US Agency Meant to Keep Voting Machines Secure Was Itself Hacked

Advertisement
By Reuters | Updated: 17 December 2016 17:32 IST

The US agency charged with ensuring that voting machines meet security standards was itself penetrated by a hacker after the November elections, according to a security firm working with law enforcement on the matter.

The security firm, Recorded Future, was monitoring underground electronic markets where hackers buy and sell wares and discovered someone offering log-on credentials for access to computers at the US Election Assistance Commission, company executives said.

Posing as a potential buyer, the researchers engaged in a conversation with the hacker, said Levi Gundert, vice president of intelligence at the company, and Andrei Barysevich, director of advanced collection.

Advertisement

Eventually they discovered that the Russian-speaking hacker had obtained the credentials of more than 100 people at the election commission after exploiting a common database vulnerability, the researchers said.

Advertisement

The hacker was trying to sell information about the vulnerability to a Middle Eastern government for several thousand dollars, but the researchers alerted law enforcement and said Thursday that the hole had been patched.

The Election Assistance Commission said in a statement late Thursday that it had become aware of a "potential intrusion" and was "working with federal law enforcement agencies to investigate the potential breach and its effects."

Advertisement

"The FBI is currently conducting an ongoing criminal investigation," the statement added.

The election commission certifies voting systems and develops standards for technical guidelines and best practices for election officials across the country.

Advertisement

The researchers said the hacker had an unusual business model, scanning for ways to break into all manner of businesses and other entities and then moving rapidly to sell that access, rather than stealing the data himself.

"We don't think he actually works for any government or is super sophisticated," Barysevich said.

In the case of the election commission, the hacker used methods including an SQL injection, a well known and preventable flaw, obtaining a list of user names and obfuscated passwords, which he was then able to crack.

Though much of the commission's work is public, the hacker gained access to non-public reports on flaws in voting machines.

In theory, someone could have used knowledge of such flaws to attack specific machines, said Matt Blaze, an electronic voting expert and professor at the University of Pennsylvania.

The researchers were confident that the hacker moved to sell his access soon after getting it, meaning that he was not inside the system before election day.

The US voting process is decentralized and there were no reports of widespread fraud in November.

The Election Assistance Commission was created by the Help America Vote Act of 2002 and is led by presidential appointees.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme P4 Power 5G Launch Today: Know Price in India, Specs and More
  2. Redmi Note 15 Pro Series Launch Today: Know Price in India, Specs and More
  3. Why the Redmi Note Remains Xiaomi's Easiest Recommendation
  4. Clawdbot (Now Moltbot) Explained: What is It and Why is It Going Viral?
  5. UIDAI's New Aadhaar App Lets You Easily Update Mobile Number, Address
  6. Apple Watch Hypertension Notifications Are Now Available in These Countries
  7. NASA Tests Nuclear Rocket Engine Designed for Faster Deep-Space Missions
  8. How to Share Your Contact Card With New Aadhaar App: A Step-by-Step Guide
  9. QCY SP7 Bluetooth Speaker Review
  10. How to Change Your Mobile Number and Address Using New Aadhaar App
  1. Realme P4 Power 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Redmi Note 15 Pro 5G, Redmi Note 15 Pro+ 5G Launching Today: Know Price in India, Features, Specifications and More
  3. Amazon Axes 16,000 Jobs as It Pushes AI and Efficiency
  4. Google AI Plus Plan Expanded Globally as the Most Affordable Gemini Subscription
  5. Redmi Note 15 Pro Series Colourways and Memory Configurations Listed on Amazon
  6. New ALMA Images Reveal Complex Rings Left Behind by Planet Formation
  7. BSNL Bharat Connect Prepaid Plan With 365-Day Validity Launched; Telco's BSNL Superstar Premium Plan Gets Price Cut
  8. Samsung Galaxy S26 Series Listed on US FCC Database With Support for Satellite Connectivity
  9. NASA Tests Nuclear Rocket Engine Designed for Faster Deep-Space Missions
  10. Hidden in Plain Sight: New Report Reveals Dozens of Nudify Apps in Major App Stores
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.