Midterm Election Traffic: What Cloudflare Saw on November 8

The 2022 US midterm elections on November 8 involved races for all 435 House seats, 35 Senate seats, and numerous gubernatorial contests. For the technology companies and government agencies tasked with protecting election infrastructure, the day represented the culmination of months of preparation against a backdrop of warnings about phishing, DDoS attacks, and state-sponsored scanning of campaign networks.

Cloudflare's involvement spans several programs: the Athenian Project protects state and local government election websites, Cloudflare for Campaigns secures political campaigns and state party infrastructure in partnership with Defending Digital Campaigns, and Project Galileo supports voting rights organizations and election results sites. For the midterms, the company also coordinated with CISA's Joint Cyber Defense Collaborative (JCDC) to provide security briefings to election officials and contributed to JCDC's Cybersecurity Toolkit to Protect Elections.

Despite public announcements from threat actors like the pro-Russia group Killnet—which successfully took some state government websites offline in the weeks before the election—and FBI notifications about Chinese hackers scanning state party websites, the anticipated large-scale attacks did not materialize on Election Day. CISA reported the morning of November 8 that it saw no specific or credible threat to disrupt election infrastructure. Cloudflare similarly identified no major attacks on that date, attributing the outcome to robust preparation by governments, nonprofits, campaigns, and municipalities.

Attack Volume and Threat Categories by Group

Cloudflare's data shows differing patterns between government election sites and campaign infrastructure in the period from October 1 through Election Day.

Protecting election groups during the 2022 US midterm elections

For the 361 election websites protected under the Athenian Project across 31 states, the numbers reflect a 31% increase in coverage since the 2020 election. Between October 1 and November 8:

  • Government election sites averaged 16,170,728 mitigated threats per day.
  • Average daily application-layer attack volume in November through Election Day was only 3.4% higher than in October.
  • The most common threat classifications for mitigated requests were HTTP anomaly, SQL injection, and software-specific CVEs.

Political campaigns and state parties protected under Cloudflare for Campaigns experienced a different trajectory. The program covered 56 House campaigns, 34 Senate campaigns, and 15 political parties. For those sites:

  • Average daily threat volume was 149,949 from October 1 through November 8.
  • Average daily application-layer attack volume in November through Election Day was over three times higher than October levels.
  • The leading mitigated request categories were HTTP anomaly, SQL injection, and directory traversal.

Pre-Election Advisories and Onboarding

In the weeks leading up to the midterms, the FBI and CISA issued multiple public service announcements on election cyber risks, including DDoS attacks and a phishing campaign targeting election officials' credentials. Those warnings were followed by a spike in attacks and an accelerated onboarding effort for campaign sites. In the week before November 8, Cloudflare said it accepted 21 Senate campaigns up for re-election into Cloudflare for Campaigns after a number of campaigns came under DDoS attack, bringing the program's total to 34 Senate campaigns.

The majority of threats that Cloudflare observed and directly assisted with occurred before Election Day, particularly following federal advisories on Killnet's targeting of US government sites. Traffic spikes remain a non-malicious concern as well; during the 2020 election, Cloudflare observed 4x spikes in traffic to government election sites.

Looking Ahead

The Athenian Project accepts applications year-round rather than only during election season. The company indicated it will publish further analysis of threats targeting election-related actors in the coming months.