Election Day 2024: Attack Volumes Rose, But Core Services Stayed Up
Cloudflare's network data from the 2024 US presidential election shows a clear pattern: malicious traffic targeting election-related infrastructure climbed sharply in the weeks before November 5, but the attacks did not succeed in taking down campaign sites, state party pages, or local government portals. Across the full election cycle, the company observed no significant outages from cyberattacks on the websites that voters rely on for registration, candidate information, and results.
The 24-hour window from October 31 to November 1 alone saw Cloudflare automatically mitigate more than 6 billion HTTP DDoS requests aimed at US election-related properties, including state and local government sites and political campaigns. That figure surpasses the total DDoS volume aimed at campaigns during all of September and October combined.
Traffic patterns on the day itself reflected the national mood. Internet usage across the US peaked just after the first polls closed, with a 15% increase over the previous week. Midwestern states saw the strongest regional growth. DNS lookups for news and polling sites surged as results came in — polling services were up 756% near poll closures, while news sites saw a 325% jump by late evening. Interest in the candidates' own web properties peaked the day before the vote, with daily DNS traffic to Trump/Republican sites rising 59% and Harris/Democrat sites up 4%.
Protection Programs Cover the Election Landscape
Cloudflare's work on election security runs through three main initiatives. Project Galileo, launched in 2014, provides free Business-level services to media and civil society groups; it currently protects more than 65 election-related US properties, including Vote America, Decision Desk HQ, and the US Vote Foundation. The Athenian Project, running since 2017, offers Enterprise-level protection to state and local election sites and now covers 423 websites across 33 states. Cloudflare for Campaigns, started in 2020 with Defending Digital Campaigns, extends protection to political operations, currently covering over 354 campaigns and 34 state-level parties.
Beyond the technical safeguards, the company briefed more than 300 election officials on emerging threats through 2024 and held 50+ calls with state and local governments to review security practices. In the weeks before Election Day, Cloudflare onboarded more than 90 campaigns and parties with Defending Digital Campaigns, and brought over 60 local media outlets into Project Galileo to keep election reporting online.
DDoS Attacks on Campaigns and Infrastructure
US political sites saw DDoS activity pick up noticeably from September onward, but the most intense attacks concentrated in the final week of the campaign. Criminal actors targeted both parties' web presences without regard for affiliation.
High-Profile Campaign Website
A series of attacks against one major campaign's website ran from October 29 through November 6. The first strike was brief — four minutes at 345,000 requests per second — but later waves were longer and larger. On October 31, an attack lasting over an hour peaked at 213,000 rps. The next day, a larger assault hit 700,000 rps, followed by two additional waves at 311,000 and 205,000 rps. Across those 16 hours spanning October 31 and November 1, Cloudflare blocked over 6 billion malicious HTTP requests. The attackers used randomized user agents and cache-busting techniques from a geodiverse set of sources. The November 1 peak also drove over 16 Gbps of bandwidth toward Cloudflare, sustaining above 8 Gbps for more than two hours.
Further waves continued through the election: 200,000 rps on November 3, 352,000 rps on November 4, 271,000 rps on Election Day itself around 14:33 ET, and a final 108,000 rps on November 6.
Campaign Infrastructure, November 3
Attackers also went after behind-the-scenes systems rather than public-facing pages. On November 3, infrastructure linked to a major campaign came under a two-minute DDoS burst reaching 260,000 malicious requests per second.
State Political Party Website
A separate attack on October 29 hit a state party's site for over four hours, from 12:00 to 17:29 ET. The assault peaked at 206,000 rps, and Cloudflare blocked more than 2 billion malicious requests total that day. The traffic pattern matched the November 1 campaign attack, with a 5.7 Gbps peak and sustained bandwidth above 3 Gbps for most of the four-and-a-half-hour window.
County-Level Targets
Local election infrastructure saw lower-intensity but persistent pressure. Sites protected under the Athenian Project absorbed over 290 million malicious HTTP requests since September 1, with 4% of all requests blocked as threats. One notable incident on September 13 targeted a county website for three hours, peaking at 46,000 malicious rps.
Attack Volumes Have Grown Sharply Since 2020
The scale of this year's attacks dwarfs what Cloudflare recorded during the previous presidential election. In October 2020, DDoS and WAF-related blocked requests for campaigns totaled nearly 100 million; November 2020 saw close to 25 million. By contrast, the first six days of November 2024 alone brought over 6 billion malicious HTTP requests in DDoS attacks targeting campaigns. Even smaller attacks remain a threat for organizations without robust protection — successful DDoS events can distract IT teams while attackers attempt other kinds of breaches.
Election Day traffic climbs as results roll in
While election days typically see only modest shifts in Internet usage, the 2024 US Election Day on November 5 broke that pattern. Traffic was consistently about 6% higher than the previous week starting from 09:15 ET (06:15 PT), likely because the US holds elections on a weekday rather than a weekend or national holiday. The first major peak came at 21:15 ET (18:15 PT), as polls began to close, when traffic hit 15% above the prior week's levels.
The most pronounced surge came later in the night. Around 01:30 ET (22:30 PT), as projections favored Trump and Fox News called Pennsylvania in his favor, traffic jumped 32% compared to the previous week. A second spike of 31% followed during Trump's victory speech between 02:30 and 02:45 ET (23:30 and 23:45 PT). For the full day, US traffic reached its highest request volume of 2024, with daily increases settling at 6% over the prior week.
Mobile device share also edged upward on Election Day, accounting for 43% of traffic versus 42% the previous week.
State-level spikes: central states lead
State-level data offers a more granular view than national figures, with traffic peaking nationwide at 21:00 ET (18:00 PT) after polling stations began closing. Unlike the presidential debates, which were broadcast nationally and drew uniform traffic increases, Election Day produced a patchwork of regional growth.
Maine, South Dakota, and Montana each saw the largest bumps at 44%, while central states generally outperformed coastal ones. Even heavily populated states like California (8%), Texas (19%), New York (22%), and Florida (23%) saw meaningful increases. Across the six key swing states—Georgia, Michigan, Nevada, North Carolina, Pennsylvania, and Wisconsin—traffic growth ranged from 17% to 36%.
DNS: news, polls, and candidate sites
Cloudflare's 1.1.1.1 resolver data shows clear category-level effects. Traffic to US news outlets climbed about 15% over the previous week starting at 09:00 ET, peaking between 22:00 and 23:00 ET with a 325% jump in DNS requests. A secondary spike occurred at 05:00 ET on November 6 at 117% above normal.
Polling services saw even sharper increases in DNS traffic—206% above normal at 13:00 ET, followed by a 756% surge at 22:00 ET once polls closed. Daily traffic to this category rose 145% on Election Day and was already up 36% the day before.
Websites dedicated to election and voting information also spiked, peaking at 12:00 ET with a 313% increase from the previous week. Daily traffic jumped 139% on Election Day and 68% on the preceding day.
Microblogging platforms such as X and Threads tracked the news cycle closely, with DNS traffic peaking at 22:00 ET—91% above the previous week—before settling to a 12% daily increase.
Interest in the candidates' own web presences was front-loaded. On November 4, daily DNS traffic to Trump and Republican websites was up 59% from the prior week, while Harris and Democrat websites rose just 4%, having seen a larger increase in the preceding week.
Email security: candidate-themed threats spike
Campaigns and candidates inevitably become targets of email-based attacks, and the 2024 race was no exception. From June 1 through November 4, Cloudflare's Cloud Email Security processed more than 19 million emails containing “Donald Trump” or “Kamala Harris” in the subject line—13.9 million for Trump and 5.3 million for Harris. Nearly half (49%) arrived since September 1. In the final ten days of the campaign, Harris appeared in 800,000 subject lines and Trump in 1.3 million.
Malicious activity followed the volume. Since June, 12% of Trump-related emails were marked as spam and 1.3% as malicious or phishing, though those rates have since fallen to 3% and 0.3% respectively since September 1. Harris-related emails saw lower overall rates at 0.6% spam and 0.2% malicious since June, climbing slightly to 1.2% and 0.2% in September. Trump was both more frequently mentioned and more often targeted by spam and malicious messages.
The broader security picture remained stable. While DDoS attacks targeted political sites and required blocking billions of requests, none caused significant disruption. As the Cybersecurity and Infrastructure Security Agency put it: “our election infrastructure has never been more secure,” with no evidence of malicious activity having a material impact on election security or integrity.



