Threat Actors Target US Midterm Elections with Phishing Campaigns and Misinformation
As the November 8 US midterm elections approach, cybersecurity experts warn that numerous foreign and domestic threat actors are attempting to influence the outcome through phishing campaigns and misinformation. The efforts are aimed at sowing distrust in the election process, particularly in battleground states such as Arizona, Ohio, and Pennsylvania. Cybersecurity experts emphasize that the real threat lies in misinformation, which can take many forms and has the potential to alter election outcomes in close contests.
Key Takeaways:
- The most significant risks to the US midterm elections are the compromise of voting machines or associated networks and the manipulation or deletion of voter registration data, according to Karim Hijazi, CEO of Prevailion.
- Hijazi ranks voter machine hacks as a lower probability risk but warns that the possibility should not be dismissed.
- Alex Hamerstone, advisory solutions director at TrustedSec, states that while technical equipment issues can occur, numerous technical protections and safeguards are in place to prevent malicious activity.
- The pool of potential threat actors has broadened, including a range of adversarial nation-states, "frenemy nations," and hacktivist groups.
- Hundreds of groups will likely use phishing-style campaigns to profit from the election, with Hijazi emphasizing the goal of information theft and fraud.
- The FBI and CISA have issued a warning about the possibility of more disinformation from dark web media channels, online journals, messaging applications, spoofed websites, emails, text messages, and fake online personas.
- Three known bad actors have been identified: APT29 (Cozy Bear) attributed to Russia's Foreign Intelligence Service, APT41 (Wicked Panda) associated with Chinese state-sponsored espionage, and LockBit, a globally operated ransomware-as-a-service group.
Statistics:
- Hundreds of groups are expected to engage in phishing-style campaigns during the election.
- The majority of acts of disinformation will be attributed to foreign state level actors and U.S.-based groups.
- Over 90% of attacks on election systems come from phishing emails or texts.