Cybersecurity and Elections: Repeating Past Loopholes in the 2020 U.S. Presidential Election?

Introduction

Cybersecurity is commonly understood as ‘defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.’ However, cybersecurity threats involve far more things than just hacking personal identity or national classified information. It also includes more subtle strategies to derail various processes using the help of digital technology: in the context of political elections, examples are the manipulation of the election result and cyber attempts to smear a candidate’s campaign, among others.  Right now, the United States is gearing up to conduct their 2020 Presidential Election. As the stakes are high for one of the most globally influential states globally, cyber threats are considered one of the issues to look out for, especially learning from the 2016 election. This commentary discusses the ways cybersecurity threats manifest in election processes in the United States and what can be done to anticipate them.  

Cybersecurity Concerns and Why Are They Dangerous

There are many methods of cyber disruptions to electoral processes. First, disinformation and hoaxes—two things that have always existed during the election and especially the campaign phase regardless of the medium. With digital technology and platforms that facilitate a rapid flow of information, disinformation spreads quicker and becomes more potentially damaging. Regarding this, the propensity for smear campaigns through cyber methods is even bigger considering social media is the second most popular source of election news to United States citizens, after cable T.V. news[i]. While disinformation can seem harmless towards people who are already educated, they also have the prospensity to wrongly influence voters’ decisionmaking process. In the 2016 election, disinformations range from assertions that Hillary Clinton ran a pedophile ring, her having Parkinson’s disease, to her arming ISIS.[ii]

Disruptions during candidates’ campaign also happen through malicious emails. Just on the day of 2020’s first presidential debate, tens of thousands of emails sent asked recipients to volunteer for the Democratic Party ahead of the November U.S. election. These came from email scammers and carry malicious software: the Word document attached to the spam contains small programs known as macros that, if enabled by the recipient, install a password-stealing program known as Emotet[iii]. However, on attacks such as this, the main motivation is not politics but rather money. This shows how election, with its many forms of campaigns, creates opportunities for scammers to launch cyber attacks for their own benefits.

For this year’s U.S. elections, FBI has warned that cybercriminals will attempt to spread misinformation about the election results. Along with CISA, the two agencies stated that cybercriminals might create fake websites or alter existing ones, and create and share corresponding social media content in an attempt to discredit the electoral process. There have also been accusations towards Russian lawmaker, Andrii Derkach, about misinformation attempts about Joe Biden[iv]. This aspect is also related to how foreign interference issues are amplified because of the existence of digital technology that can be used as a tool of cyber-attacks.

The issue of voter suppression is also frequently discussed in relation to cyber-attacks in elections. In the 2016 election, the Trump campaign was accused of suppressing three voting blocs using “dark ads” strategy, including by targeting negative Hillary Clinton ads towards specific demographics, including 3.5 predominantly Black voters.[v] These ads can also be placed through social media, making use of their algorithms. Hence, cybersecurity nowadays doesn’t only include outright attacks or violations, but how to disrupt political processes by taking advantage of digital technology. Despite the vast consequences of this strategy, using targeted ads that contain specifically disadvantageous information or history about a candidate is not illegal. This point also shows how new campaign strategies that are made feasible by the existence of digital technology are often unlawful. Still, current laws and regulations aren’t able to encompass them yet.

There are also more clear-cut cyberattack methods, such as voters’ data hacking and vote tabulation interference. Regarding the former, there have been cases where voters were turned away at the polls due to the non-synchronized voters’ data. For example, in Riverside Country, an investigation by the district attorney determined that dozens of people’s voter records had been tampered with by hackers. Following this, a cybersecurity company found a software flaw in Riverside County’s voter registration lookup system, which it believes could have been the source of the breach[vi]. On the other hand, vote tabulation interference is often attributed to foreign interference, such as the 2016 scandal of Russian government interference in Trump’s win. However, interference by hacking into election databases can also happen without it. Even if these hacks are not successful, attempted attacks on election infrastructure could be used to gather information about the system and about vulnerabilities that will be used in a future election to penetrate the system and change votes or change vote tallies[vii]. Regarding this, a new hope for a fairer election in 2020 arises since The House approved legislation that would make hacking federal voting systems a federal crime[viii].

Conclusion

From these examples, it can be understood that there are many forms of cyber attacks towards the election process, starting from the campaign phase until the tabulation. Not only potentially jeopardizing technical aspects of election, cyber attacks can also derail the fairness of the election. For example, spreading disinformation and hoaxes about candidates might lead to defamation, not to mention manipulating the voters to choose based on wrong information. As technological advancement progresses, challenges to the values of democracy and democratic elections expand too. A true and fair democratic election should be able to minimize the flow of misinformation and hoaxes about either of the candidates. The result of the election reflects what the majority wants. Hence, it can be concluded that in the context of political elections, awareness of cybersecurity issues is not only meant to protect oneself from personal data breaches through online activities but also to maintain the democratic quality of said election itself.

The novelty in these cyber threats isn’t only about the media used, but also how there is a lack of legal instruments and mechanisms that can categorize which acts of those strategies are illegal, so that interference such as these can be given repercussions. To anticipate and avoid cyberattacks in the 2020 U.S. election, the government needs to create a concise and transparent mechanism of sanctions for online defamation and disinformations done by the campaign team or even the candidate themselves. Not only that, there must be an investment in better cybersecurity protection, including software and networks, to curb the possibility of hacking federal voting systems. This needs an active role by institutions such as Homeland Security’s Cybersecurity and Infrastructure Security Agency as well as state governments. Finally, civil society needs to be more vigilant now than ever: since voters can access information directly, self-education is important. These can be achieved by taking measures such as fact-checking incoming information, increasing digital literacy, and not limiting oneself to social media’s ‘echo chamber’ where one-sided information leads to hoaxes about the opposite sides result to polarizations are prone to happen.


[i] Jeffrey Gottfried, M.B., 2020. Where Americans Are Getting News About the 2016 Presidential Election. Available at: https://www.journalism.org/2016/02/04/the-2016-presidential-campaign-a-news-event-thats-hard-to-miss/ [Accessed October 14, 2020].

[ii] Kamarck, E., 2019. Political campaigns are the first line of defense in election security. Brookings. Available at: https://www.brookings.edu/blog/fixgov/2019/08/29/political-campaigns-are-the-first-line-of-defense-in-election-security/ [Accessed October 14, 2020].

[iii] Mann, J., 2020. Ahead of U.S. election, a malicious email campaign mimics Democratic pitches for volunteers. Reuters. Available at: https://uk.reuters.com/article/us-usa-election-cybercrime/ahead-of-u-s-election-malicious-email-campaign-mimics-democratic-pitches-for-volunteers-idUSKBN26N03J [Accessed October 14, 2020].

[iv] Aratani, L., 2020. FBI warns ‘foreign actors’ likely to spread misinformation on election results. The Guardian. Available at: https://www.theguardian.com/us-news/2020/sep/23/us-election-result-misinformation-fbi-warning [Accessed October 14, 2020].

[v] Ibid.

[vi] Dilanian, K., 2020. U.S. patchwork of state, county election computer networks still vulnerable to cyberattacks. NBC News. Available at: https://www.nbcnews.com/politics/2020-election/u-s-patchwork-state-county-election-computer-networks-still-vulnerable-n1241337 [Accessed October 14, 2020].

[vii] Ibid.

[viii] Miller, M., 2020. House approves legislation making hacking voting systems a federal crime. The Hill. Available at: https://thehill.com/policy/cybersecurity/517462-house-approves-legislation-making-hacking-voting-systems-a-federal-crime [Accessed October 14, 2020].