Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-diplomatic-threatstate-sponsored-espionageai-enabled-threat-activityidentity-impersonation-fraud

US Cyber Operations Disrupted Election Interference as Federal Defenses Were Cut

Updated 28d agoFirst seen May 25, 202611 sources

US Cyber Command and the NSA have repeatedly used covert cyber operations to blunt foreign election interference, including ejecting Iranian hackers from a municipal website used to post unofficial 2020 results before false information could be spread and disrupting Russian influence operators targeting voters ahead of the 2024 election. Officials said the 2020 intrusion did not affect voting, ballot tabulation, or certified results, and described the broader mission as a joint effort with CISA, the FBI, DHS, and other agencies to counter cyberattacks, troll farms, fake websites, and AI-enabled propaganda tied to Russia, Iran, China, North Korea, and non-state actors.

At the same time, the US government has reduced parts of the election security apparatus built after 2016. Reporting says the Trump administration put CISA election security staff who worked with states on leave and dismantled or downsized programs across ODNI, the FBI, the State Department, and CISA that tracked and exposed foreign influence campaigns. Current and former officials warned that the cuts weaken coordination with state and local election officials, reduce visibility into ongoing threats, and leave the country less prepared for future elections even as harassment of election workers and concern over the safety of cyber personnel have pushed agencies to keep some leadership roles out of public view.

Share:
US Cyber Operations Disrupted Election Interference as Federal Defenses Were Cut
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
Jan 28, 20265mo ago

Reports warn election protections were gutted after 2024 cycle

By January 2026, CNN reported that many federal programs built since 2016 to counter foreign election interference had been dismantled, downsized, or deprioritized, including functions at ODNI, the FBI, the State Department, and CISA. Current and former officials warned the cuts reduced visibility into Russian, Chinese, and Iranian threats ahead of the 2026 midterms.

Cyber Command disrupts Russian influence operators before 2024 election

Before the 2024 U.S. election, U.S. Cyber Command carried out a secret operation against at least two Russian companies allegedly running covert influence campaigns in six swing states using anti-Ukraine propaganda. A source said the action slowed Russian activity, though the operators continued producing content through Election Day.

Feb 20, 20251y ago

Report says Trump administration dismantles foreign influence defenses

A New York Times report described the Trump administration as dismantling parts of the U.S. government's effort to counter foreign influence operations. The article pointed to reductions affecting multiple agencies involved in election interference monitoring and response.

Feb 10, 20251y ago

CISA election security staff working with states are put on leave

The U.S. cyber agency placed election security staffers who had worked with state officials on leave. The move marked a concrete rollback of federal election security support structures.

Mar 27, 20242y ago

NSA and Cyber Command revive election security group for 2024 cycle

By March 2024, the joint NSA-Cyber Command Election Security Group was active again ahead of the 2024 U.S. election. Officials kept current leaders unnamed due to safety concerns and highlighted threats from Russia, China, North Korea, Iran, and AI-enabled influence operations.

Apr 24, 20233y ago

Hartman publicly discloses 2020 Iranian election-site intrusion

At the RSA Conference, Maj. Gen. William Hartman revealed that Iranian hackers had accessed a U.S. municipal website reporting unofficial 2020 election results and that Cyber Command had removed them. He said the case showed how offensive and defensive cyber teams coordinated to protect election-related systems.

Nov 18, 20215y ago

US indicts Iranian hackers over 2020 Proud Boys voter intimidation emails

The U.S. Justice Department indicted two Iranian nationals for their alleged roles in a 2020 cyber-enabled influence operation that sent spoofed Proud Boys emails to intimidate Democratic voters and undermine confidence in the U.S. election. The case marked a formal law-enforcement response to Iran's election interference activity.

US indicts Iranian hackers for Proud Boys voter intimidation emails
Apr 13, 20215y ago

Cyber Command operation evicts Chinese hackers from Microsoft attack servers

In 2021, U.S. Cyber Command conducted an operation to remove Chinese hackers from servers being used in attacks exploiting Microsoft email software. Maj. Gen. William Hartman later cited it as one of many overseas cyber operations against foreign adversaries.

Jan 1, 20215y ago

CISA shares hacked federal server images with Cyber Command

After the 2020 election period, CISA provided forensic images from hacked federal servers to U.S. Cyber Command. The material supported overseas operations and intelligence collection on Russian espionage tactics.

Dec 19, 20206y ago

Krebs says SolarWinds hack should not be conflated with voting security

Following disclosure of the SolarWinds compromise, former CISA director Chris Krebs publicly warned against conflating that espionage campaign with election system security. His comments reinforced that 2020 voting infrastructure had not been shown to be altered by the hack.

Nov 1, 20206y ago

US Cyber Command removes Iranian hackers before disinformation could spread

U.S. Cyber Command discovered the Iranian intrusion into the municipal election-results site and kicked the actors off before they could use it to spread false information. The incident was later cited as an example of coordination between Cyber Command and CISA to protect election infrastructure.

Apr 18, 20197y ago

Mueller report says Russian troll farm organized dozens of US rallies

Public reporting on the Mueller investigation said Russia's Internet Research Agency organized dozens of rallies in the United States as part of its influence campaign. The disclosure added detail on how Russian online interference extended into real-world political events.

Mueller identified ‘dozens’ of US rallies organized by Russian troll farm
Jul 17, 20188y ago

Election Security Group formed to counter Russian interference

U.S. Cyber Command and the NSA created the Russia Small Group in 2018 to counter Russian election interference. The task force later evolved into the broader Election Security Group focused on multiple foreign threats.

Iranian hackers access municipal election-results website

During the 2020 U.S. election, Iranian hackers accessed a municipal website used to report unofficial election results. Officials said the intrusion did not affect voting, vote tabulation, voter data, or certified ballot counts.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.