Election Websites and Campaigns Face Divergent Threat Profiles
As the 2020 U.S. elections approach, the shift of campaign and election activities online has accelerated due to COVID-19. With virtual fundraisers, online town halls, and digital vote-by-mail forms becoming the norm, the security of these internet-dependent systems is critical. Cloudflare's analysis of its own network traffic and protected domains reveals that state and local election websites and political campaigns face distinctly different types of cyber threats.
While government election sites contend with a high volume of vulnerability exploitation attempts, political campaigns are more frequently targeted by distributed denial-of-service (DDoS) attacks. The data, drawn from Cloudflare's Athenian Project and Cloudflare for Campaigns initiatives, highlights the need for tailored security strategies for each group.
Persistent Probing of Government Election Sites
State and local government election websites under the Athenian Project have seen a 48 percent increase in protected domains since the start of 2020, now covering 229 sites across 28 states. Traffic to these sites has become increasingly unpredictable, with requests spiking to two to three times normal volumes. This surge is attributed to expanded vote-by-mail initiatives and voter registration deadline changes enacted by emergency orders across numerous states and territories. In March alone, more than 23 states held presidential primaries, including 14 on a single day.
At the DEF CON Voting Village this year, Department of Homeland Security experts identified high demand as a primary risk to election systems. Cloudflare's data supports this, showing significant unexplained traffic spikes outside of typical election cycles.
An analysis of threats blocked by Cloudflare's web application firewall (WAF) for Athenian Project domains reveals a steady stream of malicious activity. In March 2020, for instance, the WAF blocked 90 million threats. Of these, managed rulesets mitigated 51 percent of threats, while custom firewall rules accounted for an additional 35 percent. This combination of automated rulesets and user-defined rules has proven effective in safeguarding election information.

SQL injection attacks remain a primary concern for government election sites, a trend observed in previous election cycles. Cloudflare's data shows an average of 43,884 SQL injection attempts per day across all Athenian Project domains, with the WAF successfully blocking 199 such threats per day on average.
Campaigns Hit Harder by DDoS Attacks
Political campaigns present a different challenge. Often short-term and cash-strapped, these operations typically lack dedicated IT staff and robust long-term security budgets, making them attractive targets. Cloudflare surveyed 80 U.S. federal political campaigns and found that the threat landscape here is often the inverse of what government sites experience.
Since January 2020, Cloudflare has mitigated a total of 77,192,840 threats across these campaign sites, averaging 4,949 threats per day. Larger-scale attacks are more frequently seen against Senate candidates' websites than those of House candidates.
The frequency of attacks has escalated as the election season progresses. Data shows a 187 percent increase in the average number of attacks against political campaigns from May to June 2020. With in-person campaigning curtailed, campaigns have pivoted to digital platforms for fundraising, rallies, and voter outreach, exposing them to new vulnerabilities. In response, state parties and committees have begun offering cybersecurity training on basic hygiene practices like password management, two-factor authentication, and phishing identification.
DDoS attacks are a particularly notable threat to campaigns. These attacks, which can be cheap and easy to organize, are often used to take down campaign websites at critical moments. The prevalence of DDoS as a tactic is evident from the data: campaigns used rate limiting to address 63 percent of the cyber threats they encountered.

Preparing for Election Day Resilience
The distinct security challenges faced by election officials and political campaigns underscore the importance of specialized protections. While government sites benefit from robust WAF rulesets to counter vulnerability exploits and SQL injections, campaigns must prioritize DDoS mitigation and rate limiting. As the pandemic continues to push election functions online, the reliability of these systems remains central to maintaining trust in the democratic process.



