What happened
A leaked NSA analysis described a two-stage Russian military intelligence operation against US election infrastructure in 2016. On 24 August 2016 spoofed Google emails were sent to employees of Florida-based election software vendor VR Systems, directing them to a fake login page; the NSA assessed at least one account was likely compromised. On 31 October and 1 November the operators, using a Gmail account impersonating a VR Systems employee, sent malicious Word documents to 122 addresses at named local government election organisations.
How the deception worked
The first stage was a credential phishing portal: emails that looked like Google security notices pointed VR Systems staff at a counterfeit Google sign-in page where they typed their passwords. The second stage weaponised the resulting familiarity. The operators registered a Gmail address in the name of a real VR Systems employee and mailed 122 local election administrators, who knew VR Systems as their voter-registration software vendor, attaching trojanised Word documents that ran PowerShell to fetch further malware. The trust signal was the vendor relationship itself, and the timing, days before the election, supplied the urgency that made recipients open attachments.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA on vendor accounts and out-of-band confirmation of unexpected vendor attachments would have broken both stages of the chain.
Sources (2)
- Top-Secret NSA Report Details Russian Hacking Effort Days Before 2016 ElectionThe Intercept·theintercept.comOpen ↗
- Report: Russia Launched Cyberattack On Voting Vendor Ahead Of ElectionNPR·npr.orgOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.