U.S. 2020 Election-Themed Ransomware Attacks Are on Their Way – And Local Govt's Aren’t Prepared

Stu Sjouwerman | Jan 31, 2020

ransomware-screen-skull-1New research shows local governments practice a distinct lack of cybersecurity preparedness. And with local, state, and national elections coming up this year, cyberattacks are a concern.

In a recent post, anti-malware vendor Emisoft sounded the call for both private and public sector businesses to be on the lookout for cyberattacks leveraging themes related to upcoming elections - from campaign fundraising to promoting stories about candidates, the possibilities are endless. And, given the heightened political tensions that exist in the U.S., potential victims are already emotionally charged enough to respond to phishing and web-based attacks.

According to a 2019 University of Maryland, Baltimore County (UMBC) report, state and local government are grossly underprepared:

  • Slightly over one-third of government organizations have no idea how often security incidents occur
  • Over two-thirds are unaware of the frequency of actual data breaches
  • Less than half keep track of attacks

In essence, government operations, by definition, aren’t security-minded.

Put these two issues together and you have the makings of attacks that can damage, alter, or cripple elections at a state and local scale. Even ransomware attacks today are expanding operations to attack beyond simply encrypting data and holding it for ransom. Attacks now include stealing data and using extortion to improve the chances of a paid ransom, as well as hacking victim networks, which can give entrée to other kinds of attacks.

Both public and private sector organizations need to move forward with operations that include a security mindset. Layered security, data protection, Security Awareness Training, and endpoint protection are all necessary parts of proven security execution. But, in the case of state and local governments, it’s going to need to start at the top with a tough stance on cybersecurity in order to see necessary changes made throughout the organization.

Topics: Ransomware

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.