The United States is approaching the November elections while facing two problems that increasingly overlap: renewed cyber pressure on critical infrastructure and weaker cooperation between federal cyber agencies and state election officials. The Trump administration has begun rebuilding parts of the Cybersecurity and Infrastructure Security Agency after major staff reductions, but the recovery comes as suspected Iranian activity is testing vulnerable local systems. The greater danger may not be hackers changing votes directly. It is their ability to create disruption at a moment when trust in election institutions is already fragile.
CISA entered Trump’s second term with fewer resources and less institutional stability. CBS News reported that nearly 1,000 employees, close to one third of the agency’s workforce, had left or been removed from active service by mid 2025. Homeland Security Secretary Markwayne Mullin later moved to reverse part of that contraction, and Senator Mark Warner announced that the department planned to restore about 600 positions. The hiring push may rebuild technical capacity, but experienced partnerships cannot be recreated as quickly as positions can be filled.
Water attacks expose a wider weakness
Recent attacks on American water systems show why timing matters. More than 30 community water systems in Minnesota were targeted in a coordinated cyberattack, with some facilities temporarily losing automated functions or moving to manual operations. Investigators have examined whether Iranian actors were responsible, although federal authorities have not publicly confirmed attribution.
The vulnerability is not new. The Government Accountability Office recently warned that many water utilities struggle with aging technology, workforce shortages, limited budgets, and operational equipment linked to internet enabled systems. Those conditions give foreign actors relatively inexpensive ways to create physical disruption inside the United States. CISA has previously documented Iranian linked groups exploiting poorly protected industrial controllers used by American water facilities.
Iran also fits a broader national security concern. The Office of the Director of National Intelligence assesses that Iran, China, Russia, North Korea, and criminal groups will continue trying to compromise American government networks and critical infrastructure. Cyber operations give Tehran an asymmetric option when direct military retaliation carries greater risks.
Election systems face a different kind of threat
A cyberattack does not need to alter ballots to affect an election. The Election Assistance Commission explains that American elections rely on decentralized systems, physical safeguards, audits, testing, and multiple layers of security. That structure makes nationwide manipulation of vote totals extremely difficult. But voter registration databases, government websites, communications systems, and unofficial election reporting remain possible targets for disruption.
The federal relationship with election officials has become another vulnerability. Democratic senators requested stronger coordination after saying that requests for election threat briefings from CISA and the FBI had gone unanswered. Former CISA director Christopher Krebs later said that state officials had received dozens of classified briefings during the 2020 election cycle but none that he could identify during the current administration.
That breakdown creates an opening that technical defenses alone cannot close. Foreign actors can exploit uncertainty by attacking public websites, delaying services, leaking stolen information, or simply claiming responsibility for incidents they did not cause. If federal agencies and state officials distrust one another, confirming what happened and communicating it quickly becomes harder.
The administration’s attempt to rebuild CISA recognizes that cyber capacity cannot remain secondary during a period of heightened confrontation with Iran. Yet the immediate challenge is not only recruiting specialists. Washington must restore information sharing and working relationships with the officials who actually run elections and local infrastructure. Without that cooperation, even a limited cyberattack could achieve something more valuable than changing votes: convincing Americans that the system itself cannot be trusted.
Original analysis inspired by Nick Miroff and Yvonne Wingett Sanchez from The Atlantic. Additional research and verification conducted through multiple sources.
By ThinkTanksMonitor