With 20 weeks to go, now is the time to review overlapping risks between vendor infrastructure failures and the election ecosystem and draft talking points for effective public communications. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
ESX News Header

June 17, 2026

TLP:CLEAR

In This Issue:

  • Situation Room: A follow-up to the recent Canvas breach further informs proactive actions to prevent a vendor compromise from becoming an election crisis. 
  • Resource Library: Examine the common risks shared by the Canvas breach and election administration, along with effective measures for reducing them.  
  • Planning Desk: Prepare your communications plan before your general election busywork begins!   
Header text: Situation Room

Election Ecosystem Takeaways from the Canvas Attack

 

In our June 3 newsletter, we discussed the May 2026 Canvas breach of the education infrastructure through an election security lens, noting its far-reaching implications. The attackers exploited a shared Software-as-a-Service (SaaS) environment and used extortion tactics timed for maximum disruption. SaaS is a common software delivery model where applications are hosted by a service provider (vendor) and made available to customers over the internet.

 

Election officials often depend on such vendor-hosted software solutions shared across the election community and other government sectors whose systems may be interwoven with day-to-day election operations. Dependencies on systems such as email, payroll, VoIP, motor vehicle technologies, GIS or mapping, and court or death records suggest that the attack surface extends beyond election equipment and voting systems. A breach in any of these could have wide-ranging consequences for critical election infrastructure, just as the Canvas breach had for the education sector.

 

For details on defending your ecosystem, review the election parallels highlighted below in the Resource Library section of this newsletter.

 

The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.

Header text: Resource Library

Parallel Election Risks & Practical Mitigations

 

The Canvas breach serves as a warning for election officials. Below, the Exchange draws parallels between the risks presented by the Canvas breach and election administration and offers simple strategies for reducing those risks.

 

Communicate Clearly and Transparently

 

Risk: Login defacements and messaging manipulation created confusion.

 

Parallel Election Examples:

  • Fake voting instructions

  • Compromised election websites
  • Fabricated “official” communications

Mitigation Strategy Suggestions:

  • Have a trusted communication framework with established and verified channels
    • Official website domains
    • Certified social media accounts
  • Publicly educate voters on where to find trusted information
  • Pre-draft messaging for:
    • System downtime
    • Cyber incidents
    • Misinformation events
  • Monitor for domain spoofing and website defacement
  • Use content integrity monitoring and DNS security controls (DNSSEC)

 

Ensure System Redundancy and Backup

 

Risk: Canvas attackers struck during finals week when disruption would be most impactful.

 

Parallel Election Examples:

  • Early voting
  • Election Day
  • Election night reporting

Mitigation Strategy Suggestions:

  • Develop offline contingency procedures
    • Paper pollbooks
    • Manual voter lookup processes
  • Ensure operability without internet-dependent systems
  • Have a “High-Alert Period” security posture
    • Increase monitoring during:
      • 60 days before an election
      • Election week through certification
    • Freeze non-essential system changes during critical periods
  • Avoid tying all processes to a single provider or platform
  • Maintain independent communication channels (e.g., SMS, radio, backup email systems)
  • Regularly test:
    • System backups
    • Data restoration procedures
  • Validate that backups are unchangeable and offline
  • Enforce:
    • Multi-factor authentication (MFA) across all systems
    • Conditional access (location, device)
  • Eliminate shared accounts
  • Limit admin privileges: Only grant administrative rights to a system or resource when they are specifically needed, and only for a short, set amount of time. Then remove those rights automatically.
  • Monitor and log all privileged activity

 REVIEW MORE PARALLEL ELECTION RISKS HERE.

 

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.

Header text: Planning Desk

Week E-20: Developing Your Public Communications Plan

 

In the current environment of heightened scrutiny and increased focus on the election process, it is more important than ever for election officials to have a public communications plan. Clear, consistent, transparent public communication builds trust in the integrity of the process and the results that it produces.

 

In previous newsletters, we discussed developing a media relations strategy and highlighted strategies for communicating during an election incident, both critical elements of your overall communications strategy. However, there is more to public communication than outreach through the media, and your communications plan should be operating all the time, not just in response to an incident.

 

Now is the time to develop your communications plan for the upcoming general election cycle. Consider these five key steps:

 

1. Identify and Coordinate with Partners - Meet in advance with partners who can amplify, validate, and lend authority to your public communications. Examples may include:

  • Internal: jurisdiction leadership, public information officer, law enforcement, IT

  • External: state chief election official, media, political parties, civic organizations, state associations  

Make a list of these partners indicating how, and in what areas, each can help amplify your messaging. At a minimum, establish communication channels and mutual points of contact for each partner. Additionally, consider inviting a representative of each to learn about your process, discuss collaboration, and coordinate messaging.

 

2. Build Your Message and Draft Talking Points - Identify common questions and concerns among the public, common pain points in the process, and security and operational measures you are taking to address them. Examples of talking points and messaging themes can include:

  • Basic information such as when, where, and how voters can cast their ballots.

  • Explanations of confusing or complex parts of the process in advance, such as ballot receipt deadlines and results release schedules.

  • Steps taken to ensure the accuracy and security of elections, such as logic and accuracy testing, ballot reconciliation, and results auditing.

Talking points and messaging themes should be clear and concise. Practice them on someone unfamiliar with the process, and refine them as necessary.

 

3. Plan the ... READ MORE HERE.

 

The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.

Header text: Election Security News


Want to get daily updates on election news? Subscribe to electionline.

  • PRC-linked influence operations are targeting AI debates in the US | OpenAI (June 10, 2026) // International
  • What the Cyber Threat Reports Are Telling Us | Election Security Exchange (June 10, 2026) // National
  • MS-ISAC enters uncertain new era after losing federal funding and thousands of members | Cybersecurity Dive (June 15, 2026) // National
  • How Millions of Digital Home Devices Are Secretly Powering Cyberattacks | The Wall Street Journal (June 15, 2026) // National

LinkedIn
YouTube
Email
Website

Copyright © 2026 Election Security Exchange. All rights reserved. TLP:CLEAR

 

You are receiving this email because you subscribed to the Election Security Exchange Newsletter.

 

Find this useful? Pass it along and invite other election teams to subscribe.

Subscribe

Election Security Exchange

712 H Street NE, Suite 2456

Washington, DC, 20002, United States

Unsubscribe Manage Preferences