Cyber Incident Victim: Potter County
Date:
Sep 2016
Location:
United States of America
Summary
Potter County, Texas experienced a breach of its voter information website, prompting officials to assure users of its safety. The incident was detected when a county employee noticed a Google search warning indicating potential hacking. Investigation revealed that the attackers aimed to artificially inflate another website's traffic rather than manipulate election data. County IT personnel explained that accessing a specific file redirected credit to the hackers' site for page view metrics. Although the security warning remained visible in search results temporarily, administrators confirmed implementing protective measures to secure the platform.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Potter County, Texas officials confirmed a security breach affecting their voter information website in late September 2016. The incident was discovered approximately two weeks prior to October 13 when a county employee attempted to access the site through Google search and encountered a browser warning indicating potential compromise. County IT administrators subsequently verified unauthorized access to the website infrastructure. Investigation revealed that attackers modified website files to redirect traffic, though election systems remained unaffected. According to Potter County Elections Administrator Melynn Huntley, forensic analysis indicated the hackers' primary objective involved artificially inflating page view metrics for an unrelated external website rather than manipulating voter data or election processes. The compromise leveraged file manipulation techniques where visitor interactions with county resources generated fraudulent traffic credits for third-party domains.

County officials publicly assured constituents that no voter registration databases or election management systems were accessed during the breach, emphasizing the separation between informational website components and core electoral infrastructure. The Google security warning persisted in search results for an unspecified duration post-remediation due to search engine cache refresh cycles, though Huntley confirmed implementation of unspecified security precautions to restore operational integrity. No evidence suggested voter information exfiltration or tampering with upcoming election operations. The incident response focused on eliminating malicious code injections, restoring legitimate website functionality, and monitoring for residual anomalies. Public communications stressed the limited technical impact while acknowledging the violation of public trust through unauthorized system access.
