Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | The 2026 U.S. Midterms Election Season, Weakened Defenses: The Cyber Landscape Ahead
Sep 29, 2026
14 Mins Read
Moon
Summarize with:

The 2026 U.S. Midterms Election Season, Weakened Defenses: The Cyber Landscape Ahead

In late April 2026, Army General Joshua Rudd, the head of U.S. Cyber Command and the NSA, testified before the Senate Armed Services Committee that foreign adversaries would likely attempt to interfere in the upcoming midterm elections. When pressed on whether the joint Election Security Group had been stood up, he said he was not sure. “I don’t know that an ESG has been established yet,” he told lawmakers. In every prior election cycle since 2018, that task force was active and briefing Congress by this point.

Former Lt. Gen. Joshua Rudd was elevated to the rank of general as part of his confirmation. | Saul Loeb/AFP

Former Lt. Gen. Joshua Rudd was elevated to the rank of general as part of his confirmation. | Saul Loeb/AFP

That exchange captures the broader problem heading into November 2026. The threat environment is real and growing but the federal institutions built to counter it have been cut, restructured, or left without leadership.

The Threat Landscape: What Is Actually Being Targeted

The highest-probability threats to the 2026 midterms have little to do with voting machines or ballot counts. The vectors that federal agencies, congressional overseers, and election officials have flagged center on the broader election ecosystem: phishing operations, credential theft, impersonation of trusted organizations, and disinformation campaigns targeting campaign staff, fundraising platforms, media outlets, and political organizations.

During the 2025 off-year elections in New Jersey, bomb threats targeted polling places, but CISA issued no public guidance and did not activate its real-time operations center.

That silence marked a break from how the agency had operated in prior cycles, and it signaled to state and local officials that they could no longer assume federal support during election-related incidents.

AI-generated content has added a new dimension. Reporting in March 2026 documented at least three national-level Republican ads using deepfake technology, including a fabricated video of Texas Democratic Senate candidate James Talarico.

While the worst deepfake scenarios from 2024 did not materialize, the technology is steadily eroding public trust in what people see and hear. Legal guardrails remain weak: California’s 2024 deepfake law was struck down on First Amendment grounds, and no federal legislation has filled the gap.

The intelligence community’s own posture has shifted in troubling ways. For the first time in nearly a decade, the 2026 Annual Threat Assessment omitted any mention of foreign threats to U.S. elections. DNI Tulsi Gabbard dissolved the Foreign Malign Influence Center (FMIC) in August 2025, the last federal entity dedicated to tracking state-sponsored efforts to interfere in U.S. elections and institutions. The ODNI characterized the center as having been used to justify the suppression of free speech and censor political opposition.

After this development, we saw a bipartisan group of lawmakers led by Representative Deborah Ross sent a letter in July 2026 urging the administration to assess how Russia’s increasingly sophisticated interference tactics in European elections could threaten the integrity of the November vote.

The letter pointed to Russia’s recent campaigns in Moldova and Armenia, which combined coordinated disinformation, AI-generated content, cyberattacks, and deepfakes. Senators Alex Padilla, Mark Warner, and Gary Peters demanded regular intelligence briefings from ODNI, CISA, the FBI, and the NSA through November 2026, citing weakened federal election support.

China, Iran, and Russia all remain capable and motivated to attempt to influence the 2026 midterms

China, Iran, and Russia all remain capable and motivated to attempt to influence the 2026 midterms

The Domestic Policy Shift: Cutting the Shield

The federal agency most responsible for election cybersecurity has undergone severe reductions in both staffing and scope. Nearly 1,000 CISA personnel, close to one-third of the workforce, left or were removed by mid-2025.

Senator Warner’s correspondence to DHS noted that state and local officials reported CISA is no longer providing the same level of election-security training, intelligence sharing, or cybersecurity assistance it offered in prior cycles.

DOGE eliminated CISA’s red teams (over 100 people), and the Stakeholder Engagement Division, about 95 employees, was effectively shut down in October 2025.

The administration’s FY2027 budget proposal would cut an additional $700 million and eliminate CISA’s election security program, including information-sharing efforts and election security adviser positions.

CISA has had no Senate-confirmed director throughout Trump’s second term. The nominee, Sean Plankey, withdrew in April 2026 after a 13-month confirmation stall, writing that the Senate would clearly not confirm him. Acting director Nick Andersen currently leads the agency.

The cuts extend beyond personnel. In February 2025, DHS partially terminated its cooperative agreement with the Center for Internet Security, eliminating federal funding for the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC).

On March 11, CISA announced a further $10 million cut from the same agreement, removing support for the Multi-State ISAC (MS-ISAC).

The full $27 million per year cooperative agreement with CIS ended on September 30, 2025. CISA said the work “no longer effectuates department priorities.” Both organizations continue to operate under CIS on a paid model, but the loss of federal funding removed the free tier that most state and local election offices relied on.

The broader federal election-security architecture has been dismantled in parallel with CISA’s reductions.

The administration shut down the FBI’s Foreign Malign Influence Task Force and the State Department’s Global Engagement Center successor office (R/FIMI, closed April 2025), while DNI Gabbard dissolved the FMIC at ODNI in August 2025, removing what analysts assessed as the last federal body dedicated to coordinating the tracking of foreign election interference. (ODNI later quietly appointed two officials to coordinate election-threat intelligence in May 2026, though without restoring the FMIC’s structure or staffing.)

FBI agents from the CI-12 counterespionage unit, which specialized in monitoring Iranian threats, were fired days before Operation Epic Fury for their prior involvement in the classified documents investigation. And General Tim Haugh, who oversaw Cyber Command and the NSA during the 2024 election cycle, was fired in April 2025.

Former CISA director Chris Krebs was also impacted during these developments. On April 9, 2025, Trump signed a presidential memorandum directing a DOJ investigation of Krebs and revoking his security clearance, labeling him a “significant bad-faith actor.” As a response, more than 30 cybersecurity experts and academics signed a letter condemning the retaliation.

Senator Mark Warner summarized the situation in early 2026 to CNN: “We’re going into a [2026] election cycle with our guard down.”

Even though the agency went through chaos, on September 24, with 40 days until Election Day, CISA released a 2026 Election Infrastructure Security Plan. DHS Secretary Markwayne Mullin said “election security is national security” and that the plan would be implemented in full.

The document designates CISA’s 10 regional directors as election security advisers and describes a free information-sharing platform connecting election officials, state fusion centers, and federal partners. But the plan does not specify how many employees will carry out the work, does not restore dedicated election adviser positions, and does not identify funding.

Numerous state and local election officials have said that services previously provided by CISA, like tabletop exercises and penetration tests, were not available in the lead-up to the midterms. The plan also does not explain how its commitments fit with the FY2027 budget proposal that would eliminate CISA’s election security program entirely.

The New Cyber Doctrine: Offense Over Defense

On March 6, 2026, the White House released “President Trump’s Cyber Strategy for America,” the shortest U.S. cyber strategy in over a decade. The doctrine is built around what can be described as “American primacy” rather than collective defense. Its first pillar directs the use of the full suite of U.S. government offensive and defensive cyber operations and pledges to create incentives for the private sector to identify and disrupt adversary networks.

The offense-first pivot raises real questions. The strategy cites cybercrime as the only threat discussed with any specificity, while China, Iran, North Korea, and Russia go unmentioned.

A vision of U.S. dominance in cyberspace sounds forceful, but there is a growing gap between that vision and the government’s actual capacity to deliver on it. Slashing CISA’s workforce and defunding election-security information sharing while claiming to project strength leaves the defensive side of the equation weaker.

Analysts broadly assess that cyber deterrence through offensive operations alone has not been convincingly demonstrated in practice. Offensive operations may disrupt adversary infrastructure temporarily, but they do not protect voter-registration databases, patch vulnerable PLCs in water systems, or help a county election official recognize a spear-phishing email.

The strategy also stops short of explicitly authorizing private companies to conduct offensive cyber operations against foreign adversaries.

The Geopolitical Cyber Dimension

Iran: From Espionage to Active Conflict

Iran has been the most active cyber adversary tied to a live military conflict with the U.S. during this period. On February 28, 2026, the U.S. and Israel launched coordinated strikes (Operation Epic Fury / Operation Roaring Lion) with integrated cyber and electronic-warfare operations that disrupted Iranian command, control, and sensor networks. Iran’s own internet blackout during the strikes limited its ability to run state-directed retaliation, shifting activity toward hacktivist proxies using DDoS attacks and website defacements.

An April ceasefire was brokered by Pakistan, and a June memorandum of understanding was signed, but the agreement collapsed and fighting resumed in July. As of September 2026, the conflict has become a war of attrition, with the U.S. and Iran trading limited strikes amid a U.S. naval blockade and stalled diplomacy. Cyber operations, however, have continued uninterrupted throughout all phases of the conflict.

Iran’s cyber operations against U.S. infrastructure have continued to escalate outside the direct conflict. A CISA-FBI-NSA joint fact sheet from June 2025 warned that despite a declared ceasefire and ongoing negotiations, Iranian-affiliated actors may still conduct malicious cyber activity against U.S. critical infrastructure.

That warning proved as well: a joint advisory from CISA, the FBI, the EPA, and other agencies (first published April 2026, updated July 2026) documented IRGC-affiliated actors exploiting programmable logic controllers across U.S. critical infrastructure, targeting water and wastewater systems, energy, and local government facilities.

The CISA advisory provides important evidence that Iran is weaponizing the access it already had to target networks across the United States, in some cases going back to January 2025.

Iran’s cyber actors are operating in familiar territory: the activity fits the country’s track record of targeting water and energy facilities using low-sophistication methods that exploit basic vulnerabilities in internet-exposed operational technology. The administration’s own National Cyber Strategy lists securing critical infrastructure as a priority, but leadership gaps, CISA cuts, and the loss of information-sharing mechanisms undermine that goal in practice.

Russia: Breaches, Influence, and Institutional Erosion

Russia remains a central concern both as a direct cyber threat and as an election-influence actor. In August 2025, U.S. investigators assessed that Russia was at least in part responsible for a breach of the U.S. federal court filing system (CM/ECF and PACER), compromising sealed records. This was the second such breach since 2020, exploiting vulnerabilities known from the earlier incident. The attribution has not been formally confirmed by the U.S. government.

On election interference specifically, Russian influence networks behind 2024 troll-farm operations have continued producing content. A bipartisan congressional letter warned that Russia has continued to develop its election interference strategy by combining traditional influence operations with coordinated online disinformation and targeted use of AI, pointing to campaigns in Moldova and Armenia as templates.

Meanwhile, the institutional capacity to detect and publicize foreign interference has been hollowed out. The foreign-influence-focused centers at ODNI, FBI, DHS, and the State Department that were previously tasked with identifying and countering these operations have been disbanded or downsized. The administration has accused those programs of censoring Americans and conducting domestic interference in U.S. elections.

Cyber Diplomacy in Retreat

The international dimension of U.S. cyber policy has weakened alongside the domestic cuts. The State Department’s July 2025 reorganization, which eliminated roughly 1,350 jobs, fractured the Bureau of Cyberspace and Digital Policy by splitting bilateral engagement and communications functions. Chris Painter, the top U.S. cyber diplomat from 2011 to 2017, called the restructuring a gift to adversaries that sends the wrong message to allies.

The congressionally mandated Cyberspace Solarium Commission found in its October 2025 implementation assessment that only about 35% of its recommendations were now fully implemented, down from 48% in 2024. That was the first reversal in the commission’s history. Commission leaders argued that adversary offensive cyber operations are accelerating while America’s cyber defenses fall behind, and called for Senate-confirmed CISA leadership and sustained multi-year funding.

On the international stage, the U.S. continues to back the 2001 Budapest Convention as the gold standard for cyber governance. The Russia-initiated UN Convention against Cybercrime opened for signature in Hanoi on October 25, 2025, and remains open until December 31, 2026. The tension between these two frameworks is a live contest over the norms that will govern state behavior in cyberspace for years to come. Washington would be expected to promote its own policies while preparing to withstand Russia’s, but the “reorganization” of the State Department cyber-diplomacy capacity makes both tasks harder.

What to Watch and What to Do

Key dates and indicators to monitor:

The UN Cybercrime Convention signature window closes December 31, 2026. Whether the U.S. signs, and how it positions itself relative to the treaty’s surveillance provisions, will shape cyber-diplomacy dynamics for years. Watch for whether the Election Security Group is activated before November 4 (Election Day). Track whether the administration follows through on the CISA election security plan’s commitments, or whether state officials continue reporting gaps in services. Any confirmed intrusion into voter-registration databases or tabulation systems would fundamentally change the threat picture. And watch the Iran conflict: a breakdown in the current diplomatic track or a major retaliatory cyber operation timed to the election cycle would raise the threat level significantly.

What organizations should do now:

Assume reduced federal support and build alternatives. With EI-ISAC and MS-ISAC stripped of federal funding and CISA’s election-security outreach diminished, organizations that previously relied on federal threat intelligence and situational awareness need to establish alternative sources before November. State-level partnerships, sector-specific ISACs, and direct coordination with peer organizations are the immediate fallback.

Focus defenses on the actual threat vectors. Phishing, credential theft, brand impersonation, and fundraising-platform compromise are the primary risks this cycle. Register and monitor look-alike domains. Rotate credentials on donor and fundraising platforms. Apply network segmentation and zero-trust principles so that voter data, donor records, and election operations are isolated from general networks.

Prepare for AI-driven disinformation. Build rapid-response verification workflows. Train staff and stakeholders that automated verification tools, including AI chatbots, have already amplified fabricated content during the Iran conflict and should not be treated as reliable fact-checkers.

Conclusion

The United States has held many national election cycles since the 2016 interference campaign that put election security on the map. Each cycle brought stronger federal coordination, better threat intelligence sharing between Washington and the states, and a more visible deterrence posture toward foreign adversaries. That trajectory has reversed.

CISA has lost a third of its workforce and has no confirmed director. The EI-ISAC and MS-ISAC that state and local election officials relied on also lost federal funding. The Foreign Malign Influence Center has been dissolved. The intelligence community’s annual threat assessment dropped election threats from its public reporting for the first time in years. The Election Security Group that Cyber Command stood up for every cycle since 2018 may not be operational. And CISA’s own election security plan arrived 40 days before Election Day, with no staffing commitments and no funding behind it.

But the threats have not paused. Iran is running cyber operations against U.S. critical infrastructure. Russia continues to build out influence networks and has tested its playbook across European elections. China’s Salt Typhoon campaign demonstrated that even the most sensitive U.S. communications infrastructure can be compromised at scale. And generative AI has made it cheaper and faster to produce convincing disinformation, with deepfakes already appearing in campaign ads this cycle.

The administration’s answer to this environment is an offense-first cyber doctrine. Offensive capability matters. But offensive operations do not secure voter-registration databases, restore the information-sharing channels that state election officials depend on, or help a county IT administrator recognize a spear-phishing email targeting their election management system. Defense and offense serve different purposes, and cutting one to fund the other leaves gaps that adversaries will find.

For security teams, election officials, and organizations operating in and around the election ecosystem, the practical takeaway is straightforward: federal support is thinner than it has been in nearly a decade. The margin for error is smaller and the responsibility has shifted further toward state governments, local officials, and the private sector.