Skip to content
Threats

How foreign election interference works

Intermediate10 min read

Foreign election interference is a foreign state acting to shape another country's vote. It runs on a small toolkit: hacking election or party systems, stealing and leaking documents, running covert information operations, moving money in secret, and impersonating trusted institutions. It usually works on what voters see and believe, and rarely changes the count itself.

In this article

Interference targets minds and machines, rarely the tally

"Foreign interference" sounds like a single dark act — a switch flipped somewhere to change who wins. The documented reality is more mundane and more useful to understand: interference is a small toolkit, used over and over, that mostly works on the environment around a vote rather than the count inside it.

The reason is structural. As how votes are counted shows, the tally is defended in depth — by paper records, chain of custody, reconciliation, and audits — so changing it undetectably from outside is extraordinarily hard. What is far easier to reach is everything around the vote: what people read, whom they trust, and what dominates the last news cycle before they decide. That is where interference concentrates its effort.

The toolkit

Almost every documented operation is a combination of five techniques:

TechniqueWhat it doesDocumented example
Cyber intrusionBreak into election, party, or campaign systemsProbing of U.S. state voter systems, 2016
Hack-and-leakSteal private material and release it for effectDNC/Podesta emails (2016); MacronLeaks (2017)
Information operationsCoordinated inauthentic content to shape opinionInternet Research Agency troll farm (2016)
Impersonation / forgerySpoof real outlets and institutionsGhostwriter; Doppelganger cloned news sites
Covert financeMove money secretly to favoured actorsAlleged across multiple European contests

Cyber intrusion and hack-and-leak

The two cyber techniques usually work together. First, intrusion: attackers get into email or document systems belonging to a party, campaign, or election body. Then, hack-and-leak: the stolen material is released — often selectively, and timed for maximum damage.

The 2016 U.S. presidential election is the reference case. U.S. intelligence assessed that Russian military intelligence (the GRU) hacked Democratic Party systems and released the material through intermediaries, while separately probing state voter-registration systems. Crucially, the same assessment found the systems that actually tally votes were not altered — the intrusion reached the environment, not the count.

France, 2017 shows the same playbook against a different target: the eventual winner's campaign was hacked and a large cache of emails dumped online barely a day before the vote, inside the legal reporting blackout. The timing was the weapon. But French media and voters largely declined to amplify it, and the leak landed with little effect — a reminder that these operations depend on a receptive audience they do not always get.

Information operations and impersonation

If hack-and-leak supplies ammunition, information operations supply the crowd. The clearest example is the Internet Research Agency, a St Petersburg "troll farm" that ran large-scale inauthentic social-media activity impersonating American voters and groups — later detailed in a U.S. criminal indictment naming the organisation and its financiers.

The frontier since then has been impersonation: making foreign content look like trusted local sources. Two operations catalogued in this database show the range. Ghostwriter fabricated content and planted it via compromised sites and spoofed identities, targeting audiences across Poland, the Baltics, and Germany. Doppelganger went further, cloning the actual domains and layouts of real Western news outlets to publish fake articles under a borrowed masthead. Both are examples of coordinated inauthentic behaviour — the tell is not the content of any single post but the hidden coordination behind many of them.

What interference can and cannot do

Holding the toolkit in view makes the limits clear:

  • It can flood the last news cycle, launder a narrative into trusted-looking outlets, steal and time-release embarrassing material, and deepen existing divisions.
  • It struggles to change a properly run count, because the tally is protected by layers that an outside actor cannot easily reach or hide within.

This is why lumping interference together with a falsified count — the mistake the five meanings of "fraud" warns about — gets the threat exactly wrong. Treating a genuine influence operation as proof the count was faked both overstates one problem and distracts from the other.

How interference is attributed

Naming the state behind an operation is its own discipline. Investigators combine technical forensics — shared infrastructure, malware, language and timing patterns — with intelligence reporting and, in the strongest cases, criminal indictments that name specific officers. International bodies such as the EU's diplomatic service now publish structured threat reports under the label FIMI (foreign information manipulation and interference).

The result is always a graded judgement, not a binary. A careful record states the confidence level — from tentative technical overlap up to a formal indictment — rather than asserting a certainty the evidence does not support, exactly as the interference-is-not-fraud framework insists.

Reading an interference claim

When you meet a claim that a foreign power "interfered," turn it into specific questions:

  • Which technique is alleged — intrusion, leak, information operation, forgery, finance?
  • What did it target — the count, or the environment around it?
  • Who attributed it, and at what confidence — a named agency, an indictment, a platform report, or an anonymous assertion?
  • What effect is actually claimed — that minds were influenced, or that votes were changed?

Answer those, and a vague fear of "meddling" resolves into something you can weigh — which is the only way to take real interference seriously without being manipulated by the fear of it.

Frequently asked questions

Can a foreign country change the actual vote count?

It is possible in principle but very hard in practice, and rarely what interference tries to do. Changing a count undetectably means defeating the chain of custody, reconciliation, and audits against paper all at once. In the best-documented cases, foreign actors targeted the information environment and party systems, not the tallying of votes.

What is a hack-and-leak operation?

Attackers break into email or document systems, steal private material, and release it — often selectively and at a chosen moment — to damage a target. The 2016 U.S. and 2017 French elections both saw hack-and-leak operations timed to the final days of the campaign.

How do investigators know which country was behind an operation?

Through attribution: combining technical forensics (infrastructure, malware, timing) with intelligence and, sometimes, criminal indictments naming specific officers. Attribution is expressed in confidence levels, from tentative to formally charged, and a careful record reports that level rather than stating certainty it does not have.

Is foreign interference the same as election fraud?

No. Interference acts on the environment around an election; fraud, in its strict sense, means the count was falsified. An election can be heavily targeted by a foreign state and still produce an accurate count. Keeping the two separate is essential to describing either one honestly.

Sources

  1. 1.Assessing Russian Activities and Intentions in Recent US Elections (ICA 2017-01D)U.S. Office of the Director of National Intelligence (2017-01-06)
  2. 2.United States v. Internet Research Agency et al. (indictment)U.S. Department of Justice (2018-02-16)
  3. 3.United States v. Netyksho et al. (GRU officers, indictment)U.S. Department of Justice (2018-07-13)
  4. 4.1st EEAS Report on Foreign Information Manipulation and Interference ThreatsEuropean External Action Service (EEAS) (2023)
Written by VoteRights EditorialReviewed by VoteRights standards deskLast reviewed

Continue learning

Related cases in the database