Defense Secretary Pete Hegseth issued a September 22 memorandum directing U.S. Cyber Command and the Defense Intelligence Enterprise to prioritize detection, collection, analysis, and response against foreign threats to the 2026 U.S. elections. The order characterizes election protection as a “no-fail mission,” directs Cyber Command to employ its existing authorities against prospective foreign cyberattacks, and calls for coordination with the Department of Homeland Security; it does not identify adversaries, provide new resources or deadlines, or confirm use of the former NSA–Cyber Command Election Security Group.
The directive restores Defense Department emphasis on an enduring mission previously supported by the joint USCYBERCOM–NSA Election Security Group, which identified adversary activity, shared intelligence with public- and private-sector partners, and disrupted operations targeting democratic processes. It arrives amid reductions and reorganizations of election-security and foreign-influence programs at the FBI, ODNI, and CISA. CISA has released an election-security plan centered on regional advisers and a threat-sharing platform, while officials face growing concern that AI may let foreign actors scale cyber-enabled influence campaigns.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
CISA released an election-security plan identifying its 10 regional directors as election-security advisers and providing a free threat-sharing platform for election officials, state intelligence hubs, and federal partners.
Defense Secretary Pete Hegseth signed a memorandum directing U.S. Cyber Command and the Defense Intelligence Enterprise to prioritize foreign threats to the 2026 elections. The directive calls for election-threat intelligence collection, use of Cyber Command's existing authorities against potential foreign cyberattacks, and coordination with DHS.
NSA and U.S. Cyber Command stood up their joint Election Security Group again to align intelligence sharing, domestic defense support, and disruption of foreign election threats.
The Department of Homeland Security designated election security as a critical-infrastructure component.
An ODNI overhaul shifted many Foreign Malign Influence Center responsibilities to other offices; ODNI later assigned two officials to coordinate election-threat intelligence.
The administration reorganized intelligence-community coordination of foreign-influence work and reduced election-security support at CISA.
The second Trump administration dismantled the FBI's Foreign Influence Task Force as part of changes to federal foreign-influence and election-security efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcensa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.