Report on the Investigation into Russian Interference in the 2016 Presidential Election · 2019
Intrusions Targeting the Administration of U.S. Elections
Intrusions Targeting the Administration of U.S. Elections
¶In addition to targeting individuals involved in the Clinton Campaign, GRU officers also targeted individuals and entities involved in the administrntion of the elections. Victims included U.S. state and local entities, such as state boards of elections (SBOEs), secretaries of state, and county governments, as well as individuals who worked for those entities. 186 The GRU also targeted private technology fnm s responsible for manufacturing and administering election-related software and hardware, such as voter registration software and electronic polling stations. 187 The GRU continued to target these victims through the elections in November 2016. While the investigation identified evidence that the GRU targeted these individuals and entities, the Office did not investigate fmt her. The Office did not, for instan ce, obtain or examine servers or other relevant items belonging to these victims. The Office understands th at the FBI, the U.S. Depaitment of Homelan d Security, and th e states have sepai·ately investigated that activity.
¶By at least the summer of 2016, GRU officers sought access to state and local computer networks by exploiting known software vulnerabilities on websites of state and local governmental entities. GRU officers, for example, tai·geted state and local databases of registered voters using a technique known as "SQL injection," by which malicious code was sent to the state or local website in order to nm commands (such as exfiltrating the database contents). 188 In one instance in approximately June 2016, the GRU compromised the computer network of the Illinois State Board of Elections by exploiting a vulnerability in the SBOE 's website. The GRU then gained access to a database containing infon nation on millions of registered Illinois voters, 189 and extracted data related to th ousands of U.S. voters before the malicious activity was identified. 190
GRU officers that scanned state an d local websites for · od in July 2016, GRU officers - for vulnerabilities on websites ofmore than
¶-Unit 74455 also sent speaiphishing emails to public officials involved in election administration and personnel at companies involved in voting technology. In August 2016, GRU officers tai·geted employees of VR Systems, a voting technology company that developed software used by numerous U.S. counties to manage voter rolls, and installed malware on the company network. Similarly, in November 2016, the GRU sent spea1phishing emails to over 120 email accounts used by Florida county officials responsible for administering the 2016 U.S. election. 191 The speaiphishing emails contained an attached Word document coded with malicious softwai·e (commonly referred to as a Trojan) that permitted the GRU to access the infected computer. 192 The FBI was sepai·ately responsible for this investigation. We understand the FBI believes that this operation enabled the GRU to gain access to the network of at least one Florida county government. The Office did not independently verify that belief and, as explained above, did not unde1i ake the investigative steps that would have been necessaiy to do so.
51Trump Campaign and the Dissemination of Hacked Materials
¶The Trnmp Campaign showed interest in WikiLeaks 's releases of hacked materials throughout the summer and fall of 2016. Trnmp associate Roger Stone made several attempts to contact WikiLeaks founder Assange, boasted of his access to Assange, and was in regulai· contact with Campaign officials about the releases that Assange made and was believed to be planning. The investigation was unable to resolve whether Stone played a role in WikiLeaks 's release of the stolen Podesta emails on October 7, 2016, the same day a video was published of candidate Tnnnp using graphic language about women years eai·lier.