London Daily

Focus on the big picture.
Thursday, Nov 06, 2025

Russia, China and Iran trying to hack US presidential race, Microsoft says

Russia, China and Iran trying to hack US presidential race, Microsoft says

Hundreds of organisations and individuals targeted, including Trump and Biden campaigns, political parties, consultants and think tanks.

This story is published in a content partnership with POLITICO. It was originally reported by Tim Starks on politico.com
on September 10, 2020.

Russian, Chinese and Iranian hackers have mounted cyberattacks against hundreds of organisations and people involved in the 2020 presidential race and US-European policy debates, with targets including the campaigns of both Donald Trump and Joe Biden, Microsoft said on Thursday.

The report is the most expansive public warning to date about the rapid spread of foreign governments' efforts to wield hackers to undermine US democracy.

The perpetrators include the same Kremlin-aligned Russian hacking group whose thefts and leaks of confidential Democratic Party documents helped torpedo Hillary Clinton’s presidential hopes in 2016, said Microsoft, which offers products designed to detect such attacks.


Supporters, one wearing a shirt with US President Donald Trump's face on it, attend a campaign event in North Carolina on Tuesday.


Targets this time include the Trump and Biden campaigns, administration officials and an array of national and state parties, political consultants and think tanks, as well as groups such as the German Marshall Fund and Stimson Centre that promote international cooperation.

“The activity we are announcing today makes clear that foreign activity groups have stepped up their efforts targeting the 2020 election as had been anticipated,” Microsoft said in a blog post. It added that its security tools detected and blocked “the majority of these attacks”.

The company did not answer numerous questions from POLITICO seeking more details about the attacks.

The revelations come amid a feud between congressional Democrats and the administration over what it knows about foreign threats against the election, in particular the Democrats' accusations that Trump's intelligence leaders are failing to alert the public about the Kremlin's activities.

Trump and his supporters have pushed a message that the Chinese are trying to help Biden – a claim not supported by intelligence officials, who have told POLITICO that Russia's efforts pose the most active and acute danger.

An official intelligence community statement last month said China prefers that Trump not be re-elected, that Russia is denigrating Biden and that Iran is undermining the president.

Some of the hackers' targets confirmed Microsoft's reporting, though none said the cyberattacks had succeeded.

“As President Trump’s re-election campaign, we are a large target, so it is not surprising to see malicious activity directed at the campaign or our staff,” said Thea McDonald, deputy press secretary for the president's campaign team.

“We work closely with our partners, Microsoft and others, to mitigate these threats. We take cybersecurity very seriously and do not publicly comment on our efforts.”

Likewise, the Republican National Committee has “been informed that foreign actors have made unsuccessful attempts to penetrate the technology of our staff members,” an RNC spokesperson said.

Biden's campaign did not immediately respond to a request for comment.

Microsoft has also alerted SKDKnickerbocker, one of Biden’s chief communications and strategy firms, that Russian hackers had unsuccessfully targeted its networks, Reuters said early on Thursday ahead of the report's release. Those attempts also failed, Reuters reported. The firm did not respond to later requests for comment.

The attacks on the Stimson Centre were first observed in May, spokesperson David Solimini said, and Microsoft notified the think tank about the nature and source in late July. He and German Marshall Fund spokesperson Sydney Simon both said they had seen no evidence that the attacks succeeded.

Christopher Krebs, director of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, said Microsoft's findings are “consistent with earlier statements by the Intelligence Community on a range of malicious cyber activities targeting the 2020 campaign”.

“It is important to highlight that none [of the targets] are involved in maintaining or operating voting infrastructure and there was no identified impact on election systems,” Krebs said in a statement. He added, “Everyone involved in the political process should stay alert against these sorts of attacks.”

The Treasury Department announced its own steps to combat Kremlin interference Thursday, saying it had designated the pro-Russian Ukrainian lawmaker Andriy Derkach for sanctions for promoting discredited allegations against Biden.

Graham Brookie, director of the Atlantic Council's Digital Forensic Research Lab, confirmed that his group had been the target of apparently unsuccessful attacks from Chinese hackers, but cautioned that those did not appear election-related.

“It is not surprising that we would be targeted by China, based on the substance of our work,” Brookie said. “This appeared to be about information gathering and espionage as opposed to election interference of any kind.”

Among other details, Microsoft reported that:


The hacking group popularly known as Fancy Bear, which is linked to Russian military intelligence and played a major role in the 2016 attacks on Democrats, has gone after more than 200 organisations in recent months. The targets include political campaigns, national and state party organisations, consultants for both parties and think tanks. (The group is also known as APT28, and Microsoft refers to it as Strontium.)

A Chinese hacking group called Zirconium or APT31 has attacked high-profile people in Biden’s campaign and at least one prominent person in Trump’s campaign, the tech giant said.

Phosphorus, an Iranian hacker group often called Charming Kitten, has gone after Trump campaign staffers and administration officials.


Democratic presidential nominee Joe Biden speaks in a supporter’s backyard in Detroit on Wednesday.


Microsoft’s blog post said that it had blocked most of the attacks. The company’s analysis offered some new details on the hackers’ methods.

For instance, in 2016 the Russian group primarily relied on so-called spearphishing, which tricks victims into clicking on malicious email links to gain access to documents that it later released through outlets like WikiLeaks. But in recent months, Russia has shifted toward more crude “brute force” attacks and a technique called password spray, in which hackers input many passwords in a bid to guess their way into a system.

“Strontium also disguised these credential harvesting attacks in new ways, running them through more than 1,000 constantly rotating IP addresses, many associated with the Tor anonymising service,” wrote Tom Burt, corporate vice-president for customer security and trust.

“Strontium even evolved its infrastructure over time, adding and removing about 20 IPs per day to further mask its activity.”

This is far from the first time that a company in the cybersecurity business, not the federal government, has been the first to go public with details about major attacks against their customers by nation-states.

Previous examples include a landmark 2013 report by the cyber firm Mandiant on Chinese Army-connected hackers conducting cyber espionage against US critical infrastructure like the electrical power grid.

Newsletter

Related Articles

0:00
0:00
Close
UK Pre-Budget Blues and Rate-Cut Concerns Pile Pressure on Pound
ITV Warns of Nine-Per-Cent Drop in Q4 Advertising Revenue Amid Budget Uncertainty
National Grid Posts Slightly Stronger-Than-Expected Half-Year Profit as Regulatory Investments Drive Growth
UK Business Lobby Urges Reeves to Break Tax Pledges and Build Fiscal Headroom
UK to Launch Consultation on Stablecoin Regulation on November 10
UK Savers Rush to Withdraw Pension Cash Ahead of Budget Amid Tax-Change Fears
Massive Spoilers Emerge from MAFS UK 2025: Couple Swaps, Dating App Leaks and Reunion Bombshells
Kurdish-led Crime Network Operates UK Mini-Marts to Exploit Migrants and Sell Illicit Goods
UK Income Tax Hike Could Trigger £1 Billion Cut to Scotland’s Budget, Warns Finance Secretary
Tommy Robinson Acquitted of Terror-related Charge After Phone PIN Dispute
Boris Johnson Condemns Western Support for Hamas at Jewish Community Conference
HII Welcomes UK’s Westley Group to Strengthen AUKUS Submarine Supply Chain
Tragedy in Serbia: Coach Mladen Žižović Collapses During Match and Dies at 44
Diplo Says He Dated Katy Perry — and Justin Trudeau
Dick Cheney, Former U.S. Vice President, Dies at 84
Trump Calls Title Removal of Andrew ‘Tragic Situation’ Amid Royal Fallout
UK Bonds Rally as Chancellor Reeves Briefs Markets Ahead of November Budget
UK Report Backs Generational Smoking Ban Ahead of Tobacco & Vapes Bill Review
UK’s Domino’s Pizza Group Reports Modest Like-for-Like Sales Growth in Q3
UK Supplies Additional Storm Shadow Missiles to Ukraine as Trump Alleges Russian Underground Nuclear Tests
High-Profile Broodmare Puca Sells for Five Million Dollars at Fasig-Tipton ‘Night of the Stars’
Wilt Chamberlain’s One-of-a-Kind ‘Searcher 1’ Supercar Heads to Auction
Erling Haaland’s Remarkable Run: 13 Premier League Goals in 10 Matches and Eyes on History
UK Labour Peer Warns of Emerging ‘Constituency for Hating Jews’ in Britain
UK Home Secretary Admits Loss of Border Control, Warns Public Trust at Risk
President Trump Expresses Sympathy for UK Royal Family After Title Stripping of Prince Andrew
Former Prince Andrew to Lose His Last Military Title as King Charles Moves to End His Public Role
King Charles Relocates Andrew to Sandringham Estate and Strips Titles Amid Epstein Fallout
Two Arrested After Mass Stabbing on UK Train Leaves Ten Hospitalised
Glamour UK Says ‘Stay Mad Jo x’ After Really Big Rowling Backlash
Former Prince Prince Andrew Faces Possible U.S. Congressional Appearance Over Jeffrey Epstein Inquiry
UK Faces £20 Billion Productivity Shortfall as Brexit’s Impact Deepens
UK Chancellor Rachel Reeves Eyes New Council-Tax Bands for High-Value Homes
UK Braces for Major Storm with Snow, Heavy Rain and Winds as High as 769 Miles Wide
U.S. Secures Key Southeast Asia Agreements to Reshape Rare Earth Supply Chains
US and China Agree One-Year Trade Truce After Trump-Xi Talks
BYD Profit Falls 33 % as Chinese EV Maker Doubles Down on Overseas Markets
US Philanthropists Shift Hundreds of Millions to UK to Evade Regulatory Uncertainty in Trump Era
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
King Charles Strips Prince Andrew of Titles and Royal Residence
Trump–Putin Budapest Summit Cancelled After Moscow Memo Raises Conditions for Ukraine Talks
Amazon Shares Soar 11% as Cloud Business Hits Fastest Growth Since 2022
Credit Markets Flooded with More Than $200 Billion of AI-Linked Debt Issuance
U.S. Treasury Secretary Scott Bessent Says China Made 'a Real Mistake' by Threatening Rare-Earth Exports
Report Claims Nearly Two Billion Dollars in Foreign Charity Funds Flowed into U.S. Advocacy Groups
White House Refutes Reports That US Targeting Military Sites in Venezuela
Meta Seeks Dismissal of Strike 3’s $350 Million Copyright Lawsuit
Apple Exceeds Forecasts With $102.5 Billion Q3 Revenue Despite iPhone Miss
Israel's IDF Major General Yifat Tomer-Yerushalmi Admits to Act Amounting to Aiding Hamas During Wartime (Treason)
Shawbrook IPO Marks London’s Biggest UK Listing in Two Years
×