CISA, FBI say an Iran-linked APT targeted unsecured state election websites to harvest US voter info used to send threatening emails to some Democratic voters
Iranian Advanced Persistent Threat Actor Identified Obtaining Voter Registration Data Raphael Satter / Reuters : U.S. says Iranian hackers behind threatening emails accessed voter data Alex Turner-Cohen / news.com.au : Proof Iran meddling in US election Sean Lyngaas / CyberScoop : Iranian hackers probed election-related websites in 10 states, US officials say Tweets: Kim Zetter / @kimzetter : Iranian hackers who sent threatening emails to voters *did* breach at least one state's voter reg database to get voter info. Hack involved “the abuse of website misconfigurations and a scripted process using the cURL tool to iterate through voter records” https://us-cert.cisa.gov/... Us-Cert / @uscert_gov : ❗ @CISAgov and @FBI are aware of an Iranian APT Actor targeting U.S. state websites, including elections websites. Read more at https://us-cert.cisa.gov/... to secure voter registration data ASAP. #Cybersecurity #APT #Infosec #Protect2020 #Elections https://twitter.com/... Jim DeFede / @defede : The @FBI announced tonight the Iranians successfully hacked into a state voter registration system. It did not identify the state, but a knowledgeable source briefed on the cyberattack said it was NOT Florida. @CBSMiami @CBSNews https://us-cert.cisa.gov/... Ncsc / @ncscgov : New alert from @CISAgov & @FBI: Iranian Advanced Persistent Threat Actor Identified Obtaining Voter Registration Data. See: https://us-cert.cisa.gov/... https://twitter.com/... Eric Geller / @ericgeller : Iranian hackers tested the defenses of 10 state election offices and were able to steal voter registration data from one due to a “website misconfiguration,” federal officials told their state and local partners today. https://www.cyberscoop.com/... Zack Whittaker / @zackwhittaker : Suspected Iranian hackers have probed the election-related websites of 10 states and, in one case, accessed voter registration data, federal personnel told election security officials on Friday. https://www.cyberscoop.com/...
Context & Ripple Effects
The attribution arc closes here: a week after the intelligence director blamed Iran for threatening emails sent to Florida Democratic voters — initially suggesting the voter information behind them was publicly available — CISA and the FBI now say an Iran-linked APT actually obtained registration data by probing election websites across ten states, exploiting a misconfiguration at least one state site to pull real records.
The detail matters because it upgrades the incident from influence operation to intrusion: unlike the 2016 FBI warning that Arizona and Illinois voter databases had been breached, this time harvested data was weaponized directly against voters before Election Day, with CISA and the FBI naming Iran as the source.
First-order effects
- The ten states whose election websites were probed face immediate remediation pressure to close misconfigurations in their voter-registration portals ahead of the November 3 vote.
- CISA and the FBI shift from general foreign-interference advisories to naming a specific Iranian APT and its access method — website misconfiguration plus scripted harvesting — giving states a concrete patching target.
Second-order effects
- State election offices can no longer argue that exposed registration data is harmless because it is technically public: the demonstrated harvest-to-intimidation pipeline forces them to treat portal security as election integrity, driving emergency audits and hardening budgets.
Third-order effects
- If voter-data exposure keeps converting into targeted voter intimidation — from the 2016 database breaches to this harvest to the later Iran-attributed intrusions into the Trump and Biden-Harris campaigns — federal agencies will keep escalating from alerts toward enforced security baselines for state election systems, a structural push toward centralized standards over state-by-state discretion.
The trend: State-run voter data systems are being pulled from administrative back offices into the national-security perimeter, as adversaries repeatedly convert registration records into coercion tools.