Sources show election security company VR Systems' use of remote-access software may have opened gap for hackers to tamper with NC voter data in 2016
Kim Zetter / Politico :
Context & Ripple Effects
VR Systems was already under a cloud: Mueller's investigation suggested the small Florida vendor had been hacked by Russia, making it a potential weak link in US election integrity. The new reporting sharpens that worry from suspicion to mechanism — sources say the company's own remote-access software may be what let attackers reach North Carolina voter data in 2016.
The remote-access question has a paper trail. Election Systems and Software contradicted earlier statements and admitted to Sen. Wyden that some voting systems sold between 2000 and 2006 carried a remote-access feature, so VR Systems would not be the first vendor caught between sales claims and security reality.
First-order effects
- North Carolina's voter-registration data moves into the 'possibly altered' column alongside the broader theft-and-tampering pattern TIME reported in 2016, forcing state officials to decide whether a forensic review of their 2016 systems is warranted.
- VR Systems faces direct reputational and contractual exposure with every state customer, since the reported vulnerability sits in software the vendor itself operated rather than in county networks.
Second-order effects
- Other election vendors come under the same disclosure pressure ES&S felt after Wyden's inquiry, with buyers likely demanding written confirmation that remote-access features are absent or disabled before renewal.
- The finding feeds the unresolved question from the scant forensic investigations across at least 21 targeted states — each new mechanism identified gives those states a specific artifact to hunt for, raising the cost of leaving 2016 unexamined.
Third-order effects
- If remote-access tooling keeps surfacing as the entry path, election security regulation shifts from securing state networks to policing the vendor layer itself — auditing what small contractors install and how they maintain it, a structural change the largely unchanged infrastructure of 2018 suggests has not yet happened.
The trend: Election-security scrutiny is migrating from breached state voter networks up into the small vendor layer that connects them, where undisclosed remote access can quietly span many states at once.