Russian Active Measures Campaigns and Interference in the 2016 U.S. Election, Volume 1: Russian Efforts Against Election Infrastructure

on

The Senate Intelligence Committee found that Russian government-linked hackers scanned election systems in at least 21 states, and probably all 50, and breached voter registration systems in two, but saw no evidence that any votes or tallies were changed, while warning that weak coordination, thin state defenses, and paperless machines left the country exposed. Assistance from Claude AI.

Key Takeaways:

  • Russian government-directed activity against state and local election systems began in at least 2014 and ran into at least 2017.
  • Scanning was the most widespread activity. DHS first identified 21 states, later concluded all 50 were probably scanned, and found no pattern in the targets.
  • Illinois was breached through SQL injection in June 2016. Attackers accessed up to 200,000 records in a database covering about 14 million voters, and voter data was taken.
  • The Committee found no evidence that votes, tallies, or registration records were changed, but it says its own insight and the intelligence community’s is limited.
  • Russia’s goal is unclear. It may have been positioning for later action, gathering intelligence, or seeking to undermine public confidence.
  • Warnings in 2016 lacked context and often never reached election officials. Some states did not know they had been targeted until 2017.
  • DHS had few resources to offer at first, and its critical infrastructure designation caused friction with states. Trust and participation improved by 2018.
  • Paperless voting machines, aging equipment, and a shrinking vendor pool remain serious risks.
  • The Committee recommends paper ballots, statistically sound audits, stronger state cybersecurity, better information sharing, deterrence, and more funding.
  • Senator Wyden argues for mandatory national standards, and Senators Harris, Bennet, and Heinrich call for legislation, including paper ballots in all federal elections.

Summary:

In July 2019 the Senate Select Committee on Intelligence released the first of five volumes of its bipartisan investigation into Russian interference in the 2016 election. This volume, heavily redacted, examines Russian efforts against state and local election infrastructure and how governments responded. States are identified only by number.

The Committee found Russian government-directed activity beginning in at least 2014 and continuing into at least 2017. Scanning of election-related websites, mostly between June and September 2016, was the most widespread activity. After an FBI alert on August 18, 2016 listing suspect IP addresses, DHS identified 21 states whose networks touched those addresses. Neither DHS nor the Committee found a pattern to the targets, and DHS later judged that all 50 states were probably scanned, though the government relied heavily on states to self-report. Some attempts used SQL injection, which tricks a website’s database into running malicious commands; one state reported roughly 1,500 attempts from a single address.

The Committee confirmed actual access in two states. In Illinois, attackers used SQL injection on June 23, 2016, entered a voter registration system covering about 14 million voters, viewed multiple tables, and accessed up to 200,000 records. The data taken included names, addresses, partial Social Security numbers, birth dates, and driver’s license or state ID numbers. Officials noticed only on July 12, after unusual data spikes, and took the system offline the next day; the attackers kept hitting it about five times a second until mid-August. DHS attributes the intrusion to Russia with high confidence. The second state’s access is largely redacted. A separate State 4 breach, involving phished credentials, was ultimately judged criminal rather than Russian.

The Committee saw no evidence that votes were changed, tally systems manipulated, or registration data altered or deleted, and none of the compromised systems counted votes. It stressed, however, that its insight and the intelligence community’s was limited. Russia’s purpose remains unclear: it may have been probing for later use, gathering intelligence, or seeking to undermine confidence simply by being discovered. Former officials described scenarios such as scrambling voter-roll addresses to create Election Day chaos.

The report faults the warnings. State IT staff treated the FBI and multi-state alerts as routine, and few passed them to election officials. Some states first learned they were among the 21 from press coverage or hearings, and several issued statements saying they were not targeted. DHS had only four or five teams able to help, and states resisted its August 2016 idea of designating election systems as critical infrastructure, which took effect in January 2017. By October 2018, 35 states had signed up for DHS scans, and Congress had appropriated $380 million for election security.

On machines, testimony and hacking-conference research showed serious vulnerabilities, particularly in paperless equipment. As of November 2016, five states used only paperless machines and nine others used some.

Recommendations include keeping states in charge of elections, deterring attackers, better threat sharing and security clearances for state officials, two-factor authentication, sensors and backups for registration systems, paper ballots, post-election audits, resisting online voting, and more funding. Senator Wyden dissented from the emphasis on state primacy, arguing for mandatory national standards and giving little weight to the no-changed-votes finding because of data gaps. Senators Harris, Bennet, and Heinrich endorsed the findings but urged legislation, including paper ballot requirements.

Citation:
United States Congress. Senate Select Committee on Intelligence. Russian Active Measures Campaigns and Interference in the 2016 U.S. Election, Volume 1: Russian Efforts Against Election Infrastructure. 116th Congress, 1st session, Senate Report 116-XX, 25 July 2019, www.intelligence.senate.gov/sites/default/files/documents/Report_Volume1.pdf.