/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US says Russia-linked group targeted IT systems used by state and local officials, but there was no evidence “integrity of elections data has been compromised”

It's no secret that the hacking group often referred to as Energetic Bear or TEMP.Isotope — linked by multiple security firms …

CyberScoop Sean Lyngaas

Context & Ripple Effects

This attribution lands three years after reporting that [[a:919711|Russia's cyber operations against the US electoral system reached voter databases and software in 39 states]] — a much larger footprint than initially acknowledged. It also extends Energetic Bear's own file: within a day of this disclosure, officials connected the same group to an intrusion at San Francisco International Airport, showing the unit operating well beyond electoral targets.

First-order effects

  • State and local election officials get an explicit federal assurance — no evidence elections data integrity was compromised — while simultaneously learning their IT environments were in scope for a named Russian military-linked group.

Second-order effects

  • Energetic Bear's appearance on both airport systems and election-adjacent state networks pushes other critical-infrastructure operators to treat the group's tradecraft as a shared threat model rather than an election-cycle problem.

Third-order effects

  • If the pattern from the 2017 voter-database reporting through today holds, Russian intrusion activity against US election infrastructure becomes a recurring, attributed backdrop to every cycle — normalizing public attribution-with-assurance disclosures as a standard federal response.

The trend: Russian state-linked hacking groups are diversifying from direct attacks on voter databases toward broader state and local government infrastructure, with the US responding through rapid public attribution paired with integrity assurances.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    BREAKING: U.S. administration officials have been watching Russia's FSB penetrate state and local systems in recent weeks and believe they have pieced together Russia's plans for election interference. https://www.nytimes.com/... It is far worse than Iran. w/ @julianbarnes @Sange…
  • @mollymckew Molly McKew on x
    This seems more serious than some spoof emails https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    The group, believed to be a unit of the FSB, known as “Energetic Bear” or “Dragonfly,” is the same group that has been caught breaking into American nuclear, water, power plants and airports. See our previous reporting on this actor: https://www.nytimes.com/...
  • @nedfoley Ned Foley on x
    1/2 Most worrisome sentence: “The officials fear that Russia could change, delete or freeze voter registration or pollbook data, making it harder for voters to cast ballots, invalidating mail-in ballots or creating enough uncertainty to undermine results.” https://www.nytimes.com…
  • @davidcorndc David Corn on x
    This is what Trump does not want you to know. Russia is again attacking a US election to help him. https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    CISA confirms our reporting. Says Russian unit has “has targeted dozens of SLTT government and aviation networks..successfully compromised network infrastructure, and as of Oct. 1, exfiltrated data from at least two victim servers.” https://us-cert.cisa.gov/...
  • @joycewhitevance Joyce Alene on x
    Last night's rush-rush press conference seemed tailored to a narrative that benefited Trump. Now, we learn more of the truth. We need a POTUS who will lead an all-of-government effort to protect our elections from foreign interference, not one who is wrapped up in self interest. …
  • Vox Sara Morrison on x
    What we know about Iran and the threatening “Proud Boys” emails
  • @cenkuygur Cenk Uygur on x
    Ratcliffe's assertion that Iran wanted to hurt Trump by sending anti-Biden emails makes no sense but neither does idea that Iran would send any anti-Biden emails when they hate Trump. How sure are officials Ratcliffe is not 100% lying and that the emails came from Iran at all? ht…
  • @josephfcox Joseph Cox on x
    New: we've published a redacted version of the interference video that allegedly Iran sent to U.S. voters while posing as the Proud Boys. Idea is to show what a foreign interference operation looks like. Spoke to multiple people whose data was included https://www.vice.com/...
  • @dnvolz @dnvolz on x
    Two officials told me Ratcliffe made an analytical leap saying Proud Boys email spoofing was intended to harm Trump and said it was aimed at undermining public confidence. A third official said the claim was backed by specific intelligence. https://www.wsj.com/...
  • @tedlieu Ted Lieu on x
    I've concluded this hastily arranged press conference was a desperate attempt by @DNI_Ratcliffe to change the subject. Iran's emails tell Dems to vote FOR Trump. Also, you know who can get voter registration information? You can. Basically anyone; all you need is to pay a fee. ht…
  • @benyt Ben Smith on x
    Oh man https://twitter.com/...
  • @natashabertrand Natasha Bertrand on x
    Ratcliffe then says Iran has been inciting social unrest and trying to damage Trump, despite WaPo reporting that Iran was targeting *Democrats* and threatening them if they didn't vote for Trump. https://www.washingtonpost.com/ ...
  • @nicoleperlroth Nicole Perlroth on x
    Ratcliffe could have said: -Iran is trying to undermine confidence in the election. -Iran has also been trying to hack the Trump campaign for more than a year. Instead Ratcliffe said: Iran's Proud Boys disinfo campaign was designed to harm Trump. https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Someone calling themselves “Proud Boys” is sending threatening emails to Florida voters who are registered as Democrats. We obtained one of the emails and talk to one of the people who got them. Scoop by @misstessowen and me. https://www.vice.com/... https://twitter.com/...
  • @joelockhart Joe Lockhart on x
    Ratcliffe's job tonight was to give @realDonaldTrump an excuse not to accept the election results.
  • @npr @npr on x
    Voters in Alaska and Florida have reported receiving emails threatening them to “vote for Trump or else!” — prompting investigations in both states. Cybersecurity experts say the origin is unclear and may be the product of a foreign disinformation effort. https://www.npr.org/...
  • @jason_koebler Jason Koebler on x
    SCOOP: Included in the threatening ‘Proud Boys’ emails sent to voters was a video suggesting a larger, more organized disinfo campaign. Method showed in video won't work, designed to sow fear and distrust of the system https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    SCOOP: Some emails allegedly from “Proud Boys” far-right group also included a video of hackers using voter registration data to print absentee ballots. The video is highly suspicious a voting security expert called it “just bullshit fear mongering.” https://www.vice.com/... http…
  • @josephfcox Joseph Cox on x
    New: some of those threatening voter emails also included an elaborate video. Shows an alleged hacker breaking into a database of voter information, and using it to fill out a ballot. But it is highly suspicious, and voter fraud scheme unlikely to work https://www.vice.com/...
  • @yashar Yashar Ali on x
    I think it's important to always be skeptical and want to learn more but also don't treat Iran as some fair actor in all of this...you'll be doing their bidding Iran LOVES to do stuff like this and while this isn't sophisticated, Iranian intelligence is among the best at cyber. h…
  • @yashar Yashar Ali on x
    U.S. government concludes Iran was behind threatening emails sent to Democrats The deceptive campaign made use of a Internet domain associated with the far-right Proud Boys https://www.washingtonpost.com/ ...
  • @joelockhart Joe Lockhart on x
    Iran endorses Trump. Russia endorses Trump. Saudi Arabia endorses Trump. Hillary Clinton has no chance of winning. https://twitter.com/...
  • @repdeanphillips Rep. Dean Phillips on x
    Interfering in an American election is an act of aggression and must result in consequences if we hope to protect the integrity of our electoral system. The Trump Administration is responsible for defending us against threats both foreign and domestic, and I hope it will. https:/…
  • @hayesbrown Hayes Brown on x
    Okay so they say both Russia and Iran have obtained Democratic voter lists. And both plan on using this information to influence the election. But it's definitely Iran behind the Proud Boys email. Okay. https://www.nbcnews.com/...
  • @gregmitch Greg Mitchell on x
    Ratcliffe of course IDs Iran as interfering in election for Biden, and refuses to label Russia for Trump. He's a total tool so take this accordingly.
  • @evanchill Evan Hill on x
    Fifteen million hacked Florida voter records have been posted on a Russian forum, and voters in the state are now receiving (apparently faked) threatening messages from “Proud Boys” sent through an Estonian IP: https://www.vice.com/... https://twitter.com/...