Newsletter: Issue 33
Published: September 23, 2026
In this issue:
- Situation Room: The frequency of DDoS attacks on government websites increased more than in any other sector in the past year.
- Resource Library: First Things First: Website Security Fast Wins for Election Offices describes five free-to-low-cost “fast win” actions to strengthen website security now.
- Planning Desk, E-6: Prepare now to effectively respond to and reduce the impact of false information generated by AI.
Situation Room
When the Website Goes Down: DDoS and Election Offices
A distributed denial-of-service attack, or DDoS, is a malicious attempt to flood a website, server, or network with fake traffic to disrupt service, overwhelm a system, or cause it to slow down or crash. Election-related websites can be prime targets for DDoS attacks.
On election night, people go to the results page. During peak registration, they go to the site to register to vote or verify their status. When the site goes dark, voters, candidates, and reporters may look elsewhere; unverified claims can fill the gap, and your office can spend days afterward correcting them.
On August 21, 2026, website security provider Cloudflare briefed state and local election officials on what it has seen across election websites over the past year. Between August 2025 and August 2026, those sites received 29.5 billion requests. Cloudflare blocked 1.5 billion of them as malicious, about five of every 100. Government websites moved from the 29th most-attacked industry to the ninth, the largest jump of any sector.
Three findings are particularly helpful in informing how your office plans.
- Floods of web traffic are short: about 90% last 10 minutes or less. That is not enough time to turn on DDoS protection after an attack starts, so it has to be running already.
- Low-volume attempts aimed at specific pages and the databases behind them are far more common than floods, and they often show up outside election season, so protection cannot be seasonal either.
- Default settings are not enough. Over two-thirds of what Cloudflare blocked was stopped by rules written for each jurisdiction’s own pages, while the default rules that come with the service accounted for only about a quarter of blocked attempts.
The Exchange published an advisory covering DDoS attack types, what Cloudflare’s data showed, and steps you can take now to mitigate the impact on your jurisdiction. Start by reviewing the advisory with your IT and website administrators or providers and asking the suggested questions.
It’s important to understand what protects your sites and whether those protections are always running. If there is nothing in place, two programs protect election websites at no cost: Cloudflare’s Athenian Project and Google’s Project Shield. It’s not too late to prepare and protect your election websites!
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.
Resource Library
First Things First: Website Security Fast Wins For Election Offices
As Election Day draws closer, voters and the general public increasingly rely on election websites for critical information across all phases of the election – registration, ballot tracking, polling place location, and results reporting. As your most public-facing asset, your website also becomes a valuable target. Whether it is DDoS, defacement, or any other form of compromise, a website attack is not just a technical problem; it is a public trust problem.
The Exchange’s new First Things First: Website Security Fast Wins for Election Offices describes five free-to-low-cost “fast win” actions to strengthen website security. Many of these recommended actions can still be taken now and have a meaningful impact this election cycle:
- Establish a Trusted Online Presence: A .gov domain and HTTPS encryption work together to ensure visitors to your site know they can trust the information they find.
- Enroll in Free DDoS Protection: Enrollment in a free DDoS protection service can be done in less than an hour.
- Control Who Has Access to Your Site: Multifactor authentication (MFA) paired with an updated access list and a firm off-boarding process removes the most common avenues for unauthorized access.
- Monitor Your Website for Problems: Free monitoring and change detection services are available now to alert you when your site is down or content has been altered.
- Prepare Your Incident Response Plan: Prepare now to enable clear, factual, early communication in the event of an incident, before inaccurate information has a chance to fill the void.
Each section of the guide describes actionable next steps, including links to recommended services and resources, as well as “Quick Checks” you can use to assess your current state of website security preparedness.
Additional Resources:
- Google: How to apply for Project Shield provides free DDoS protection using Google Cloud infrastructure for qualifying election organizations.
- OWASP Foundation: OWASP Top 10:2025 is a standard awareness document for developers and web application security, representing a broad consensus about the most critical security risks to web applications.
- CISA: No Downtime in Elections: A Guide to Mitigating Risk of Denial-of-Service offers proactive steps for election officials and election technology providers to reduce the likelihood and impact of denial-of-service incidents, including DDoS attacks and non-malicious service interruptions.
The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.
Planning Desk
Week E-6: Assembling an Approach When Responding to False Narratives
A few issues ago, we looked at how AI could be used against election offices: harassment campaigns that can easily scale, impersonation of officials through cloned video or audio, and seemingly realistic images or videos that seek to spread mistrust by depicting officials engaged in misconduct or manipulating results. The end result is the same; actors will try to drive a divisive wedge between election officials and the electorate.
We also covered two signals, watermarks and provenance, that can help you tell what’s authentic. While imperfect, they offer a tool for your toolbelt.
However, knowing the threats and detection signals only gets you halfway there. What should happen when something surfaces that’s not correct or is depicting fraud that never occurred? Similar to equipment testing, an effective response depends on planning and preparation in advance, and that includes having a written communication and incident response plan.
Consider the following steps to improve your readiness to respond to AI-generated deception aimed at your office:
- Tell your story (pre-bunking). We’re listing this first because it is one of the most important things you can do. Your voice is a source of truth, and carries the most weight during contentious and highly scrutinized moments. Explain to the public how diligently you prepare to maintain safe, secure, and free elections. The more you do this in advance of a potentially misleading narrative, the more likely your neighbors and electorate will recognize something as false and know where to turn for true information. Highlight official channels as much as possible.
- Leverage a workgroup. We’re big proponents of working with election security partners. So much so, we built a product around it. These partners can be resourceful when triaging inauthentic content, crafting messaging around your security safeguards, and helping to amplify accurate messaging, whether during an incident or in advance of one. Bottom line, these are trusted partners to support the work you’re doing.
- Build a habit of monitoring your online presence. Someone on your staff should be regularly checking what’s circulating about your office. This is a good practice for seeing how your messaging appears on search engines and social media platforms. You may also catch and correct false narratives before they take root. The U.S. Alliance for Election Excellence has a checklist on low-tech options for monitoring your name space.
- Verify before you amplify. Watermark and provenance tools may indicate something is amiss, but it shouldn’t be treated as a complete signal. Similarly, even if tools report something as clean, attempt to verify it through alternative sources to help determine if it is authentic.
- Triage when necessary. Triage is not a one-size-fits-all approach, and the situation will dictate the response. It is perfectly acceptable to let minor things go if responding may have more drawbacks than benefits, such as a post with limited reach. However, if something raises a potential safety concern, escalate it quickly, whether to HR, a safety coordinator, or a direct line to local law enforcement.
- Align internally before you speak. With a nod toward your key partners, ensure everyone is on the same page before you officially respond. Make sure all partners work from one set of facts and that there is one primary spokesperson, even if the situation dictates a fast response. Otherwise, varying statements may slow response and dilute the facts.
- Build relationships with local influencers and the media. Researchers have demonstrated that local, less-politicized voices often land better than others. Knowing local influencers and media representatives can help amplify the right information and push back against misleading narratives. Elections are a community affair by nature, so don’t be afraid to pull in members of the community to help your office.
- Reflect and learn. Following an incident, an intentional debrief and reflection period can identify what worked well, what didn’t, and where you can improve. Your plan should improve over time as you refine the process.
The use of generative AI to spread false information about elections and election officials is a reality that is not going away. Taking the steps above can reduce the negative impact of this activity and maintain your reputation as the trusted source of election information when it is needed most.
The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.
Election Security News
Want to get daily updates on election news? Subscribe to electionline.
