Election Security: Attack Trends From 2023 That Shape 2024
With more than 70 elections scheduled across 40 countries in 2024, the security of election-related infrastructure is a critical concern. Trust in the democratic process depends on the Internet being secure, reliable, and accessible for voters and election officials alike. Cloudflare's work protecting election entities provides a data-rich view into the threats these groups face.
Cloudflare has been expanding its security offerings for vulnerable groups since late 2022, when it added Zero Trust products to its Athenian Project and Project Galileo initiatives. The company also runs Cloudflare for Campaigns, a partnership with Defending Digital Campaigns. Analyzing traffic from these programs between November 1, 2022, and August 31, 2023, reveals key patterns in how election-related websites are targeted.
Over that ten-month period, Cloudflare mitigated 234.74 million threats against U.S. election groups covered under these programs. Internet traffic to these sites grew steadily, rising nearly 25% between January and August 2023. Traffic spikes aligned with election cycles, and HTTP Anomaly was the top layer 7 attack vector mitigated by the Web Application Firewall (WAF), followed by SQL Injection.
State and Local Election Sites: The Athenian Project
The Athenian Project provides Cloudflare's highest level of protection to U.S. state and local governments that run elections. As of November 2023, 390 such entities across 31 states were enrolled. Between November 1, 2022, and August 31, 2023, Cloudflare mitigated 213.78 million threats against these government election sites — an average of 703,223 threats per day.

On Election Day (November 7, 2022), traffic to these sites surged by over 500%. Analysis indicates that 80% of that traffic came from human users, a predictable pattern as constituents checked polling locations and results on county board of election websites.

A notable trend is the increased onboarding of .gov domains. Following CISA's September 2022 announcement about a new .gov registrar designed to simplify and secure domain setup, Cloudflare observed that 65% of traffic to Athenian domains now targets .gov sites.
Examining traffic mitigated by Cloudflare's managed WAF rulesets reveals an oscillating pattern of HTTP anomalies that drops suddenly and permanently after mid-April 2023. Managed rulesets are pre-configured firewall rules created by Cloudflare's security team and updated frequently to address new vulnerabilities while reducing false positives.

These managed rules are particularly valuable for organizations with limited security resources, as they are easy to activate and guard against common vulnerabilities affecting thousands of websites. Among WAF Managed Rules mitigations, HTTP Anomalies dominate at 76% — these include malformed method names, null byte characters in headers, non-standard ports, and zero-length POST content. SQL Injection follows at just 8%. The data also shows XSS (Cross-Site-Scripting) attempts occurring with a repetitive pattern every 23rd day of the month, suggesting automated attack activity.
Political Campaigns: Cloudflare for Campaigns
Cloudflare for Campaigns launched in January 2020 in partnership with Defending Digital Campaigns. The program currently protects 70 political campaigns and 20 political parties in the United States. Between November 1, 2022, and August 31, 2023, Cloudflare mitigated 1.83 million threats against campaign sites, averaging 6,019 threats per day.
<
Traffic to these domains spiked in November 2022 during the U.S. midterm elections and then fell significantly, reflecting that interest in campaign websites is largely confined to election periods and the months shortly before. A majority of blocked requests (79%) were handled by WAF rules. However, not all blocked traffic was malicious — some blocks came from rules campaigns configured themselves, such as restricting access from outside the United States. This is a positive indication that campaigns are actively customizing their security settings to filter unwanted traffic.
Beyond these customer-configured rules, campaign sites are also protected by Cloudflare-run WAF managed rules. Of the traffic mitigated by these managed rules, 47% was classified as HTTP Anomaly and 30% as SQLi.

Voting Rights Nonprofits: Project Galileo
The analysis also covered 69 U.S.-based organizations under Project Galileo that work on voting rights and fair election advocacy. For these nonprofits, Cloudflare mitigated 19.13 million threats between November 1, 2022, and August 31, 2023, an average of 62,927 threats per day.
Traffic spiked during the November 2022 elections, with another increase in April 2023. The largest share of blocked requests for this group was handled by Cloudflare's Security Level tool. This feature ranks requests by IP reputation and issues a Managed Challenge when appropriate. Managed challenges determine whether a request is legitimate or malicious — visitors who pass are allowed through, while those who fail are blocked. Many of these challenges result from domains enabling Under Attack Mode, which enforces an elevated Security Level to counter layer 7 DDoS attacks.
For WAF-mitigated traffic in this cohort, the top categories were HTTP Anomalies at 48% and SQLi at 25%. Overall, more requests were mitigated by the WAF than were flagged as DDoS.
Expanding Election Security Globally
Since 2021, Cloudflare has partnered with the International Foundation for Electoral Systems (IFES) to provide its highest level of protection, free of charge, to election management bodies (EMBs) worldwide. EMBs are responsible for organizing and overseeing elections in their jurisdictions. To date, Cloudflare has provided protection or expertise to seven such bodies, including election commissions in Kosovo and North Macedonia.

"Security is the cornerstone of any democratic process, and free and fair elections are no exception. Security products like those from Cloudflare become even more critical in an increasingly digital world. With Cloudflare, we have effectively mitigated numerous cyber threats, ensuring citizens uninterrupted access to electoral information in Kosovo. This has significantly fostered trust and transparency in our electoral processes." — Kreshnik Spahiu, Director of the Information Technology Department, Central Election Commission of Kosovo
Preparing for 2024: Internet Controls and Digital Freedoms
If 2023 is any indicator, election-related internet irregularities will continue in 2024. In Cambodia, officials ordered internet service providers to block access to three news outlets covering the 2023 election, limiting independent media before an unopposed vote. In Zimbabwe, the passage of the Patriotic Bill before the general election made it illegal to engage in speech deemed to threaten national sovereignty or vital interests.
Recent years have shown a range of government actions that restrict the flow of information — including internet shutdowns, social media restrictions during elections, and blocking of websites reporting on results. If these trends persist, 2024 will be a decisive year for online freedom. Groups supporting democratic processes need the security tools to stay safe and operational online, whatever the political climate brings.



