US officials and cybersecurity firms looking for evidence of foreign interference say Russian hackers mostly sat on the sidelines during the midterm elections
U.S. officials and cybersecurity firms cite a number of reasons 2018 wasn't like 2016 — SAN FRANCISCO—After unleashing … Tweets: @dnvolz and @brianstelter Tweets: Dustin Volz / @dnvolz : Russia mostly skipped the midterms, but no really knows why. Meanwhile, alarm grows that Trump is doing more to undermine confidence in American democracy than Moscow could ever hope to achieve by repeatedly deriding Florida recounts as corrupt exercises. http://www.wsj.com/... Brian Stelter / @brianstelter : Quote of the day via this WSJ story titled “Russian Hackers Largely Skipped the Midterms, and No One Really Knows Why.” Clint Watts: “What could the Russians possibly do to distort things even more than what Americans are already doing?” http://www.wsj.com/...
Context & Ripple Effects
This story closes one loop opened in 2016, when the FBI began investigating the suspected Russian hack of the DNC and its WikiLeaks email trove, and deepened when sources reported the intrusion was broader than known — including stolen voter records and at least one successful data alteration. Weeks before these midterms, reporting showed voting infrastructure still largely unchanged despite those warnings, setting up 2018 as the test case.
It didn't come: officials and cybersecurity firms found Russian hackers largely on the sidelines, and — as Dustin Volz's framing captures — no one can yet say whether that reflects deterrence, changed Russian calculus, or something else. The ambiguity matters because the same officials warn the underlying vulnerabilities flagged in 2017 were never fixed.
First-order effects
- US officials and cybersecurity firms are left without a confirmed explanation for Moscow's restraint, which complicates their ability to claim credit for deterrence or to model what Russia does next.
- Per the Volz tweet cited in the piece, Trump's repeated deriding of the Florida recounts as corrupt is doing more damage to confidence in American democracy than Russian interference managed in 2018.
Second-order effects
- With the 'why' unanswered, the pressure shifts to hardening before 2020 — though later reporting finds the post-2016 security response still judged inadequate even as Russian tactics evolve.
- The quiet cycle feeds a competing narrative by 2020, when officials credit pre-emptive steps by US Cyber Command for the absence of a crippling attack on election infrastructure — a causal claim this 2018 non-event makes harder to verify.
Third-order effects
- If the pattern holds, election security settles into a recurring cycle where penetration of voter-registration networks persists beneath calm election days, leaving structural vulnerability intact regardless of any single cycle's outcome.
- Domestic rhetoric about election legitimacy becomes a rival threat vector to foreign hacking itself, pushing the policy debate beyond infrastructure toward confidence in the count.
The trend: US election security is becoming a cycle of attributed attacks and unexplained pauses, where defensive posture and domestic rhetoric shape perceived integrity as much as adversary behavior.