Back Thehill Hackers more focused on misleading voters than ballot tampering: Report
Hackers and foreign influence operators are increasingly turning to misinformation campaigns to confuse and mislead voters rather than tampering with voting machines and ballots in the 2026 midterm elections, a new cybersecurity report found.
The report , published Monday by cybersecurity firm Check Point Software, said attempts at phishing, impersonation and misinformation activity will be most prevalent this election cycle, targeting election-related systems and services.
These risks, also seen in at least the past two election cycles, are amplified by artificial intelligence, giving malicious actors cheaper, broader and faster deception methods according to researchers. This has led to an increase of altered videos or audio and deceptive pictures populating online, along with more targeted phishing attempts.
“The current threat environment favors operations that are inexpensive, scalable, and capable of producing outsize political or psychological impact,” the report states, adding these campaigns can “create confusion, reputational harm, and operational disruption without requiring direct compromise of core election infrastructure.”
Aaron Rose, security architect manager for Check Point, called it an “attack on the mind,” in a recent interview with The Hill.
“If you are able to confuse 10,000 people in a swing county or swing state, that alone could change the outcome of the election,” Rose said, “because you’ve confused them voting locations or who the options are.”
These operations are similar to what Check Point observed in the 2024 election. Rose explained going after voting machines, ballot boxes or the counting infrastructure is “heavily technical,” prompting the focus on misinformation.
Instead, hackers will target services used for election-related activities, like fundraising or donor websites, communications channels and public information and government platforms, the report states. Third-party services, like e-mail, are also impacted through phishing messages and impersonations of legitimate services.
These processes are especially effective given the deep political divides the U.S. currently faces.
“Everybody’s politically charged when they see information that either makes them angry or 100 percent aligns with their views, they just instantly hit that repost and don’t know if it’s a valid source or not,” Rose said.
Some attempts have already showed success for hackers. According to the report, nearly 9,500 credentials of donors to Democratic fundraising platform ActBlue, along with 6,500 donor credentials for GOP fundraising platform WinRed have been leaked.
While hackers may not do much with usernames and passwords, Rose emphasized the information can be used later to target donors. For example, a donor could receive an email listing their past donations with dates but get asked to resubmit credit card information due to a fake payment error, Rose said.
“When you add AI into the mix and the fact that we all overshare way too much on social media platforms, they can learn so much you,” Rose said.
Other hacking methods include website domain registrations that use election-related terms like “vote,” or “election” to trick users.
Rose hopes voters will be aware of these schemes, recommending users pause and think before reposting content or clicking on new links.
It comes as the Trump administration pushes concerns election security, often citing voting machines and mail-in ballots.
Asked whether Washington is prepared for these threats, Rose said cybersecurity and intelligence agencies are aware and attempting to manage risks, but the volume of these attacks are difficult to track.
Researchers are also preparing for state-linked foreign actors, mostly from Russia, Iran and China, to attempt election interference this year, following behavior from past elections. This includes a mix of influence operations and cyber reconnaissance.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
