Moldova’s Election Day: Defending the Vote, Not Just Counting It

On September 28, 2025, the Republic of Moldova held a pivotal parliamentary election, widely seen as a test of the nation's geopolitical direction between pro-European and pro-Russian factions. The democratic process unfolded under the shadow of significant foreign interference, with reports of disinformation, illegal funding, and coordinated digital threats. While cyberattacks were not the decisive story of the day, ensuring the resilience of election infrastructure was a critical priority, allowing citizens to access authoritative results in real time.

In the days leading up to the vote, Cloudflare onboarded the Moldovan Central Election Commission (CEC) under the framework of its Athenian Project, which has provided security for over 450 U.S. state and local election entities since 2017. The onboarding, completed in under a week, involved protecting a suite of election websites and deploying mitigation strategies to prepare for election day traffic and threats.

An Attack Timeline: From Polls to Final Results

Cloudflare’s data reveals a sustained and sophisticated attack campaign aimed at the CEC, stretching from September 27 to September 29, 2025. The core assault took place on election day itself, with a series of concentrated, high-volume DDoS attacks that began at 09:06:00 UTC and persisted for over twelve hours, ending at 21:34:00 UTC as official results were being reported.

Over that period, Cloudflare mitigated more than 898 million malicious requests directed at the CEC.

BLOG-3057 image 1

The attacks were not singular events but organized into distinct waves—referred to as 11 attack "chunks"—indicating a multi-wave strategy. One of the most intense periods, Chunk 5, struck at 15:31:00 UTC during peak afternoon voting hours, recording the largest peak of 324,333 requests per second (rps).

BLOG-3057 image 3

Despite the polls closing at 18:00 UTC, the malicious traffic did not let up. Further sustained waves, with peaks exceeding 243,000 rps, targeted the result reporting phase. Cloudflare’s automated defenses neutralized these attacks in real-time, keeping the CEC website stable and accessible for Moldovan citizens.

The Moldovan government corroborated the scale of the assault. The Information Technology and Cybersecurity Service (STISC) reported a wide-ranging campaign against the CEC.md platform, government cloud systems, and diaspora voting stations. STISC confirmed the attacks were neutralized with no impact on the availability or integrity of electoral services.

“On behalf of the Information Technology and Cybersecurity Service (STISC), the institution technically responsible for ensuring cybersecurity of the electoral process conducted by the Central Electoral Commission of the Republic of Moldova on 28 September, we would like to extend our sincere gratitude for your outstanding support. We truly appreciate the opportunity to use your advanced systems and enterprise licenses during this critical period. Despite facing numerous DDoS attacks, thanks to your effective protection, no service interruptions were experienced, and the public remained unaffected.” - STISC Team, Information Technology and Cybersecurity Service, Republic of Moldova

“Cloudflare’s support was essential for Moldova’s parliamentary elections, ensuring uninterrupted access to real-time results for citizens at home and abroad. Their resilient infrastructure allowed us to withstand heavy DDoS attacks and protect the integrity of the democratic process.” - Anatolie Golovco, Cybersecurity and Digital Transformation Expert in the Office of the Prime Minister of Moldova

Beyond the Election Commission: A Broader Campaign

While the CEC was the primary target, it was far from the only one. Cloudflare mitigated hundreds of millions of malicious requests aimed at a broader set of Moldovan election-related, civic, and media websites on September 28. These included a civic participation portal, democracy-related services, a broadcaster, and independent news outlets.

BLOG-3057 image 4

The Commission’s site absorbed the largest share of traffic, nearing 900 million requests in a single day. It was joined, however, by significant DDoS traffic against civic and media infrastructure. One particularly intense application-layer wave hit a democracy-related parliamentary site, peaking at over 243,000 requests per second.

BLOG-3057 image 5

The attack patterns against these secondary targets mirrored those directed at the election authority, suggesting a coordinated effort to disrupt both the official election processes and the public information channels voters depend on. Cloudflare’s automated protections mitigated these multi-wave attacks in real-time, ensuring critical information channels remained available throughout the electoral timeline.

In the aftermath, the pro-Western governing party secured a clear majority in the Moldovan parliament. The successful defense of the election infrastructure underscores the growing importance of proactive security measures for democratic processes, ensuring that citizens—not malicious actors—have the final say in determining their nation’s future. The Athenian Project remains a cornerstone of such efforts, extending its protection to democracies worldwide.