Election traffic and attack patterns under the microscope
During the 2022 US midterm election cycle, Cloudflare's Athenian Project and Cloudflare for Campaigns provided security coverage for state and local election infrastructure, political campaigns, and state parties. Traffic and attack data from Cloudflare Radar offers a look at what those sites faced between October 1 and November 8, 2022.
Both programs saw overall traffic climb as Election Day neared, with SQL injection (SQLi) and HTTP Anomaly attacks making up the largest share of WAF-mitigated requests. Notably, most observed attack traffic originated from US-based IP addresses.
Athenian Project sites
For Athenian Project participants — state and local government election sites — daily peak traffic roughly doubled over the course of October, following a clear weekday/weekend rhythm. The most significant growth arrived on Monday, November 7, and Election Day itself. November 7 peaks were just under twice October's levels. On November 8, two distinct peaks appeared: one just under four times October's peaks at 1300 UTC (0800 Eastern, 0500 Pacific), aligning with East Coast poll openings, and another just above four times at 0400 UTC (2300 Eastern, 2000 Pacific), coinciding with West Coast poll closings.
The aggregate numbers obscure some variation. The second Election Day spike was amplified by an outsized surge to a single customer's site, though traffic growth stretched across multiple sites. Still, the pattern confirms voters flocked to local government sites for authoritative election information.

WAF-mitigated attack traffic stayed largely flat through October and into November, with one clear exception. On Monday, October 10, a rate-limited attack targeted a single Athenian Project participant.

SQLi attacks grew markedly in the week and a half before Election Day, with an earlier spike on October 24. The final weekend of October saw heavy SQLi activity, while the weekend of November 5-6 was comparatively calm. Attacks ramped up again into Election Day.

HTTP Anomaly attacks also increased in the week leading up to November 8, though less dramatically than SQLi. The largest HTTP Anomaly spikes appeared on October 31/November 1 and just after midnight UTC on November 4 (late afternoon/evening in the US). Related request volume grew steadily into Election Day without major short bursts. The graph also shows a notable but brief attack on October 10, occurring hours after the rate-limited event — it's unclear whether they were connected.

Across the full survey window, SQLi and HTTP Anomaly categories accounted for just over two-thirds of all WAF-mitigated requests. Nearly 14% fell under "Software Specific," covering attacks tied to particular CVEs. The remainder was split among File Inclusion, XSS (Cross Site Scripting), Directory Traversal, and Command Injection rules.
Despite media reports of foreign election interference, more than 95% of mitigated requests targeting Athenian Project sites geolocated to US IP addresses. That likely reflects attackers leveraging compromised systems and proxies inside the US rather than the attackers' physical locations.
Cloudflare for Campaigns sites
Candidate sites participating in Cloudflare for Campaigns saw traffic build earlier than government sites. Peak volumes rose roughly 50% starting October 12, with another 50-100% increase a week later. Activity slackened toward month's end, then surged again into and on Election Day.
As with the Athenian Project data, one outlier site drew far more traffic than the rest. Other participating sites showed similar directional shifts, but their numbers were dwarfed in aggregate.

WAF-mitigated traffic for campaign sites tracked overall traffic closely. Attack volume began climbing around October 19, with another ramp near the end of the month. A spike on October 27 traced to a single customer's site, addressed via Cloudflare's "Security Level" ruleset, which relies on IP reputation to determine whether to challenge requests.

For candidate sites, HTTP Anomaly and SQLi together made up nearly three-quarters of mitigated requests, with Directory Traversal just under 10%. Compared to Athenian Project participants, campaign sites saw higher proportions of HTTP Anomaly and Directory Traversal attacks, with a slightly lower SQLi share.

US IP addresses still dominated, but to a lesser degree — 55% of attacks against campaign sites, versus 95% for Athenian Project participants. The remainder came from a long tail of countries, including Germany, Canada, and the UK among the top five. Again, attackers could be operating from anywhere, routing through botnets or compromised hosts in those countries.
Beyond the numbers
Publishing detailed data on threats to election sites helps the organizations running them improve their defenses. For those interested in the underlying traffic and attack intelligence, Cloudflare Radar provides real-time visibility into internet trends.



