up
to the election.

This attack would involve hackers actually infiltrating election teams or depending on poor physical security surrounding voting machines. In the years of the DRE rush following the 2000 election, many voting security experts showed a host of vulnerabilities that depended largely on physical access to the machines.

This is a potential attack vector that would likely involve a fairly large number of sneaky conspirators who don’t get caught.

Given all those potential problems, this attack is probably unlikely. It’s an "unsophisticated version" of an election hack, said Free and Fair's Kiniry.

2.    An attack on DREs during software updates.

This is a more likely scenario than No. 1. While DREs aren’t supposed to be connected to the internet during an election, many DRE models get software updates through network connections.

A lack of an internet connection on Election Day does not make DREs "immune to internet hacking," because of their election management systems [EMSes], Jones said. A "clever hacker" could inject malware into DREs during the process used to load ballots and other election configuration information, he said.

The basic pre-election checks in many states might not find the malware, he added. "Malware can be made that triggers only on the first Tuesday after the first Monday of November in an even-numbered year," he said. "Malware can be made to trigger only if the polls are open for longer than six hours. Malware can be made to trigger only if the machine is used by more than 25 voters."

Unplugging DREs from the Internet is a "red herring," Kiniry added. "The threat vectors on DREs and similar equipment -- as shown many times by security researchers -- are manifold," he said. "Installing malware in an EMS over the 'Net and then having that EMS infect a ballot definition file written on a USB stick or DVD is totally a thing."

3.    Finally, the goal of some hackers may be to raise doubts about the election results, instead of swinging the election for one candidate.

This is the scariest potential attack because the hackers would need to compromise just one election system in one jurisdiction, and it wouldn't need to be in a swing state or affect the outcome of the election.

With recent attacks on the Democratic National Committee, some US law enforcement authorities have accused Russian hackers of trying to influence the election. Republican Trump has suggested that if he loses in November, the election will be "rigged."

A close election is needed for hackers "only if you are looking to actually change the outcome," Kiniry said. "If all you want to do is cast doubt on the outcome, it doesn't matter if it is a landslide for Clinton or a squeaker for Trump, you just do a hack or two and reveal it to the media after-the-fact."

Hackers could also tamper with election registration lists to raise questions, Jones added. Or they could release forged emails that make it appear the election was hacked.

"If I were Vladimir Putin or the kind folks in North Korea, I wouldn't really care who won the election, what I'd want to do is delegitimise the election," he added. "To do that, you don't need to successfully hack it, you just need to create the widespread impression that it has been hacked."

Information-Management

 

« Cyber Security & The US Presidential Race
What Does Brexit Mean For British Data Privacy? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Source Defense

Source Defense

Source Defense provides websites with the first ever prevention technology for attacks of third-party origin.

Ubiq Security

Ubiq Security

Ubiq has developed a software solution that secures any type of data, on any device, anywhere, with nearly no impact to system performance or user experience.

Bottomline Technologies

Bottomline Technologies

Bottomline Technologies is an innovator in business payment automation technology, helping companies make complex business payments simple, smart and secure.

Excelerate Systems

Excelerate Systems

Excelerate Systems is a leading provider of IT services with a focus on Big Data, Cloud Services and Security.

Sysdig

Sysdig

With Sysdig teams find and prioritize software vulnerabilities, detect and respond to threats, and manage cloud configurations, permissions and compliance.

IBLISS Digital Security

IBLISS Digital Security

How cyber-resilient is your business now? We help companies to continuously answer this never-ending C-level question.

APERIO

APERIO

APERIO, the global leader in industrial data integrity, helps its customers drive profitability and sustainability while mitigating risk in their industrial operations.

Zuratrust

Zuratrust

Zuratrust provide protection for all kinds of email related cyber attacks.

ITRenew

ITRenew

ITRenew is a leading global IT lifecycle management solutions company, specializing in onsite data center decommissioning and data erasure services.

IoT M2M Council (IMC)

IoT M2M Council (IMC)

The IMC is the largest and fastest-growing trade organisation in the IoT/M2M sector.

The Cyber AB

The Cyber AB

The Cyber AB is the official accreditation body of the Cybersecurity Maturity Model Certification (CMMC) Ecosystem.

Conatix

Conatix

Conatix was formed to apply recent advances in AI and other fields of technology to insider fraud, one of the most intractable problems in cybersecurity.

OwnZap Infosec

OwnZap Infosec

OwnZap Infosec aims to digitally shield the cyberspace by offering services like Penetration Testing and Red Teaming, Infrastructure Security Testing, and Vulnerability Assessments.

Advent One

Advent One

Advent One are recognised for solving intricate dilemmas, not only making technology work but building foundations that customers can grow upon in an effective and secure way.

Wadilona Cyber Securities

Wadilona Cyber Securities

Wadilona Cyber Securities' sole aim is to bring and secure Information and Communications Technology (ICT) to and work for humans in its simplest terms.

Pointsharp

Pointsharp

Pointsharp delivers software and services that help organizations secure data, identities, and access in a user-friendly way.