DC Board of Elections says voter roll was stolen from its hosting provider
- Organization
- District of Columbia Board of Elections (DCBOE)
- Exploit
- Third-Party Data Breach
- Industry
- Government
The District of Columbia Board of Elections said it learned on October 5, 2023 that voter records had been accessed through the web server of DataNet Systems, the vendor that hosted its website. The agency stated that its own internal databases and servers were not compromised.
A group calling itself RansomedVC claimed the intrusion and advertised the data on a dark web leak site, saying it held more than 600,000 lines of United States voter information and intended to sell it to a single buyer. BleepingComputer reported that the exposed fields included names, voter and registration identification numbers, partial Social Security numbers, driver's license numbers, dates of birth, phone numbers and email addresses.
DCBOE took its website offline and ran security assessments and vulnerability scans while working with the Multi-State Information Sharing and Analysis Center's incident response team, the FBI and the Department of Homeland Security. It later engaged Mandiant to assist the investigation.
In an update issued on October 20 the board said the situation was broader than first understood. It told voters that DataNet's breached database server had contained a copy of the DCBOE voter roll and that attackers may have had access to the full roll, including personally identifiable information. DataNet had not yet determined whether the entire roll was actually accessed, when the access occurred, or how many people were affected. The board contacted all registered voters.