Election Day DDoS: How 2024's Votes Played Out Online

With more than 60 countries and the European Union holding national elections in 2024—affecting roughly half the world's population—the Internet became a central battleground for political engagement and cyber threats. Cloudflare's visibility across its network of over 330 cities in 120 countries, interconnected with 12,500 networks, offered a real-time view of how these events unfolded digitally.

BLOG-2648 2

Traffic patterns shifted notably on election days, while authorities in several nations ordered Internet shutdowns tied to voting. Email activity also responded to political polarization, particularly around high-profile candidates. Below is a breakdown of attack trends, outages, and traffic anomalies observed during key votes throughout the year.

Attack Surges Hit Campaigns and Election Infrastructure

Distributed denial-of-service (DDoS) attacks were a persistent theme across 2024 elections, striking political parties, campaign websites, and state-run election portals. While many attacks were mitigated, their frequency and intensity underscored the elevated threat landscape.

United States: Record Traffic and Sustained Onslaughts

Between November 1 and November 6, Cloudflare blocked over 6 billion malicious requests. In the lead-up to Election Day on November 5, one presidential campaign endured multiple days of DDoS attacks, peaking at 700,000 requests per second (rps) with sustained traffic of 8 Gbps. Attackers employed cache-busting techniques, geodiverse source patterns, and randomized user agents to evade detection.

BLOG-2648 3

State and local election websites saw heightened activity as well, with 290 million malicious requests blocked since September under the Athenian Project—a free Cloudflare program protecting election-related infrastructure. Compared with the 2020 cycle, 2024 attacks were markedly more severe.

European Elections: Coordinated Attacks on Parties

In France, political parties faced repeated DDoS strikes culminating on election day, July 7, with peaks reaching 96,000 rps. The UK saw its most severe incident hit a campaign website at 156,000 rps shortly after results were announced on election day. In the Netherlands, two politically affiliated websites were targeted on June 5–6 (the latter being election day), peaking at 73,000 rps.

BLOG-2474 Embedded Image - 4iru7i
BLOG-2648 5

Romania's election cycle, ending with parliamentary polls on December 1, was marked by weeks of DDoS attacks against party websites and news outlets. South Africa's general election on May 29 was preceded by a multi-day attack on a major news site, peaking at 54,000 rps on May 7. In Portugal, election day on March 10 saw attacks on party sites after polls closed; one party saw traffic hit 69,000 rps on May 11.

In Taiwan, a local fact-checking website was hit three days before the January election, while in Japan, a site dedicated to reporting scams and misinformation was attacked a week before the October 27 vote.

These figures may seem modest compared to larger attacks Cloudflare mitigates daily, but for unprotected sites, even moderate DDoS traffic can knock services offline. Beyond the immediate disruption, successful attacks also serve as a smoke screen, diverting IT teams while attackers attempt secondary intrusions.

Government-Ordered Shutdowns During Elections

In several countries, authorities restricted Internet access during or immediately after elections, citing security or public order concerns. Comoros, a nation of under 1 million in Southeastern Africa, held presidential elections on January 14. Following protests against the re-election of President Azali Assoumani, officials shut down the Internet on January 17, cutting traffic by 50% for two days before restoration.

BLOG-2648 8

Pakistan's general election on February 8 saw a targeted shutdown of mobile networks. The outage began around 02:00 UTC, reducing traffic by half compared with the prior week; recovery took until after 15:00 UTC. In Mauritius, with a population under 2 million in the Indian Ocean, the government suspended social media platforms from November 1 to November 11, ahead of parliamentary elections on November 10.

BLOG-2648 9

Election Day Traffic: A Mobile-First Pattern

Across 2024, election-day Internet traffic trends often mirrored a country’s dominant device usage. Nations where mobile connectivity leads, such as Indonesia, Mozambique, and Ghana, showed noticeable traffic drops once polling stations closed. Desktop-centric regions like Europe and the Americas displayed different habits, though analysts found no consistent link between device preference and overall traffic increases or decreases during elections.

BLOG-2648 10

The map above illustrates how mobile (purple) or desktop (green) traffic dominates various countries.

Regional Election Traffic Highlights

Observations from specific elections, ordered by date, reveal how citizens engage online during critical political moments:

Taiwan (January 13) — Traffic dipped slightly during voting hours, with an 8% drop in the morning. After 17:00 local time, levels returned to normal, and the following morning saw a 5% increase compared to the prior week.

BLOG-2648 11

Indonesia (February 14) — This single-day general election, likely the largest with over 200 million voters across 17,000 islands, saw a traffic dip of up to 15% between 08:00 and 13:00 local time. Mobile device usage hit 77%, its annual high, and traffic only recovered the next morning after an evening of 8%–16% lower-than-usual levels.

BLOG-2648 12

Russia (March 17) — Unlike most countries where post-election traffic surges are common, Russia’s presidential election saw a 7% decrease after polls closed. The pattern underscores the stronger influence of broadcast media on election coverage there.

South Korea (April 10) — Legislative elections saw pre-dawn traffic above normal, a 14% drop by 07:15 after polling opened at 06:00, and a rebound to normal levels by mid-morning. After closing time (18:00), traffic declined 7% from the prior week.

India (April 19–June 1) — The seven-phase general election recorded its largest nationwide traffic dip of 6% on May 7, with populous states like Uttar Pradesh down 9% and Maharashtra down 17%. On the final election day, mobile usage peaked at 68%, its highest of the year.

BLOG-2648 13

North Macedonia (April 24 & May 8) — The second round of the presidential election on May 8 drove a 56% traffic increase after 11:00 local time, sustained all day, with similar but smaller trends seen in the first round.

South Africa (May 29) — General election traffic dipped 16% at 05:45 and stayed low through polling hours. A 25% surge hit the night before, and post-election traffic rose up to 12% early on May 30.

Mexico (June 2) — The general election saw hourly traffic dips of up to 11% during polling (08:00–20:00 local time). As results arrived, traffic surged 14% at 01:30 the following day.

Iceland (June 1) — Presidential election traffic showed a 12% dip between 14:00 and 16:00, but rose by 11% at night (20:00) and climbed 26% the following day compared to the prior week.

European Union (June 6–9) — European Parliament elections brought drops over 10% in the Czech Republic and Slovakia, with Finland and Ireland seeing moderate declines. Major political events, such as Belgium’s PM resignation and French President Macron’s snap election call, caused their own traffic fluctuations.

BLOG-2439 Embedded Image - bi5RYH

Iran (June 28) — Presidential election traffic fell 16% after 17:30 local time and dropped 24% by 22:30, driven by extended evening polling hours. After midnight, traffic rebounded 13% from the prior week.

France (June 30 & July 7) — Legislative elections saw a 16% traffic decline at 20:00 on July 7 as polls closed and TV announced results. Mobile usage hit 58%, while DNS traffic to news outlets surged 250% during the first round and 244% on runoff day.

BLOG-2648 15

United Kingdom (July 4) — Northern Ireland saw the sharpest traffic drop (10%) during voting, versus 6% in Scotland and 5% in Wales, with a minor 2% dip at noon overall. In the evening, DNS traffic to election-related domains peaked with increases of 600% at 22:00 and 671% at 04:00 the next day.

BLOG-2648 16

Sri Lanka (September 21) — The presidential election caused a 9% morning dip but an 18% post-election surge; results triggered a 109% traffic spike at 03:00 on September 22.

Mozambique (October 9) — The election fell on a public holiday, producing a 31% daily traffic drop. Levels fell as much as 51% below normal by 20:30, with a 16% surge at 01:30.

Georgia (October 26) — Parliamentary election traffic reached 67% above normal around 23:00 when results surfaced, despite only a slight 2% dip in the afternoon. Daily traffic ran 11% above the previous week.

United States (November 5) — A 15% spike in Internet traffic followed poll closings, led by the Midwest. DNS traffic surged 756% to polling services and 325% to news sites, and news brands like CNN, Fox News, and The New York Times ranked higher among DNS traffic leaders.

BLOG-2648 17

Ghana (December 7) — Mid-morning traffic fell 11% after stations opened, with declines of 13% and 14% after 17:00 closing time.

Email Volumes Around the US Candidates

Beyond network traffic, cybersecurity trends are visible in email flows: trending topics and individuals attract more spam and phishing. From June 1 to November 5, Cloudflare processed over 19 million emails mentioning “Donald Trump” or “Kamala Harris.” Trump appeared more frequently and drew higher rates of spam (12%) and malicious email (1.3%) than Harris (0.6% and 0.2%, respectively). Nearly half of these messages arrived after September, with a surge in the final 10 days of the campaign.

BLOG-2648 18

What 2024 Taught Us About Election Security

The 2024 election cycle demonstrated how deeply the Internet is embedded in democratic processes—as both a platform for civic engagement and a point of attack. Distributed denial-of-service (DDoS) attacks on election infrastructure and government-imposed network shutdowns both emerged as recurring patterns, underscoring the need for stronger cybersecurity postures around critical electoral systems.

The trend shows no sign of slowing. Germany has called a snap federal election for February 23, 2025, after the collapse of its governing coalition during the 2024 government crisis. That vote follows similar early elections in France and the UK, pointing to a pattern of political instability that forces rapid electoral mobilization—and rapid preparation of the digital infrastructure those elections depend on.

Several lessons from 2024 are worth carrying forward:

  • DDoS remains a go-to disruption tactic. Attacks aimed at campaigns and election systems are not diminishing in frequency or complexity, and they increasingly require always-on defensive capacity rather than reactive mitigation.
  • Shutdowns are a blunt but persistent tool. Network blackouts imposed during elections in places like Pakistan and Comoros show that countries may still choose to interrupt connectivity rather than secure it. Such measures can undermine confidence in the electoral process and complicate independent verification.
  • The threat surface is wide. Phishing campaigns and misinformation surges targeting voters continue to grow, requiring coordinated responses that extend beyond technical defenses into public awareness and platform policy.

For organizations and governments preparing for future votes, the takeaway is that election security needs to be designed as an ongoing discipline, not a last-minute exercise. Continued collaboration between state actors, technology providers, and civil society will be essential to keep electoral infrastructure resilient.

More detailed data on these trends is available through Cloudflare Radar, including the dedicated 2024 Elections Insights report.