Amid recent ransomware attacks against local governments, US officials fear similar attacks on election databases; CISA to launch a program to help secure them
Christopher Bing / Reuters :
Context & Ripple Effects
The fear is not new: back in 2016, Bruce Schneier argued that recent hacks showed US election systems and voting machines were plausible targets and pressed the government for urgent defensive steps. What changed by 2019 is the attack pattern — ransomware crews had moved down-market into local governments, the same tier of IT where many election databases live.
That makes CISA's new program a direct answer to both threads at once: the ransomware wave hitting municipal networks and the election-security gap flagged years earlier. It also foreshadows the agency's later posture, including its [[a:837780|pilot program warning critical-infrastructure owners about internet-accessible vulnerabilities tied to known ransomware actors]].
First-order effects
- Local election officials gain a federal point of contact for hardening voter-registration and election databases, shifting some of the security burden off under-resourced county IT shops.
Second-order effects
- Ransomware operators who found soft targets in local government (Ryuk's hospital spree showed how lucrative public-sector victims were) now face hardened election databases, pushing them toward less-defended adjacent municipal systems.
Third-order effects
- If the pattern holds, election infrastructure gets treated like other critical infrastructure — with standing federal programs rather than ad-hoc pre-election pushes, a trajectory CISA's later vulnerability-warning pilots and its 2020 election war room confirm.
The trend: US election security is evolving from episodic warnings into permanent federal defense programs, with CISA institutionalizing protection of state and local systems against ransomware.