Skip to main content

Cyberattack on Florida election raises questions

Cybersecurity experts say we have now witnessed the first documented attack on a U.S. election.
Cybersecurity experts say we have now witnessed the first documented attack on a U.S. election.
STORY HIGHLIGHTS
  • A grand jury report outlines problems in an August 14, 2012, primary election in Florida
  • Someone created a computer program that made 2,500 bogus requests for absentee ballots
  • It's the first documented attack on a U.S. election, said computer scientist David Jefferson
  • Jefferson: "It's clear that the attackers knew what they were doing"

(CNN) -- It's a fear that keeps cybersecurity experts up at night: an attack on an online election system.

Apparently, it's now come to pass.

According to a grand jury report about problems in an August 14, 2012, primary election in Miami-Dade County, Florida, "someone created a computer program that automatically, systematically and rapidly submitted to the County's Department of Elections numerous bogus on-line requests for absentee ballots."

It's the first documented attack on a U.S. election, said computer scientist David Jefferson, who is on the board of the Verified Voting Foundation and the California Voter Foundation, in an interview with CNN.

America under cyberattack
Hackers taking aim at celebrities

The report notes that 2,500 fraudulent requests were submitted. (For perspective, Miami-Dade mailed out 139,047 absentee ballots last July and another 174,919 in October.)

With voting by mail increasing, the fact that the system was challenged is worrisome for cybersecurity experts.

"The computer scientists have been saying for many years now that this is going to be possible, and one of the counters to us has been, 'How come it hasn't happened?' We always say, we don't know if it's happened, because it might happen without leaving any evidence," said Avi Rubin, a Johns Hopkins computer science professor who is an expert in cybersecurity. "And now we're finally starting to see proof that it actually does happen."

Jefferson, who classified the attack as "weak," nevertheless highlighted several reasons to be concerned.

"It's clear that the attackers knew what they were doing, did it deliberately (and) tried to cover their tracks -- they were deliberately hiding their actions," he said. Moreover, he added, "It is not at all clear what their motives were."

According to the report, Miami-Dade's online ballot request system had "very low" security, with no user-specific logins or passwords. A concerned election vendor noted the influx of requests and flagged them, said the report.

"The vendor hired by Election officials ... became suspicious when it appeared that an extraordinary number of absentee ballot requests 1) appeared to be submitted from the same group of computers; and 2) were being submitted at a rate that was not humanly possible if the data on the screen was being entered by a person," the report said.

The requests came from IP addresses primarily located overseas, the report added, "although there was at least one fraudulent request from inside the United States."

The grand jury report is dated December 19, 2012. Its findings were reported last month by the Miami Herald, although they did not receive widespread national attention until now.

Florida, of course, is no stranger to electoral snafus. In 2012 alone, the state endured long lines, chaotic polling places and disputes over legislative actions that shortened the number of days and hours for early voting. But Jefferson says that, in terms of online issues, the state is far from the worst.

He said he and his colleagues in the cybersecurity community found two states that had "serious vulnerabilities" in their online registration systems: Washington and Maryland.

"Those dangers were so severe because it would not take a lot of skill to change the registrations of thousands of voters, online, while sitting in, say, Bulgaria," he said.

With hackers getting increasingly sophisticated, Rubin expects there will be more cyberattacks in the future. Indeed, even putting elections aside, reports of denial-of-service attacks, stolen passwords and other cases of Internet invasion are regular occurrences in the news -- and they've affected major corporations, government agencies and even security companies, Jefferson observes.

That doesn't mean we have to revert back to dropping paper ballots in an old wooden box. Rubin believes that election authorities "do a pretty good job at understanding their threats." It's just that voting is such a sensitive issue that they should have to plan for the worst -- and be prepared to handle it.

"The first thing to do is have a realistic understanding of the threat, so that before you offer a service on the Internet you know how you're going to respond when you're attacked -- and I say 'when' and not 'if' you're attacked," he said.

Indeed, Jefferson hopes that the Miami-Dade report serves as a wake-up call for authorities who have scoffed at computer scientists' concerns.

"For me, of course, this is no surprise. I've seen this and much worse in many circumstances," he said. "But because this is the first real documented attack in a U.S. election, it has outsized importance. We can now say we do have an example in a U.S. election of a bona fide cyberattack. You don't have to believe us -- we didn't write that grand jury report. Read it."

Cyberthreats getting worse, House intelligence officials warn

Alan Brill, senior managing director for Kroll Advisory Solutions, is optimistic that the wake-up call will be received promptly.

"If you look back, 20, 25 years, (legislators) had no real understanding of computers. But over time, it's kind of a rising tide" of comprehension, he says. "As you get more specialists in a field like this, I think the risks become more evident, and it becomes more urgent for them to do something about it."

ADVERTISEMENT
Part of complete coverage on
October 6, 2013 -- Updated 1036 GMT (1836 HKT)
In two raids, U.S. special operations forces capture a suspected terrorist operative and also target an Al-Shabaab leader, officials say.
October 4, 2013 -- Updated 1518 GMT (2318 HKT)
The first phone-call between U.S. and Iranian presidents raised hopes of a new start -- but could Iran's Revolutionary Guards spoil the party?
October 3, 2013 -- Updated 1804 GMT (0204 HKT)
Violence in Syria has left millions displaced. And while many Syrians have fled across the border to escape, others remain in harm's way.
October 2, 2013 -- Updated 0822 GMT (1622 HKT)
Iraq's violence is growing. The world seems oblivious but with unrest spreading though the region, this is why you should not ignore it.
October 5, 2013 -- Updated 1510 GMT (2310 HKT)
The FBI says it has caught the shadowy creator of the Internet's infamous criminal marketplace, the mysterius "Dread Pirate Roberts."
October 4, 2013 -- Updated 1523 GMT (2323 HKT)
For the past two years, she's been a pocket accessory to millions of Americans. Meet the woman who says she is the voice of Siri.
October 4, 2013 -- Updated 1021 GMT (1821 HKT)
Qatar businesses expect to take a hit if the 2022 World Cup is moved. CNN's John Defterios explains.
October 4, 2013 -- Updated 0707 GMT (1507 HKT)
The show is less traditional puppet theater and more a Balinese Baz Luhrmann-style "spectacular" with a cast of hundreds, including dancers.
October 4, 2013 -- Updated 1100 GMT (1900 HKT)
Like screaming fans at a gig, a young generation of Japanese have found a new obsession: horse racing -- a new rival to baseball and football.
October 4, 2013 -- Updated 0024 GMT (0824 HKT)
China issues an illustrated 64-page "Guidebook for Civilized Tourism" to instruct Chinese citizens on social norms overseas.
Explore CNN's Formula One interactive as the world's best drivers head to South Korea for round 14 of the world championship.
October 3, 2013 -- Updated 1047 GMT (1847 HKT)
Life extension cryotherapy chamber Franck Ribery
It is an age-old question: will humankind ever defeat old age? The multinational tech giant Google would like us to think it might be possible too.
October 6, 2013 -- Updated 1543 GMT (2343 HKT)
Graphene -- at one atom thick, it is the thinnest material ever discovered. CNN speaks to its inventor and Nobel laureate Kostya Novoselow.
October 2, 2013 -- Updated 1308 GMT (2108 HKT)
She was dubbed "The Assassin" after winning gold in London. But Kaori Matsumoto prefers to be known as "Beast."
October 3, 2013 -- Updated 1328 GMT (2128 HKT)
The common doodle has long been frowned upon in business meetings. But now researchers say it aids concentration.
ADVERTISEMENT