Category Overview

Attack Methods — Election Security Glossary

24 election security terms in the Attack Methods category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.

Browse all 24 terms in Attack Methods

Ransomware

A type of malware that blocks access to a system, device, or file until a ransom is paid.

Low consensus7 sources

Phishing

A technique for attempting to acquire sensitive data, such as bank account numbers, through a fraudulent solicitation in email or on a web site, in which the perpetrator…

Medium consensus6 sources

Social Engineering

An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.

Medium consensus6 sources

Spear Phishing

A targeted attack by hackers, via bogus emails, that attempts to get the victim to provide login information or personal information to the hackers.

Medium consensus6 sources

Trojan Horse

A computer program that appears to have a useful function, but also has a hidden and potentially malicious function that evades security mechanisms, sometimes by exploiting…

Medium consensus6 sources

Dox

Publish damaging or defamatory information about an individual or organization on the Internet.

Medium consensus4 sources

Computer Network Attack (cna)

Actions taken through the use of computer networks to disrupt, deny, degrade, or destroy information resident in computers and computer networks, or the computers and networks…

Medium consensus3 sources

Exploit

A technique to breach the security of a network or information system in violation of security policy.

Low consensus3 sources

Penetration

See intrusion.

Medium consensus3 sources

Reconnaissance

the phase of an attack where an attacker gathers information on, and maps networks, as well as probing them for exploitable vulnerabilities in order to hack them.

Medium consensus3 sources

Zero Day Attack

An attack that exploits a previously unknown hardware, firmware, or software vulnerability.

Medium consensus3 sources

Attack Method

Attack methods are specific techniques adversaries use to achieve tactical goals, such as gaining initial access, stealing credentials, or moving through a network.

Low consensus2 sources

By ESG Editorial Team · Drawing on MITRE ATT&CK, CISA advisories, and 25+ sources on election-targeted threats

Attack methods are the techniques adversaries use against election infrastructure. They span the full range of cyber and physical activity: phishing, malware deployment, denial-of-service, supply chain compromise, insider threat, physical intrusion, influence operations, and disinformation. No single defense addresses all of them. Defending against the full range requires knowing what the threats are.

Why this category matters for election security is that defenders cannot prioritize what they do not understand. The threat intelligence community publishes indicators of compromise, advisories, and reports of observed activity. The most useful of these are election-specific: not just "ransomware is active" but "ransomware has been observed targeting county government networks that support elections."

The taxonomy of attack methods is not fixed. Adversaries develop new techniques as defenders close off old ones. Election infrastructure is a specific target with specific characteristics, and the threats to it are correspondingly specific. Phishing against a county election office is not the same as phishing against a bank. The vocabulary here reflects that specificity.

The terminology in this category covers the major categories of attacks that have been observed against election infrastructure. The concepts here are descriptive. They name the threats so they can be discussed and defended against.

How These Terms Relate

These concepts together describe the threat landscape that election infrastructure faces. The terminology here draws on the broader cybersecurity vocabulary, but applied to the election context. The unifying theme is that named threats are addressable threats. A jurisdiction that knows what it faces can plan for it. The category does not rank threats by likelihood: the threat a given election office faces depends on its size, its visibility, its connectedness, and the resources of its adversaries.

Related categories

Can't find the right category?

Search the full glossary, or browse every term alphabetically instead.