Executive Summary
A previously disclosed vulnerability in voting systems used across 21 U.S. states, including Georgia, was exploited using AI tools during the May 2026 primary election to recover the chronological order of ballots cast. The attack required only publicly available data sources - early voting lists and cast-vote record (CVR) files - combined with AI coding agents to analyze voter behavior patterns. No direct access to voting machines, networks, or source code was necessary, demonstrating how AI amplifies the exploitation of known vulnerabilities in critical infrastructure.
This incident highlights the growing intersection of AI capabilities with election security vulnerabilities, as threat actors increasingly leverage automated tools to exploit weaknesses in democratic processes and critical infrastructure systems.
Why This Matters Now
AI tools are democratizing the exploitation of known vulnerabilities in critical infrastructure, transforming theoretical security flaws into practical threats that can be executed with minimal technical expertise using publicly available data.
Attack Path Analysis
Attacker exploited a voting system vulnerability using AI tools to analyze publicly available early-voting lists and cast-vote record (CVR) files, reconstructing ballot order without directly accessing voting machines or networks. The attack leveraged data correlation techniques to de-anonymize voting patterns, potentially exposing individual voter behavior through cross-referencing temporal voting data with ballot selections.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker obtained publicly available early-voting lists and CVR files from Georgia counties through legitimate data requests, identifying the vulnerability disclosure paper as attack methodology
MITRE ATT&CK® Techniques
Data from Information Repositories
Gather Victim Identity Information: Email Addresses
Gather Victim Network Information: Domain Properties
Acquire Infrastructure: Domains
Data Staged: Local Data Staging
Ingress Tool Transfer
System Owner/User Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Data Classification and Protection
Control ID: Data Pillar - Categorical Protection
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Voting system vulnerabilities enable ballot order recovery through AI analysis of public CVR files, compromising voter privacy and election integrity processes.
Computer Software/Engineering
AI coding agents can exploit disclosed vulnerabilities in election systems, highlighting risks in automated security analysis and data correlation capabilities.
Legal Services
Election data exposure creates legal compliance risks around voter privacy protection and potential challenges to election result verification processes.
Information Technology/IT
Demonstrates how public data sources combined with AI tools can compromise system security without direct network access or exploitation.
Sources
- Security Vulnerability in a Voting Systemhttps://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.htmlVerified
- CISA Election Security Informationhttps://www.cisa.gov/topics/election-securityVerified
- Georgia Secretary of State Elections Division CVR Fileshttps://sos.ga.gov/page/cast-vote-recordsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the attacker's ability to expand data collection across multiple counties and limit cross-correlation analysis by restricting lateral movement between data processing environments and controlling egress to external AI services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric would likely have limited the attacker's ability to aggregate and process voting data across distributed cloud environments through workload isolation and identity-aware access controls.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained the scope of data processing capabilities by limiting access between different analytical workloads and reducing the blast radius of correlation activities.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have limited the attacker's ability to move collected voting data between different analytical environments and constrained cross-correlation processing across multiple data sources.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely have constrained the attacker's ability to utilize distributed AI services for data correlation by limiting cross-cloud communication and reducing analytical processing capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have limited the attacker's ability to extract processed voting analysis results and constrained outbound data transfer of de-anonymized voter behavior patterns.
While the foundational privacy vulnerability in voting data publication would remain unaddressed, the scope of successful data correlation and analysis would likely be significantly constrained through limited processing capabilities.
Impact at a Glance
Affected Business Functions
- Election Administration
- Voter Privacy Protection
- Public Trust in Electoral Process
- Ballot Processing Systems
Estimated downtime: N/A
Estimated loss: N/A
Voting pattern correlation data exposing ballot casting order in Georgia primary elections across 21 states using affected scanners. While no personally identifiable information was directly exposed, the vulnerability allows inference of voter behavior patterns through AI-assisted analysis of publicly available early-voting lists and cast-vote record files.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security controls to monitor and restrict unauthorized data correlation activities involving sensitive public datasets
- • Deploy threat detection capabilities to identify anomalous AI-driven data processing patterns that may indicate privacy violation attempts
- • Establish zero trust segmentation around data analysis environments to prevent unauthorized cross-referencing of sensitive datasets
- • Enable encrypted traffic monitoring to detect potential exfiltration of processed voting analysis data to external AI services
- • Implement multicloud visibility controls to monitor AI agent activities and detect suspicious automation patterns in data processing workflows



