Elections increasingly attract cyber operations that target politicians, businesses and the public. These activities range from espionage campaigns against political parties targeting operations seeking to shape opinions, sow discontent or undermine democratic processes.
This newsletter, published twice a month, provides an overview of key cyber incidents and emerging threats related to the upcoming October 2026 general elections in Brazil. It offers recommendations on how organizations and individuals can mitigate and protect against these threats.
Key incidents
In this issue we focus on the following:
Threat actor breaches US DHS’ information-sharing network
US government-affiliated technology news outlet Nextgov/FCW on June 30 reported that an unknown threat actor had breached the US Department of Homeland Security (DHS)'s Homeland Security Information Network (HSIN) between late May and early June.
Israeli cyber security start-up seeking to expand into Latin America
According to tech media outlet The Next Web, an Israeli cyber security start-up called Dream, co-founded by the same man who created the NSO Group and its Pegasus spyware, is actively looking to expand sales in Latin America and is focusing on countries and governments in the region that align with its ideologies.
50,000+ phone numbers were reportedly selected for surveillance by the Pegasus spyware in a leaked target list from 2020, according to Amnesty International.
Those targeted include opposition politicians, journalists, human rights activists, lawyers and other political dissidents in countries around the world, according to the Amnesty International investigation.
Mitigation advice
- Strengthen protection of critical collaboration and information-sharing platforms by enforcing multi-factor authentication (MFA), restricting administrative privileges, monitoring collaboration environments for anomalous activity and conducting regular reviews of access rights to reduce the risk of unauthorized access or data exposure.
- Implement comprehensive safeguards against spyware and surveillance threats by maintaining rigorous patch management, deploying endpoint detection and response (EDR) tools, restricting unapproved software installations and monitoring for indicators associated with keyloggers, infostealers, rootkits and other covert monitoring tools.
- Increase resilience against credential theft and information harvesting by enforcing strong authentication controls, monitoring for exposed credentials, reducing browser-stored secrets where possible and educating personnel on the risks posed by spyware, phishing and malicious software.
- Establish procedures to identify and respond to surveillance, influence and intelligence-gathering activity by monitoring for suspicious communications, unusual data access patterns and attempts to collect sensitive information relating to executives, employees, business operations or election-related issues.
- Integrate cyber security, communications, legal and crisis management teams into an election-period preparedness program by conducting joint exercises, reviewing escalation procedures, validating response playbooks and ensuring readiness to address cyber incidents, information operations or unauthorized surveillance activity that could affect business operations.
Threat actor breaches US DHS’ information-sharing network
DHS investigators are currently probing the HSIN intrusion. There is currently insufficient information to assess the threat actor’s identity or determine whether they exfiltrated any documents from the system. The DHS Office of Intelligence and Analysis is also conducting a damage assessment of the incident. According to the Nextgov/FCW report, the intrusion potentially exposed sensitive but unclassified data shared between federal, state, local and industry partners.
The threat actor targeted HSIN servers and a Microsoft SharePoint system. HSIN supports real-time communication, document sharing, alerts, web conferencing and incident management for approved federal, state, local, territorial, tribal, international and private-sector users. It is also used to exchange information about persons of interest and potential threats during emergencies and events.
Potential impact: Threat actors may attempt to penetrate critical government systems during key events, such as the upcoming Brazilian elections, either to compromise sensitive data or to disrupt critical information sharing between federal, state and private sector industry partners.
Israeli cyber security start-up looking to expand into Latin America
The Next Web reported that Israeli AI cyber security start-up Dream is expanding into Latin America, with a particular focus on US-aligned governments in the region. Dream co-founder Shalev Hulio previously created NSO Group, an Israeli surveillance company that successfully marketed the Pegasus spyware, used by governments to monitor political opponents, journalists and activists. However, Dream says its products are purely defensive and that it provides governments with AI-enabled platforms to detect and patch vulnerabilities.
According to The Next Web, activists in Latin America remain concerned given previous direct experience with spyware, as well as the ideological shift to the right of governments such as Argentina and Colombia in recent years. This shift may make governments more receptive to engaging with such companies. Demand for these products is also growing, as Latin America remains the world’s fastest-growing region for cyber attacks, with incidents increasing by approximately 25% annually and cyber security budgets expanding in response.
Potential impact: Although the stated use cases for Dream’s products appear markedly different from those of NSO Group, the developments evoke previous concerns in the region regarding government surveillance and the targeting of civil society actors critical of the government. These groups, as well as the population at large, should remain vigilant against such threats, especially during key inflection points such as the lead-up to Brazil’s October elections.
Focus on: Spyware
Spyware is a type of malware designed to covertly collect information from a device and send it to another party without the user's knowledge or consent. It often steals sensitive information such as passwords, browsing history, financial data, messages, location data and other personal information.
The most common types of spyware are:
- Keyloggers – record keystrokes to steal usernames and passwords
- Infostealers – extract credentials, cookies and sensitive files
- Adware – track browsing behavior to deliver targeted advertisements
- Rootkits – provide hidden, privileged access to a device
- Stalkerware – monitors communications, location and activity
- Commercial spyware (e.g. Pegasus) – highly sophisticated tools used for surveillance and espionage
Electoral protection in Brazil: cybersecurity training and support
Register to receive these twice-monthly reports