www.infosecurity-magazine.com 25 Sept 2026, 12:30 UTC

CISA Warns Election Systems Face Breaches Ahead of 2026 Midterms

CISA Warns Election Systems Face Breaches Ahead of 2026 Midterms

THE US Cybersecurity and Infrastructure Security Agency (CISA) has published an Election Infrastructure Security Plan ahead of the 3 November 2026 midterm elections. The plan offers guidance to state, local, tribal, territorial and federal bodies on mitigating cyber and physical threats to election infrastructure, including polling places, storage facilities, vote-tabulation sites, voter-registration databases, voting machines and systems used to manage elections and report results. CISA warned that these assets could be targeted to manipulate voting systems or steal sensitive information.

The agency identified vulnerability exploitation, attacks on statewide voter-registration databases and insider threats as key risks. Election infrastructure is often connected to wider enterprise networks, allowing attackers to exploit known vulnerabilities and move laterally. CISA said voter-registration databases in all 50 states have been targeted, with confirmed breaches in at least 20 states over the past decade.

It recommended multifactor authentication, phishing-resistant protection for privileged accounts, continuous monitoring, anomaly detection and comprehensive logging. The plan also supports paper ballots, bipartisan ballot handling, observers during counting and chain-of-custody procedures to reduce technical and insider risks.

CISA highlighted no-cost, voluntary services including tabletop exercises, penetration testing, workshops, vulnerability and web scanning, its Known Exploited Vulnerabilities catalogue, regional security advisers and threat-intelligence sharing through fusion centres. The plan follows concerns about reported 2025 cuts to CISA and the termination of federally funded support for the Election Infrastructure Information Sharing and Analysis Center. On 3 September 2026, Senator Alex Padilla and Representative Joe Morelle urged the administration to restore that funding.

View full article

Article by CyberSIXT