
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The Cybersecurity and Infrastructure Security Agency goes into detail on efforts to secure voting registration bases in a recently published guide targeted at state and local election officials, as the agency unveiled an election infrastructure security plan less than six weeks to go before Election Day.
Summary
“State and local election officials must prioritize enhanced defenses to protect voter registration databases, and to limit the ways that compromised data can be exploited,” CISA writes in a 11-page guide on addressing threats to statewide voter registration databases. The guide was initially prepared in July 2026 but formally published on Sept. 24 when CISA rolled out a new election infrastructure security plan .
The guide was included in a footnote in the plan and quietly made available under CISA’s resources and tools webpage . A report providing lessons learned from CISA’s election security activities from 2019 to 2024 was also quietly published Sept. 24 on CISA’s website.
CISA’s new guidance comes as the Trump administration has taken renewed interest in election integrity activities ahead of the November midterms, with a focus on mail-in ballots and collecting voter rolls. Prior to the new push, the White House proposed major cuts to CISA’s election security efforts through spending requests for CISA in fiscal 2026 and 2027. The voter registration guide provides an overview of potential avenues for bad actors to exploit databases and offers recommendations for election officials to safeguard statewide database systems.
The guide explains how hackers who gain access to voter registration databases could obtain absentee ballots, alter voter registration information and delete registrants. “A breach can allow bad actors to access public information such as name, date of birth, and address but also sensitive information like driver’s license numbers, full or partial social security numbers, and voter signatures on file,” according to the guide. “That information could enable bad actors to request absentee ballots at scale for low-propensity voters,” CISA says.
CISA’s election infrastructure security plan highlights how statewide voter registration databases are “attractive targets for foreign adversaries” and claims “[h]ackers have attempted to breach voter registration systems in all 50 states, with confirmed success in at least 20 states.” “State and local election officials must prioritize system security and implement safeguards to prevent the exploitation of data that may already have been exposed,” according to the plan. The security plan also emphasizes addressing vulnerabilities in election-related software systems is a priority for CISA. “Election-related software, like all complex software, contains vulnerabilities that require timely remediation.
However, structural constraints within the certification ecosystem can significantly limit vendors’ ability to release patches and prevent system owners from applying them quickly,” the plan says. The plan identifies three major cybersecurity threats that are impacting the “overall security of U.S. elections,” starting with software vulnerability management efforts “limited by outdated certification regimes.” The other threats are inconsistencies with transparency from election system vendors on vulnerabilities and patch status and addressing the “cybersecurity immaturity” of state and local networks used to host election systems. “Across all critical infrastructure sectors, threat actors consistently rely on basic, reliable techniques that function across diverse products and environments.
Instead of relying on novel exploits, they repeatedly target the same categories of weaknesses that resurface in software,” according to CISA. The plan says, “These adversaries often succeed, because many preventable software flaws remain unresolved.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.