|8 min read|Yvann Lièvre

Elections and Cybersecurity: Lessons from 2024-2025

Electoral interference by Midnight Blizzard and APT28, social media manipulation, political deepfakes, voting infrastructure protection. ANSSI and VIGINUM.

ÉlectionsAPT

The 2024-2025 electoral cycles were the most targeted in history in terms of cyberattacks and influence operations. US presidential election, European elections, national elections in Romania: the post-mortems reveal systemic threats against democracies.

Interference actors

Midnight Blizzard (ex-Nobelium/APT29)

Attributed to Russia's SVR (foreign intelligence service), Midnight Blizzard is the group behind the 2020 SolarWinds attack. In 2024, Microsoft revealed the group had compromised email accounts of Microsoft executives themselves, accessing communications with US government agencies. Their operations systematically target Western democratic processes.

APT28 / Fancy Bear

Linked to Russia's GRU (military intelligence), APT28 is the group that hacked the US DNC in 2016. In 2024-2025, the group intensified operations against European institutions, targeting political parties, think tanks, and media outlets. ANSSI documented intrusion attempts against French entities linked to the European elections.

Social media manipulation

Informational influence operations reached an industrial scale:

  • Automated account farms: networks of thousands of fake accounts amplify divisive narratives on X (ex-Twitter), Facebook, TikTok, and Telegram

  • Coordinated campaigns: the Doppelganger network (attributed to Russia) created fake sites cloning legitimate media (Le Monde, Der Spiegel) to spread disinformation

  • Algorithmic exploitation: polarizing content is amplified by recommendation algorithms, creating a multiplier effect for influence operations

Deepfakes: the new frontier

Generative AI has democratized the creation of convincing deepfakes. In 2024, audio deepfakes of political leaders were used to spread false messages in multiple electoral campaigns worldwide. The cost of creating a convincing deepfake dropped from thousands of dollars to less than $50 in two years, thanks to open source models.

Deepfake detection remains a major technical challenge. Current detection tools have significant error rates on the latest model generations, creating an arms race between creators and detectors.

ANSSI and VIGINUM: the French response

VIGINUM

The Service for Vigilance and Protection Against Foreign Digital Interference (VIGINUM), created in 2021 under the SGDSN, is responsible for detecting and characterizing foreign digital interference operations. VIGINUM monitors online platforms to identify informational manipulation campaigns targeting France.

ANSSI

ANSSI handles the technical cybersecurity aspect of elections: securing political party IT systems, auditing voting platforms, protecting result dissemination infrastructure. During the 2024 European elections, ANSSI offered cybersecurity support to political parties and candidates.

Protecting voting infrastructure

Electoral systems are critical infrastructure requiring enhanced security:

  • Voting systems: in France, paper voting remains the rule, limiting the risk of direct manipulation. Electronic voting for French citizens abroad undergoes strict security audits

  • Results systems: result transmission and aggregation are potential targets (DDoS, data manipulation)

  • Electoral rolls: voter databases are targets for data theft and targeted disinformation

Lessons for organizations

Electoral interference techniques are directly applicable to the business world:

  • Targeted spear-phishing: the same APT28 techniques target business executives. CTI monitoring helps detect ongoing campaigns

  • Executive deepfakes: CEO fraud cases using audio/video deepfakes are documented. Awareness and verification procedures are essential

  • Disinformation: reputational attacks through fake content creation also affect businesses

  • Continuous monitoring: ThreatClaw's audit tools and monitoring detect phishing campaigns and account compromises in real time

FAQ

Is electronic voting safe?

The cybersecurity expert consensus remains cautious. Paper voting offers guarantees of transparency and auditability that electronic voting cannot match today. France maintains paper voting for national elections, except for citizens abroad where electronic voting is offered under strict audit conditions.

How to detect a deepfake?

Several technical indicators: lip movement inconsistencies, visual artifacts around the face, file metadata, absence of verifiable source. Detection tools exist (Microsoft Video Authenticator, Sensity) but their reliability remains limited against the latest generations. The best defense remains source verification.

Can my company be targeted by these APT groups?

If your company operates in a strategic sector (defense, energy, technology, media, finance) or works with governments, yes. APT28 and Midnight Blizzard also target the private sector for economic intelligence. Appropriate monitoring is essential.

What does VIGINUM actually do?

VIGINUM detects and characterizes information manipulation operations involving foreign actors targeting French public debate. It does not surveil French citizens but monitors coordinated inauthentic behavior on online platforms (fake accounts, bot networks, organized disinformation campaigns).

Related articles