VR Systems

Last updated

VR Systems is a provider of elections technology systems and software. VR Systems is based in Tallahassee, Florida. [1] [2] The company's products are used in elections in eight U.S. states. [3] The company was founded in 1992 by Jane and David Watson. [4] [5] [6] The CEO and President is Mindy Perkins. [7] [8]

Contents

History

VR Systems was founded in Florida in 1992 and grew its voter registration system, VoterFocus, in the years following the passage of the Help America Vote Act in 2002. [6] In 2004, in response to devastation caused by Hurricane Charley in South Florida, VR created the EViD electronic pollbook designed to check in voters at central locations as many of the precincts in the area had been destroyed. VR Systems attends the United States Department of Homeland Security executive committee and initiates a cybersecurity communications education program, revealing their working process with election administrators nationwide. Today, most counties in Florida use VR products. In 2010, VR became a 100% employee-owned company. [9]

Russian hacking controversy

VR Systems Phishing Alert to Mecklenburg County VR Systems Phishing Alert to Mecklenburg County.pdf
VR Systems Phishing Alert to Mecklenburg County

VR Systems was reportedly targeted by operatives of the Russian Main Intelligence Directorate (GRU) in and around August 2016. [5] [10] [11] Russian actors also attempted to impersonate VR Systems by creating a false email address as part of a spear phishing campaign targeting state electoral officials. [5] [12] [11] There are no reports that the spear phishing campaign was successful. VR Systems insisted that none of its employees fell for the Russian phishing scam and that none of its systems were hacked. [13] [14] The investigation by North Carolina has been proved inconclusive. [11] [15]

Timeline of Russian hacking controversy

  • On August 24, 2016, Russian hackers sent phishing emails to VR Systems.
  • On August 30, VR Systems experienced an election-reporting mishap during the state primary in Broward County, Florida, when preliminary vote totals were posted live before the election ended.
  • On September 30, the Federal Bureau of Investigation (FBI) held a conference call with Florida election officials warning them to look out for suspicious activity coming from specific IP addresses. VR Systems, which is on the call, discovers activity from the IP addresses and notifies the FBI. On October 31, Russian hackers sent spear-phishing emails from a fake email [16] account to more than 120 election officials in Florida, North Carolina, and other states. If opened, the documents attached to the email would invisibly download a malware package that could have provided the attacker with remote control over a target’s computer. [17] VR Systems immediately alerted its clients and notified the FBI, but the company could not fully estimate the scope of the attack.
  • On Election Day, November 8, Durham County, North Carolina, experienced problems with its VR Systems poll book software in five precincts. [18] State officials immediately ordered Durham County to abandon the laptops in favor of paper printouts of the voter list to check in voters. However, the switch caused extensive delays at some precincts, leading an unknown number of voters to leave without casting ballots. [19]

Products

VR Systems offers the EViD [20] electronic pollbook, [21] [22] Voter Focus voter registration software, ELM online training and website services specifically designed for the elections community.

EViD electronic pollbook

The EViD electronic pollbook, short for Electronic Voter Identification, is available as a tablet, an all-in-one station or customized for an existing device. More than 14,000 EViDs were in use during the 2016 elections in eight U.S. states: California, Florida, Illinois, Indiana, North Carolina, New York, Virginia, and West Virginia. [23] It was used in 23 of North Carolina’s 100 counties and in 64 of Florida’s 67 counties. The latter include Miami-Dade, the state’s most populous county. [11] It is proceeded with four steps: 1. Plug in the activator, connect to any network wired or wireless. 2. Voters sign for their ballot at an EViD terminal and receives ballot ticket. 3. The voters take their ballot ticket to get their ballot. The custom ballot is printed through the DirectPrint printing option. 4. Voting data is processed automatically and device could be packed up. [24]

Voter Focus

Voter Focus is an elections management solution before, during, and after election day. This solution organizes the election cycle, including voter registration, mail ballot delivery, precinct look-up, poll worker management, candidate requests. Voter Focus comes automatically with software updates, compliance updates and extensive built-in Q&A capabilities. [25]

ELM

ELM is an online elections training platform designed specifically for election worker training. Each jurisdiction can create custom training by reusing existing media content or content from the ELM collaborative library. [25]

VR Tower

VR Tower is designed for elections officials who would like a complete website solution with maintenance tools. The websites specifies in politician-voter communication. [25]

Related Research Articles

<span class="mw-page-title-main">Phishing</span> Form of social engineering

Phishing is a form of social engineering and scam where attackers deceive people into revealing sensitive information or installing malware such as ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim is navigating the site, and transverse any additional security boundaries with the victim. As of 2020, it is the most common type of cybercrime, with the FBI's Internet Crime Complaint Center reporting more incidents of phishing than any other type of computer crime.

Vote counting is the process of counting votes in an election. It can be done manually or by machines. In the United States, the compilation of election returns and validation of the outcome that forms the basis of the official results is called canvassing.

<span class="mw-page-title-main">Election Systems & Software</span>

Election Systems & Software is an Omaha, Nebraska-based company that manufactures and sells voting machine equipment and services. The company's offerings include vote tabulators, DRE voting machines, voter registration and election management systems, ballot-marking devices, electronic poll books, ballot on demand printing services, and absentee voting-by-mail services.

<span class="mw-page-title-main">Ion Sancho</span>

Ion Voltaire Sancho was an elected official who served Leon County, Florida, as Supervisor of Elections for 28 years, from 1989 to 2017. During his time in office, he was admired for his integrity as a voter advocate and elections expert, and became nationally known for his role in the Florida presidential election recount of 2000. He was also known for his appearance in the 2006 investigative documentary Hacking Democracy.

<i>Hacking Democracy</i> 2006 film by Simon Ardizzone

Hacking Democracy is a 2006 Emmy nominated documentary film broadcast on HBO and created by producer / directors Russell Michaels and Simon Ardizzone, with producer Robert Carrillo Cohen, and executive producers Sarah Teale, Sian Edwards & Earl Katz. Filmed over three years it documents American citizens investigating anomalies and irregularities with 'e-voting' systems that occurred during the 2000 and 2004 elections in the United States, especially in Volusia County, Florida. The film investigates the flawed integrity of electronic voting machines, particularly those made by Diebold Election Systems, exposing previously unknown backdoors in the Diebold trade secret computer software. The film culminates dramatically in the on-camera hacking of the in-use / working Diebold election system in Leon County, Florida - the same computer voting system which has been used in actual American elections across thirty-three states, and which still counts tens of millions of America's votes today.

Electoral reform in Florida refers to efforts to change the voting and election laws in the United States state of Florida.

<span class="mw-page-title-main">Elections in Florida</span> Overview of the procedure of elections in the U.S. state of Florida

Elections in Florida are held on the first Tuesday after the first Monday of November in even-numbered years, as provided for in Article 6 of the Florida Constitution. For state elections, the Governor of Florida, Lieutenant Governor, and the members of the Florida Cabinet, and members of the Florida Senate are elected every four years; members of the Florida House of Representatives are elected every two years. In national elections, Florida plays an important role as the largest bellwether state, occasionally determining the outcome of elections for U.S. President — as it did in 1876 and in 2000.

A zero-day is a vulnerability or security hole in a computer system unknown to its owners, developers or anyone capable of mitigating it. Until the vulnerability is remedied, threat actors can exploit it in a zero-day exploit, or zero-day attack.

A supply chain attack is a cyber-attack that seeks to damage an organization by targeting less secure elements in the supply chain. A supply chain attack can occur in any industry, from the financial sector, oil industry, to a government sector. A supply chain attack can happen in software or hardware. Cybercriminals typically tamper with the manufacturing or distribution of a product by installing malware or hardware-based spying components. Symantec's 2019 Internet Security Threat Report states that supply chain attacks increased by 78 percent in 2018.

<span class="mw-page-title-main">Kaspersky Lab</span> Russian multinational cybersecurity and anti-virus provider

Kaspersky Lab is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky and Alexey De-Monderik. Kaspersky Lab develops and sells antivirus, internet security, password management, endpoint security, and other cybersecurity products and services.

Cozy Bear, classified by the United States federal government as advanced persistent threat APT29, is a Russian hacker group believed to be associated with one or more intelligence agencies of Russia. The Dutch General Intelligence and Security Service (AIVD) deduced from security camera footage that it is led by the Russian Foreign Intelligence Service (SVR), a view shared by the United States. Cybersecurity firm CrowdStrike also previously suggested that it may be associated with either the Russian Federal Security Service (FSB) or SVR. The group has been given various nicknames by other cybersecurity firms, including CozyCar, CozyDuke, Dark Halo, The Dukes, Midnight Blizzard, NOBELIUM, Office Monkeys, StellarParticle, UNC2452, and YTTRIUM.

Fancy Bear, also known as APT28, Pawn Storm, Sofacy Group, Sednit, Tsar Team and STRONTIUM or Forest Blizzard, is a Russian cyber espionage group. Cybersecurity firm CrowdStrike has said with a medium level of confidence that it is associated with the Russian military intelligence agency GRU. The UK's Foreign and Commonwealth Office as well as security firms SecureWorks, ThreatConnect, and Mandiant, have also said the group is sponsored by the Russian government. In 2018, an indictment by the United States Special Counsel identified Fancy Bear as GRU Unit 26165. This refers to its unified Military Unit Number of the Russian army regiments. The headquarters of Fancy Bear and the entire military unit, which reportedly specializes in state-sponsored cyberattacks and decryption of hacked data, were targeted by Ukrainian drones on July 24, 2023, the rooftop on one of the buildings collapsed as a result of the explosion.

X-Agent or XAgent is a spyware and malware program designed to collect and transmit hacked files from machines running Windows, Linux, iOS, or Android, to servers operated by hackers. It employs phishing attacks and the program is designed to "hop" from device to device. In 2016, CrowdStrike identified an Android variant of the malware for the first time, and claimed that the malware targeted members of the Ukrainian military by distributing an infected version of an app to control D-30 Howitzer artillery. The Ukrainian army denied CrowdStrike's report and stated that losses of Howitzer artillery pieces had "nothing to do with the stated cause".

<span class="mw-page-title-main">Election audit</span>

An election audit is any review conducted after polls close for the purpose of determining whether the votes were counted accurately or whether proper procedures were followed, or both.

Election cybersecurity or election security refers to the protection of elections and voting infrastructure from cyberattack or cyber threat – including the tampering with or infiltration of voting machines and equipment, election office networks and practices, and voter registration databases.

Red Apollo is a Chinese state-sponsored cyberespionage group which has operated since 2006. In a 2018 indictment, the United States Department of Justice attributed the group to the Tianjin State Security Bureau of the Ministry of State Security.

Charming Kitten, also called APT35, Phosphorus or Mint Sandstorm, Ajax Security, and NewsBeef, is an Iranian government cyberwarfare group, described by several companies and government officials as an advanced persistent threat.

<span class="mw-page-title-main">Maksim Yakubets</span> Ukrainian national and a computer expert (born 1987)

Maksim Viktorovich Yakubets is a Russian computer expert and alleged computer hacker. He is alleged to have been a member of the Evil Corp, Jabber Zeus Crew, as well as the alleged leader of the Bugat malware conspiracy. Russian media openly describe Yakubets as a "hacker who stole $100 million", friend of Dmitry Peskov and discussed his lavish lifestyle, including luxury wedding with a daughter of FSB officer Eduard Bendersky and Lamborghini with "ВОР" registration plate. Yakubets's impunity in Russia is perceived as clue of his close ties with FSB, but also criticized by domestic information security experts such as Ilya Sachkov.

<span class="mw-page-title-main">Electronic voting in the United States</span> Facet of American elections

Electronic voting in the United States involves several types of machines: touchscreens for voters to mark choices, scanners to read paper ballots, scanners to verify signatures on envelopes of absentee ballots, and web servers to display tallies to the public. Aside from voting, there are also computer systems to maintain voter registrations and display these electoral rolls to polling place staff.

Double Dragon is a hacking organization with alleged ties to the Chinese Ministry of State Security (MSS). Classified as an advanced persistent threat, the organization was named by the United States Department of Justice in September 2020 in relation to charges brought against five Chinese and two Malaysian nationals for allegedly compromising more than 100 companies around the world.

References

  1. Waters, TaMaryn (January 26, 2016). "VR Systems names new COO". Tallahassee Democrat. VR Systems, located at 2840 Remington Green Circle, was founded 20 years ago in Tallahassee.
  2. Hoskinson, Cyd (July 19, 2018). "Local Election Supervisors Explain Cyber Security Precautions". WJCT. Duval County uses voter information software made by Tallahassee-based VR Systems, which is the company Russia reportedly tried to hack in 2016 by sending malware infected emails to local elections offices.
  3. Malone, Claire (July 13, 2018). "What The Latest Mueller Indictment Tells Us About Election Hacking". FiveThirtyEight. The Intercept report was based on National Security Agency documents, which did not directly identify the company but made references to a product made by VR Systems, whose products are used in eight states.
  4. Bomey, Nathan; Burlew, Jeff (June 6, 2017). "Russian hacking attempt targets small elections-technology industry". USA Today. VR Systems was founded in 1992 by David and Jane Watson of Tallahassee, in part to help the Leon County Supervisor of Elections Office move its voter registration data from the county's mainframe to a custom-made system.
  5. 1 2 3 Biddle, Sam (July 13, 2018). "A Swing-State Election Vendor Repeatedly Denied Being Hacked by Russians. The New Mueller Indictment Says Otherwise". The Intercept.
  6. 1 2 "VR Systems Announces New President". VR Systems, Inc. June 10, 2015. Archived from the original on July 20, 2018. VR, founded in 1992, established a strong Florida client base which expanded rapidly following the passage of HAVA in 2002.
  7. Schneider, Mike (June 19, 2017). "Florida voter-registration firm denies it got hacked". Orlando Sentinel. "When something like this happens, it hurts us and hurts us as an elections community," VR Systems CEO Mindy Perkins told supervisors Monday at the Florida State Association of Supervisors of Elections conference in the Polk County city of Davenport
  8. Sherman, Amy (October 19, 2016). "Premature posting of election results was mistake, not a crime". Miami Herald. In an affidavit the next day, VR Systems CEO Mindy Perkins explained what happened leading to the early release of results.
  9. Dozier, Shauna (2019), "Changing Demographics in Election Administration", The Future of Election Administration, Cham: Springer International Publishing, pp. 67–74, doi: 10.1007/978-3-030-18541-1_9 , ISBN   978-3-030-18540-4 , retrieved 2021-09-13
  10. Norden, Lawrence (July 16, 2018). "Mueller's Latest Indictment Suggests Russia's Infiltration of U.S. Election Systems Could Get Worse". Slate. We already know that hackers targeted election systems in 21 states and allegedly hacked into the computers of a private U.S. elections systems vendor. (The indictment did not name the vendor, but details seem to match a reported hack of the company VR Systems; VR Systems has denied any breach had occurred.)
  11. 1 2 3 4 Zetter, Kim. How Close Did Russia Really Come to Hacking the 2016 Election? Politico. 26 Dec. 2019
  12. Weise, Elizabeth (June 6, 2017). "Russian hackers' election goal may have been swing-state voter rolls". USA Today. In this case, the Russians identified staff at VR Systems that provided consulting and support services to local election entities across the United States, The Intercept reported. Posing as staff at those vendors, hackers sent local election workers carefully-faked phishing emails that contained malware hidden in a Microsoft Word document. When the worker opened the document, that would have allowed the attackers to gain a beachhead in multiple election jurisdiction networks.
  13. Elfrink, Tim. "Russian Hackers Broke Into Elections Company Used in Miami-Dade, Broward". Miami New Times. Retrieved 2021-11-07.
  14. Fessler, Pam (2017-06-20). "Despite NSA Claim, Elections Vendor Denies System Was Compromised In Hack Attempt". NPR. Retrieved 2021-11-07.
  15. "Wyden Remarks at "In Defense of American Democracy" on Election Security and Vote-By-Mail | U.S. Senator Ron Wyden of Oregon". www.wyden.senate.gov. Retrieved 2021-10-21.
  16. Biddle, Sam (2018-06-01). "Here's the Email Russian Hackers Used to Try to Break Into State Voting Systems". The Intercept. Retrieved 2021-10-21.
  17. "DocumentCloud". www.documentcloud.org. Retrieved 2021-10-21.
  18. "State officials demand voting system vendors reveal owners after Russian hacks and investments". NBC News. Retrieved 2021-11-02.
  19. Zetter, Kim. "Wyden seeks answers in Florida election hacking allegations". POLITICO. Retrieved 2021-10-21.
  20. "CONFIGURATIONS FOR CERTIFIED EPOLLBOOKS BY VENDOR" (PDF). Election Assistance Commission. March 26, 2015. Retrieved July 20, 2018.
  21. "EViD FAQ" (PDF). VR Systems, Inc. Retrieved July 20, 2018.
  22. Brennan, Christopher (September 22, 2017). "Feds tell 21 states that they were targeted by election hackers". New York Daily News . VR Systems' website says its EViD software for election management is used in states including California, Florida, Illinois, Indiana, New York, North Carolina, Virginia and West Virginia.
  23. "VR Delivers Technology for Modern Elections". www.vrsystems.com. Retrieved 2021-09-27.
  24. "EViD FAQs" (PDF). Retrieved September 27, 2021.
  25. 1 2 3 "VR Delivers Technology for Modern Elections". www.vrsystems.com. Retrieved 2021-10-21.