Protect your election site from DDoS attacks now. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
ESX Form Banner

ADVISORY

TLP:CLEAR

September 14, 2026

TL;DR

  • The Threat: A distributed denial-of-service (DDoS) attack overwhelms a website or service with traffic or resource requests, preventing real visitors from accessing it. These attacks do not change votes or steal data, but they can make your site unavailable.
  • Immediate Action: Ask your website or IT provider in writing what protects your website and whether those protections are always running. DDoS protection absorbs the traffic surge. A web application firewall (WAF) limits low-volume attacks targeting connections and underlying infrastructure, such as databases.
  • Broader Risk: Flooding (i.e., driving a lot of traffic to your website) is only part of the problem. The low-volume attacks and quiet attempts to break into election websites are far more common, and frequently occur outside active election seasons. Approximately 90% of floods last 10 minutes or less, so protection should be continuous.
  • Free Protection Available: Two main programs continue to cover election websites at no cost: Cloudflare’s Athenian Project and Google’s Project Shield. Election officials should consider taking advantage of these no-cost protections. Also, many offices already use platforms with built-in protections that simply need to be enabled.

Common Types of DDoS Attacks

Understanding attack types helps you select the right defenses. Both forms aim to disrupt site access.

  • Volumetric Floods (high traffic): Overwhelm the site's resources, preventing legitimate users from accessing the site.
  • Non-volumetric Attacks (low traffic): Target specific pages to overload underlying databases or exploit protocols to stall connections.

What Happened

On August 21, 2026, Cloudflare briefed state and local election officials on data from its latest DDoS threat report. All data referenced here has been anonymized so individual jurisdictions are not identifiable.

 

Between August 2025 and August 2026, these sites received a total of 29.5 billion requests, and Cloudflare blocked 1.5 billion malicious attempts, meaning 5 out of every 100 requests targeting election websites were malicious.

 

Flooding attacks occurred earlier in the cycle than in previous years, peaking about a month before Election Day through the day immediately following. Government websites overall moved from the 29th to the 9th most-attacked industry this year, the largest jump of any sector.

 

Configuration & Fine-tuning

Proper configuration is crucial:

  • Custom Rules: Over two-thirds of blocked activity was stopped by custom WAF rules specifically fine-tuned for that jurisdiction and public-facing pages.
  • Default Rules: Only about one-quarter of all blocks came from default managed rules.

Relying solely on default settings would have allowed most attacks through.

 

State Trends & Examples

  • Large Off-season Flood: A two-day DDoS attack in August 2025 was observed. It peaked at 10.1 million requests, 10x that of any other jurisdiction at the time. This attack occurred completely outside any election window or registration deadline.
  • Registration-timed Flood: Another attack occurred over multiple days in late September 2025 during active voter registration ahead of local elections.
  • Targeted Exploits: A less successful attempt was observed just prior to a jurisdiction’s 2026 primary election; most attempts were successfully blocked by its WAF.

Why This Matters

While public website disruptions do not affect ballot tabulation, they still carry risks:

  • Diminished Communication: If election results pages go dark on election night or sites crash during peak registration, voters, candidates, and media cannot access important information.
  • Misleading Narratives: When official sources become unavailable, unverified claims or misleading narratives take root quickly, potentially leaving you to respond and expend resources for days to come.
  • Erosion of Trust: The public may perceive a website outage as a breach of core operations, causing reputational damage.

      What To Do Now

      • Seek answers from your website or IT provider. Here are some suggested questions to start the conversation:
        • What protections do our websites have, and are they always running?
        • Are all pages covered? If not, which pages are covered, including vendor-hosted pages?
        • What’s the process and expected notification timeline if our site goes down?
        • Is defense automated, or does a human need to update rules manually?
        • Can custom defense rules be configured for specific pages versus others?
      • If you don’t have existing protection, consider two programs supporting election offices for free:
        • Cloudflare's Athenian Project is open to U.S. state, county, and municipal sites tied to election administration, voter data, or reporting results.
        • Google's Project Shield covers election information sites. Apply at g.co/shield. Google replies only to applicants who qualify, so no reply means no.
      • List every public page you own. Results pages and ballot trackers often live with a different vendor, outside whatever protects your homepage.
      • Tailor defensive rules by need. Apply specific protections by page type, such as rate-limiting search tools, automating bot checks (CAPTCHAs), and setting WAF rules on data-entry forms to block malicious attacks.
      • Create a backup plan. Social accounts, local radio, your public information officer, printed handouts at the polls. Write it down before you need it.

        Resources

        • Cloudflare: Cloudflare DDoS Threat Report H1 2026

        • Cloudflare: Athenian Project

        • Google: How to apply for Project Shield

        • Exchange: First Things First: Website Security Fast Wins for Election Offices

        • OWASP Foundation: OWASP Top 10:2025

        • CISA: No Downtime in Elections: A Guide to Mitigating Risk of Denial-of-Service

        LinkedIn
        YouTube
        Email
        Website

        Copyright © 2026 Election Security Exchange. All rights reserved. TLP:CLEAR

         

        You are receiving this email because you subscribed to the Election Security Exchange Alerts & Advisories.

         

        Find this useful? Pass it along and invite other election teams to subscribe.

        Subscribe

        Election Security Exchange

        712 H Street NE, Suite 2456

        Washington, DC, 20002, United States

        Unsubscribe Manage Preferences