Skip to main content
Election Security8 min read

Can Israel's 2026 Election Be Hacked? What the Real Cyber Threat Looks Like

A sober threat map for Israel's 2026 election: what paper ballots protect, and how accounts, websites, suppliers, leaks and influence operations can still cause harm.

#Elections 2026#Cybersecurity#Election Security#Disinformation#Israel

Can someone hack Israel's election? The question sounds as if it should have a simple yes or no answer. It also summons a familiar movie scene: an attacker reaches one central computer, changes numbers on a screen, and quietly replaces the voters' decision. That is dramatic, but it is the wrong starting point for understanding an Israeli election.

At an ordinary polling station, a voter goes behind a screen, selects a paper ballot slip, places it in an envelope, and puts the envelope into a physical ballot box. After voting ends, the polling-station committee counts the slips at the station. The Central Elections Committee's official voter information describes a committee that supervises the process from voting through the completion of the count.

That physical process sharply limits the movie scenario in which someone abroad remotely rewrites millions of votes with a keystroke. It does not make the wider election immune to cyber harm. Around the paper ballot sits a large digital environment: email accounts, phones, public-information websites, databases, cloud suppliers, campaign teams, news organisations, and social platforms. Sometimes an attacker's real goal is not to change a vote. It is to change what people believe happened.

First, what does 'hacking an election' actually mean?

A useful answer starts by separating four objectives. An attacker may succeed at one without getting anywhere near the other three:

  1. Integrity: changing, deleting, or falsifying information. The target could be a campaign document, a website notice, or an operational record. It does not automatically mean ballot papers were altered.
  2. Availability: making a website, service, or communication channel unavailable when people need it. Even a short outage can create pressure and a vacuum for rumours.
  3. Confidentiality: stealing messages, contact lists, campaign plans, or personal data for intelligence, coercion, or a timed release.
  4. Authenticity and trust: impersonating a known source, publishing a fabricated recording, or leaving the public unsure which account, document, or announcement is genuine.

This distinction matters because an election is both a process and a public story about that process. An attacker does not need to control the result to gain something valuable. If people spend several hours wondering whether an official site has failed, an emergency notice is real, or a video is authentic, the confusion itself can serve a strategic purpose.

The ballot is only one part of the election

In Israel's ordinary process, the choice is recorded on a physical slip inside an envelope. When voting closes, the polling-station committee opens valid envelopes, displays and reads each slip, records the count, and documents the result. The Central Elections Committee's official polling-station secretary guide says the count begins immediately after voting, takes place at the polling station, and is performed by committee members under the secretary's supervision and recorded in a protocol.

That physical procedure has security value: it creates tangible evidence and distributes counting across many polling stations. It is why the idea of one national 'voting server' is misleading. But it would be equally misleading to conclude that everything around an election is manual. Voter information, campaign work, communications, suppliers, and public debate depend heavily on connected systems and connected people.

Seven realistic cyber targets around an election

  1. Campaign and party email accounts: One convincing phishing message can lead to a stolen password or a mailbox takeover. An intruder may read plans, collect documents, impersonate a colleague, or send credible-looking instructions. The harm is not limited to secrecy. A compromised real account gives an attacker a trusted voice, which is why phishing and business email compromise are also authenticity problems.
  2. Personal accounts belonging to candidates, advisers, journalists, and public figures: A private account may be less protected than an employer's system while holding sensitive conversations, contacts, and photographs. Compromise can produce intelligence, material for coercion, or a convincing route for impersonating someone the public already recognises.
  3. Public websites and information services: A DDoS attack can obstruct access, defacement can place a false notice on a real page, and a cloned website can look almost identical to the official one. The genuine site may recover quickly, while screenshots of the fake message continue circulating long afterwards.
  4. Campaign databases and third-party applications: Campaigns store volunteer lists, public enquiries, polling information, donations, and contact data in internal tools and external platforms. A breach can violate privacy, enable more precise targeting, or enrich information gathered elsewhere. Understanding this ordinary campaign risk requires no speculation about the Central Elections Committee's non-public systems.
  5. Suppliers: Cloud, communications, marketing, analytics, call-centre, and media suppliers may hold access or information for several clients. An attacker may choose a smaller provider instead of the best-defended organisation. Vendor and supply-chain risk therefore belongs in the main threat model, not in the contractual footnotes.
  6. Hack-and-leak operations: An attacker steals genuine material and releases selected parts at a useful moment. Forged documents can also be mixed into a real collection. Journalists and the public must then work out what is genuine, what is missing, and who chose the timing while the story is already spreading.
  7. Information operations: Fake identities, bots, impersonation, AI-generated media, and false urgent notices can amplify a narrative and manufacture the appearance of broad agreement. Not every false post is a cyberattack, and not every cyberattack is an influence operation. A stolen account, leaked data, and fabricated content can, however, become parts of the same campaign.

Why 2026 is different

The paper ballot has not suddenly become digital. What has changed is the environment around it, where convincing content is faster and cheaper to produce and distribute. In January 2026, a Knesset Science and Technology Committee discussion reported that the Central Elections Committee and Shin Bet had established a dedicated team to address external influence ahead of the election. Preparation is not evidence that a particular incident has occurred. It is official recognition of a risk.

In July 2026, the State Comptroller said Israel's national preparation for foreign influence in the digital space had material shortcomings and stressed that an election period is especially sensitive. The report concerns influence on public discussion and confidence. It does not claim that anyone has changed ballots in the 2026 election.

The attackers' broader toolkit is already visible in official warnings. In February, the Israel National Cyber Directorate warned that hostile actors were using false information, intimidation, impersonation, and messages intended to undermine trust and create pressure and confusion. Days earlier, Shin Bet and the Cyber Directorate reported hundreds of cyber attempts against Israeli public figures during the preceding year, including attempts attributed to Iranian intelligence actors to compromise Google and messaging accounts through targeted phishing.

The terms should remain separate. A cyberattack describes a means such as intrusion, theft, or disruption. Foreign influence describes an outside actor or strategic purpose. Disinformation describes the deliberate use of false or misleading information. They can overlap, but they are not synonyms.

What an attacker may want more than changing a vote

Doubt may offer the better return. An attacker may try to make voters distrust an official notice, force a false story to dominate the news cycle, embarrass and distract a campaign, or create the impression that election infrastructure has failed even while polling stations continue operating normally.

There is a second, less obvious effect. As synthetic media becomes more convincing, an interested party can more easily dismiss a genuine recording or document as fake. Authenticity therefore matters in both directions: people need to identify fabrications without making truth impossible to establish.

The central point is simple: an election can be harmed without a single paper ballot being digitally altered. That is a threat model, not a claim that such harm has already occurred in Israel's 2026 election.

What voters can actually do

  1. Check polling locations, voting hours, and operational information through the Central Elections Committee or another official government channel, not through a forwarded link.
  2. Treat an urgent SMS, WhatsApp, or Telegram claim about a polling-place change, cancellation, or security event as unverified until an official source confirms it.
  3. For a surprising video or recording, find the original account and check whether several reputable news sources report the same event in the same context.
  4. Do not forward material simply because it confirms an existing political belief. Content that produces instant agreement deserves an extra check, not a lower standard.
  5. A suspected account compromise, phishing message, impersonation page, or other cyber incident can be sent to the Cyber Directorate's official reporting service. That report does not replace the police where required and does not determine whether a political assertion is true.

The same verification standard should apply to content supporting any party and to content attacking it. Pausing before sharing is not dramatic, but it is one of the few security controls every voter can apply personally.

The business-security lesson

Replace 'campaign' in this article with 'law firm', 'clinic', or 'small technology company', and most of the attack surface remains. A business also depends on employee identities, Microsoft 365, suppliers, a public website, sensitive databases, and reputation. One phishing message can become a data breach, and a weak supplier can become an indirect route inside.

The useful controls are not glamorous: phishing-resistant MFA, least privilege, backups, monitoring, supplier review, and a tested incident-response plan. Managed cybersecurity cannot promise that no attack will succeed. It can reduce the likelihood, shorten detection time, and keep a technical incident from becoming a prolonged crisis of trust.

NetFortress helps Israeli SMBs reduce the same identity, email, endpoint, vendor, and incident-response risks. The approach is practical: build layers that can be implemented, tested, and improved, without drama or absolute promises.

Frequently asked questions

Can hackers directly change votes in Israel's 2026 election?

At ordinary Israeli polling stations, voters use paper ballot slips and polling-station committees count them after voting ends. That limits the remote mass-vote-changing scenario, but it is not responsible to say "impossible" or to treat the whole election environment as immune. Accounts, websites, databases, suppliers, and public-information channels can still be targeted.

What election systems are most exposed to cyberattacks?

The clearest public targets include campaign email, personal accounts belonging to public figures, websites, information services, campaign databases, third-party applications, and suppliers. There is no need to speculate about undisclosed Central Elections Committee systems to explain those risks.

Can a cyberattack affect an election without changing votes?

Yes. Service disruption, document leaks, impersonation, and false information can affect behaviour, the news agenda, and confidence in the process even when no ballot paper is changed.

How can voters verify election information?

Check operational information through official Central Elections Committee or government channels, and cross-check urgent claims with more than one reputable source. For a surprising video, recording, or screenshot, find the original publication and verify its context before sharing it.

Why are businesses relevant to an article about election cybersecurity?

Both environments depend on identities, email, suppliers, data, availability, and reputation. Controls such as MFA, least privilege, monitoring, backups, vendor management, and incident response protect an SMB from the same classes of risk, even though the context is very different.

Ready to secure your business without building an internal IT team?

Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.