The EAC company responsible for the US voting and certification systems has been breached, according to a publication by security firm Recorded Future. The report was further documented by TechCrunch, as well as the US Election Assistance Commission (EAC) itself confirming a “probable intrusion” that coincided with the US Presidential Election.
The US Election Assistance Commission (EAC) was established in 2002 as part of the Help America Vote Act (HAVA), a piece of legislation signed by President Bush to prevent the disaster that Florida experienced in the 2000 election. Back then, more than two million ballots were invalidated because the systems had given multiple or no votes.
So today the EAC manages the testing, maintenance and certification of these machines, as well as the costs, ordering new machines and maintaining the Voter Registration form.
The EAC hack is not the same as a breach of a voting system, and so the hack is not believed to have played any role in the election of the new President. But it is still disturbing, and something that is certainly of concern to the CIA, which believes that Russia is behind the hack.
Earlier this month, security firm Recorded Future conducted an independent investigation that led to the discovery of a hacker by the name of “Rasputin.” The hacker was attempting to sell over a hundred connections to these systems, while also offering an unpatched exploit on the EAC international website. The SQL vulnerability has since been patched.
It may be funny, but Rasputin speaks Russian. Of course, that doesn't mean he's necessarily from Russia or that he works for the Russian government.
