The FBI and CISA warned that foreign actors and cybercriminals could use online journals, pseudo-academic websites, spoofed domains, fraudulent email accounts, and DDoS attacks to spread false election information and erode confidence in the 2020 U.S. election. The agencies said attackers were likely to amplify claims about voter suppression, ballot fraud, cyberattacks on election infrastructure, and other narratives designed to portray the election as illegitimate, while lookalike websites and emails could also be used to steal credentials, harvest personally identifiable information, and deliver malware.
U.S. officials said cyber threats to election infrastructure could cause localized delays or disrupt access to public-facing voting information, but were not assessed as capable of preventing voting or altering ballot integrity or vote tallies. They emphasized that safeguards such as provisional ballots, paper backups, backup pollbooks, and alternative communication channels limited the impact of incidents, while later reporting indicated Russia did not mount a major interference campaign on the scale of 2016, despite continued lower-level influence efforts and persistent concern that uncertainty around vote counting and result reporting could be exploited to fuel post-election confusion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
The FBI and CISA issued a joint warning that spoofed election-related internet domains and email accounts could be used by foreign actors and cybercriminals to spread false information, steal credentials and personal data, and deliver malware. The advisory urged voters to verify website and email spellings and rely on trusted sources for election information.
The FBI and CISA issued a public announcement warning that foreign-backed online journals, including pseudo-academic sites, could be used to spread misinformation and disinformation about the 2020 U.S. elections. The agencies said such narratives could include claims about voter suppression, cyberattacks, or ballot fraud intended to undermine confidence in the election.
The FBI and CISA warned that DDoS attacks against election-related public-facing websites could slow or disrupt access to voting information and unofficial results, but would not prevent eligible voters from casting ballots or compromise ballot integrity. They also cautioned that cyber actors could falsely claim such attacks affected voting systems.
The FBI and CISA issued a joint alert warning that false claims about hacked voter information or compromised election systems were likely intended to cast doubt on the legitimacy of U.S. elections. The agencies said they had no information that cyberattacks had prevented elections, altered voter registration accuracy, stopped registered voters from voting, or compromised ballot integrity.
The FBI and CISA announced that cyber threats to election infrastructure could cause temporary disruptions or delays but were not assessed as capable of preventing voting or changing vote tallies in the 2020 elections. They said observed attempts had been localized, blocked, minimal, or easily mitigated.
Several U.S. government agencies issued a warning that foreign entities could use disinformation to create confusion and discord around the 2020 U.S. election, including by manipulating communications about election activity and results. The warning emphasized that attackers might exploit delays and uncertainty without compromising election systems directly.
The U.S. intelligence community publicly assessed in August that Russia was using a range of measures primarily to denigrate Joe Biden and the anti-Russia establishment. William Evanina also publicly identified Andriy Derkach as spreading unfounded corruption claims about Joe Biden.
During Ukraine's 2014 presidential election, election authorities were reportedly disrupted and official election-result announcements were interdicted. The case was cited as an example of attackers targeting election communications rather than altering vote totals directly.
U.S. officials said Russia failed to mount any major hacking or disinformation operation against the 2020 U.S. presidential election at the scale seen in 2016, and Kremlin hackers did not significantly target election systems. Officials and analysts attributed this in part to Cyber Command and NSA actions, stronger election security, and Russia's own cost-benefit calculations.
The U.S. Treasury Department sanctioned Andriy Derkach and described him as an active Russian agent. The Washington Post reference cites this as part of the lower-level Russian influence activity seen during the 2020 election cycle.
8 references tracked. Mallory keeps watching after this page renders.
washingtonpost.com
Open sourceic3.gov
Open sourceic3.gov
Open sourceic3.gov
Open sourceic3.gov
Open sourceic3.gov
Open sourcepylos.co
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.