US cyberwarriors thwarted 2020 Iran election hacking attempt

Apr 25, 2023, 1:16 PM

FILE - In this image provided by U.S. Cyber Command, Army Major Gen. William Hartman, commander of ...

FILE - In this image provided by U.S. Cyber Command, Army Major Gen. William Hartman, commander of U.S. Cyber Command's Cyber National Mission Force, speaks during a ceremony at U.S. Cyber Command headquarters at Fort George E. Meade, Md., on Dec. 19, 2022. Before the 2020 presidential election, Iranian hackers broke into to a system used by an unidentified local government to support its election night operations but were kicked out before any attack could be launched, according to U.S. military and cybersecurity officials. (U.S. Navy Chief Petty Officer Jon Dasbach/U.S. Cyber Command via AP)
Credit: ASSOCIATED PRESS

(U.S. Navy Chief Petty Officer Jon Dasbach/U.S. Cyber Command via AP)

Iranian hackers broke into to a system used by a U.S. municipal government to publish election results in 2020 but were discovered by cyber soldiers operating abroad and kicked out before an attack could be launched, according to U.S. military and cybersecurity officials.

The system involved in the previously undisclosed breach was not for casting or counting ballots, but rather was used to report unofficial election results on a public website. The breach was revealed during a presentation this week at the RSA Conference in San Francisco, which is focused on cybersecurity. Officials did not identify the local government that was targeted.

“This was not a system used in the conduct of the election, but we are of course also concerned with systems that could weigh on the perception of a potential compromise,” said Eric Goldstein, who leads the cybersecurity division at the U.S. Cybersecurity and Infrastructure Security Agency.

If not expelled from the site, the hackers could have altered or otherwise disrupted the public-facing results page — though without affecting ballot-counting.

“Our concern is always that some type of website defacement, some type of (denial of service) attack, something that took the website down or defaced the website say on the night of the election, could make it look like the vote had been tampered with when that’s absolutely not true,” Major Gen. William J. Hartman, commander of U.S. Cyber Command’s Cyber National Mission Force, told conference attendees Monday.

Hartman said his team identified the intrusion as part of what he termed a “hunt-forward” mission, which gathers intelligence on and surveils adversaries and criminals. The team quickly alerted officials at the U.S. cybersecurity agency, who then worked with the municipality to respond to the intrusion.

Hartman said his team then acted “to ensure the malicious cyber actor no longer had access to the network and was unable to come back into the network in direct support of the elections.”

No details were released on how or from what country the Iranian intrusion was detected.

Its successful thwarting highlights the stealthy, largely classified, efforts of U.S. military cyberwarriors to prevent a repeat of 2016, when a Russian hack-and-leak operation targeting Hillary Clinton’s campaign favored former President Donald Trump’s election.

Asked in a recent interview about his accomplishments since he was promoted to U.S. Cybercom and National Security Agency chief in 2018, Gen. Paul Nakasone pointed to election security.

“We said if you are going to come and try to influence or interfere in our elections, we’re going to take you on, and we did,” he said.

Election and national security officials have been increasingly focused on cybersecurity threats since the 2016 election. Locally, they have been trying to heighten protections for voting machines, vote tabulators, voter registration databases and electronic pollbooks, which are used to check in voters at polling locations.

Some of the non-voting systems present security challenges because they have internet connections. As the use of electronic systems has grown, they have proved an attractive target for those seeking to meddle in elections.

In 2016, Russian hackers scanned state voter registration systems looking for vulnerabilities and accessed the Iranian hackers obtained confidential voter data and used it to send misleading emails, seeking to spread misinformation and influence the election.

Beginning in 2018, the National Defense Authorization Act let the U.S. “take down infrastructure” and “take on adversaries” outside the country, Nakasone said. So by 2020, when Russian and Iranian actors attempted to interfere with the U.S. election, U.S. cyber operators were able to thwart them, he added.

Under Nakasone, Cybercom has sent small teams to 22 countries to help hunt on their networks — “to identify malware, tradecraft, techniques that adversaries are using and then broadly publicize that,” he said. That includes Ukraine, where he said a team arrived on Dec. 3, 2021, more than two months ahead of the Russian invasion.

In a March statement ahead of a congressional hearing, Nakasone said Cybercom had deployed its teams 40 times to work on 59 networks, generating insights and “imposing costs on common adversaries.” He said the missions “exposed malicious cyber activity by China, Russia, Iran and cyber criminals,” helped make other nation’s networks more secure and “led to the public release of more than 90 malware samples for analysis by the cybersecurity community.”

___

Cassidy reported from Atlanta. Bajak reported from Boston.

National News

FILE - Attorneys and criminal justice advocates stand outside Louisiana's Supreme Court on May 10, ...

Associated Press

Historic acquittal in Louisiana fuels fight to review ‘Jim Crow’ verdicts

NEW ORLEANS (AP) — Evangelisto Ramos walked out of a New Orleans courthouse and away from a life sentence accompanying a 10-2 jury conviction, thanks in large part to the landmark U.S. Supreme Court decision bearing his name. Ramos v. Louisiana outlawed nonunanimous jury convictions as unconstitutional, with justices on the 6-3 majority acknowledging the […]

1 day ago

Associated Press

Pay per wave: Native Hawaiians divided over artificial surf lagoon in the birthplace of surfing

EWA BEACH, Hawaii (AP) — Brian Keaulana is the quintessential Native Hawaiian waterman, well-known in Hawaii and beyond for his deep understanding of the ocean, gifted with surfing and lifeguarding skills passed down from his big-wave rider father. Now, as one of the islands’ standard-bearers of surfing, Keaulana wants to further boost the sport in […]

1 day ago

FILE — A man checks his footing as he wades through the Morris Canal Outlet in Jersey City, N.J.,...

Associated Press

As rising oceans threaten NYC, study documents another risk: The city is sinking

NEW YORK (AP) — If rising oceans aren’t worry enough, add this to the risks New York City faces: The metropolis is slowly sinking under the weight of its skyscrapers, homes, asphalt and humanity itself. New research estimates the city’s landmass is sinking at an average rate of 1 to 2 millimeters per year, something […]

1 day ago

This undated photo shows the late Army Cpl. Luther H. Story. The Army said Friday, May 19, 2023, th...

Associated Press

‘He’s home’: Missing 73 years, Medal of Honor recipient’s remains return to Georgia

SAVANNAH, Ga. (AP) — Soldiers of the 9th Infantry Regiment made a desperate retreat as North Korean troops closed in around them. A wounded, 18-year-old Army Pfc. Luther Herschel Story feared his injuries would slow down his company, so he stayed behind to cover their withdrawal. Story’s actions in the Korean War on Sept. 1, […]

1 day ago

A skeleton in sunglasses sits beside a sign reading "Just waiting for the insurance check," outside...

Associated Press

Struggles continue for thousands in Florida 8 months after Hurricane Ian as new storm season looms

FORT MYERS BEACH, Fla. (AP) — Eight months ago, chef Michael Cellura had a restaurant job and had just moved into a fancy new camper home on Fort Myers Beach. Now, after Hurricane Ian swept all that away, he lives in his older Infiniti sedan with a 15-year-old long-haired chihuahua named Ginger. Like hundreds of […]

1 day ago

President Joe Biden speaks in the Roosevelt Room of the White House, Sunday, May 28, 2023, in Washi...

Associated Press

Takeaways on debt ceiling: McCarthy’s balancing act, Biden’s choice and the challenges ahead

WASHINGTON (AP) — It’s a deal no one in Washington claims to really like. But after weeks of negotiations, President Joe Biden and House Speaker Kevin McCarthy have struck an agreement to raise the debt ceiling and avert a potentially devastating government default. The stakes are high for both men — and now each will […]

1 day ago

Sponsored Articles

Internet Washington...

Major Internet Upgrade and Expansion Planned This Year in Washington State

Comcast is investing $280 million this year to offer multi-gigabit Internet speeds to more than four million locations.

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.

SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!

safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.

Comcast Ready for Business Fund...

Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.

US cyberwarriors thwarted 2020 Iran election hacking attempt