Recent cyberattacks offer lessons for election officials, who can use fast cybersecurity wins and mock elections to prepare. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
ESX News Header

August 5, 2026

TLP:CLEAR

In This Issue:

  • Situation Room: July’s string of cyberattacks on local governments and utilities is a stark reminder that basic cyber defenses are essential for keeping election offices functioning.    
  • Resource Library: First Things First: Cybersecurity Fast Wins and Phishing Threats: Essentials for Safeguarding Election Infrastructure provide simple steps for keeping unauthorized visitors out of your office network.  
  • Planning Desk: Round out your pre-election testing of technologies, systems, and processes with an end-to-end practice run.
Header text: Situation Room

Cyberattacks Knocked Several Local Government Services Offline Throughout July

 

Cyberattacks last month took systems offline at a town in New Hampshire, a county government in Georgia, and more than 30 water and wastewater utilities in Minnesota. A fourth attack hit an internet provider in Maine and cut service to 23 towns, including one town's government offices. The attackers and the targets varied, but staff in all four places had to keep working without the tools they rely on every day.

 

In Milford, NH, the outage took down phones, internet, online payments, and the town clerk's connection to state systems. Because New Hampshire town clerks serve as election officials, the disruption may have impacted election operations. The town is working with forensic specialists to investigate what it describes as a “cybersecurity incident involving unauthorized activity.” In May, a cybersecurity professional pointed out a vulnerability to town leadership, noting a storage device was exposed directly to the internet and urged the town to take it offline. It’s unknown whether that device had anything to do with the outage.

 

In Greene County, GA, initial reports suggested ... READ MORE HERE.

  

The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.

Header text: Resource Library

Cyber Hygiene Resources

 

Cybersecurity doesn’t have to be complicated; secure systems start with simple habits. First Things First: Cybersecurity Fast Wins offers a jumping-off point for daily cyber hygiene with five low-cost, high-impact practices:

  • Password managers keep your login credentials in a protected vault with its own lock.
  • Screen locking can prevent unauthorized access and protect sensitive information from prying eyes.
  • Phishing awareness keeps everyone alert to evolving scams and reinforces reporting habits. The Exchange offers free phishing awareness training written specifically for election staff rather than security specialists.
  • Software updates close security gaps, improve performance, and protect the entire office network.
  • Multifactor authentication (MFA) blocks nearly all account-compromise attempts.

Easy to implement and proven to significantly reduce risk, the guidance also suggests a cost range and trusted products to help you put these practices in place.

 

Keep in mind that firewalls cannot stop phishing attempts because they go straight to your people. Phishing Threats: Essentials for Safeguarding Election Infrastructure highlights key warning signs and offers practical steps to mitigate the threats posed by phishing and other commonly used cyber attack techniques. It covers:

  • Common phishing methods with variations that attackers are using to gain access.
  • Recognizing red flags to look for in a phishing email.
  • Ways to reduce the risk of falling victim to a phishing attempt.

Consider distributing this guide to your staff, or, if you’re a state official, to your local jurisdictions. Following up with a test phishing campaign can be a good way to assess whether staff and local officials are improving their ability to spot phishing attempts before taking the bait.

 

Attackers may not be targeting your office specifically. They scan for unlocked doors. Implement the cybersecurity basics, and do them well, and attackers will move on.

 

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.

Header text: Planning Desk

Week E-13: End-to-End Election Prep and Testing

Part 4: Running a Mock Election

 

Over the last three weeks, we have covered why testing critical election technologies, systems, and processes matters for protecting the integrity and security of data. From software configurations and hardware readiness to post-election workflows and records, functionality and security boundaries must be tested and validated.

 

Once pre-testing of every component is complete and any issues have been addressed, performing an end-to-end “mock election” can provide the final assurance that all technologies, systems, and processes function seamlessly through each stage of the election. Walking through everything needed to conduct an election as one continuous workflow is another chance to verify that documentation is up to date, training has been effective, and protocols are in place to ensure that data integrity is maintained throughout all data transfers and processing that occurs before, during, and after the election.

 

A typical mock election might include:

  • Ballot programming and tabulator configuration
  • Creation of absentee and mailed-ballot lists
  • Creation of voter lists for polling locations and electronic poll books
  • Incorporation of logic and accuracy (L&A) test data to review procedures for data transfer and election night reporting
  • Entry and display of unofficial election night results
  • Reconciliation of ballots, voters, and results
  • Capture and reporting of voter participation information
  • Post-election audits, canvass reports, and certification of the mock election
  • Preparation of storage space and materials needed for record retention

Use a mock election to verify your approach to data integrity and transferring data between election systems, build checklists, and update contact information for key stakeholders and security partners.

 

Election officials considering whether to run a mock election might ask themselves:

  • Have we recently experienced high turnover in our office? This end-to-end test is an opportunity for the entire team to review all procedures and can be a vital practice run for new election officials and new and returning staff and election workers.
  • Have we recently implemented new election systems or changes to processes? A mock election can identify training needs and if systems, processes, and data interactions are not functioning as expected. Issues can be corrected before they surface in real time.

With testing of critical technologies, systems, and processes complete and a mock election that ensures they will work in real time, election officials and their teams can approach each stage of the election with renewed confidence grounded in practice and preparation.

 

The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.

 

 

Header text: Election Security News


Want to get daily updates on election news? Subscribe to electionline.

  • 2026 Minimum Elements for a Software Bill of Materials (SBOM) | Cybersecurity and Infrastructure Security Agency (CISA) (July 29, 2026) // National
  • Attackers are using Microsoft's legitimate login system to camouflage phishing attacks | Help Net Security (July 30, 2026) // National
  • Should you ask AI about voting? Election officials are cautious, but some see opportunity | ABC News (July 28, 2026) // National
  • Experts: Cyberattack on Pennington County likely by foreign adversary | KOTA TV (July 31, 2026) // South Dakota
  • CA man arrested in Scottsdale after postal inspectors catch him stealing mail, election ballots | ABC15 (August 2, 2026) // Arizona

LinkedIn
YouTube
Email
Website

Copyright © 2026 Election Security Exchange. All rights reserved. TLP:CLEAR

 

You are receiving this email because you subscribed to the Election Security Exchange Newsletter.

 

Find this useful? Pass it along and invite other election teams to subscribe.

Subscribe

Election Security Exchange

712 H Street NE, Suite 2456

Washington, DC, 20002, United States

Unsubscribe Manage Preferences