Microsoft detected and helped combat three hacking attempts against congressional candidates this year, marking the first cyberattack in the midterm elections.

“Recently, we discovered a fake domain that visually closely resembled the genuine Microsoft website, which was being used as a landing page for phishing attacks,” said Tom Burt, Microsoft’s vice president of security, adding, “We also saw from the metadata that these phishing attacks were targeting three candidates in the upcoming election.”.
Burt declined to name the three targeted candidates, saying that because they were people with critical social positions, they could have been interesting targets for espionage or some other type of attack.
Microsoft, in collaboration with the authorities, took down the fake domain and stopped the phishing messages on the page. It was also reported that none of the 3 victims were affected, but there has been no statement so far about the country of origin of the attack.
Microsoft and other threat researchers say the numbers have changed. During the 2016 election, the numbers were quite different, with a much higher proportion of threats coming from Russia than they are now.
This is not the first time that there have been cyberattacks during election season. A vulnerability was recently announced in vote counting systems in the US, which allowed remote login without any type of authentication. However, it is not yet known whether the vulnerability has been exploited so far, although investigations are ongoing.
