Defense Secretary Pete Hegseth directed U.S. Cyber Command and military intelligence agencies to prioritize countering foreign threats to the upcoming elections, ordering intelligence collection and coordination with the Department of Homeland Security.
The Sept. 22 memorandum was released publicly Monday and instructs the defense intelligence enterprise to gather and analyze information on foreign election threats. It separately directs Cyber Command to use its existing authorities and capabilities to counter potential cyberattacks by foreign actors targeting the elections.
“I am therefore directing the entire [Defense Intelligence Enterprise] to mobilize every authorized asset, capability, and partnership under your command to defend our election infrastructure from foreign malign influence,” Hegseth wrote.
The memo is addressed to the leaders of Cyber Command, the National Security Agency, the Defense Intelligence Agency and the National Geospatial-Intelligence Agency. It calls protecting elections a “no-fail mission,” but does not identify particular adversaries or operations, specify additional staffing or funding, or set implementation deadlines.
The directive notably comes amid a broader retreat from dedicated federal efforts to track foreign influence and disinformation. The second Trump administration has dismantled the FBI’s Foreign Influence Task Force, reorganized the intelligence community’s coordination of that work and reduced election security support at the Cybersecurity and Infrastructure Security Agency.
At the Office of the Director of National Intelligence, an overhaul shifted many responsibilities of the Foreign Malign Influence Center to other offices. ODNI has subsequently assigned two officials to coordinate election threat intelligence.
Foreign election threats can range from attacks on voting-related computer systems to campaigns intended to manipulate public opinion.
The NSA collects foreign signals intelligence, including intercepted communications, to understand adversaries’ plans and capabilities, while also helping protect sensitive U.S. systems. Cyber Command conducts military cyber operations, including missions to disrupt foreign hackers and the infrastructure they use.
The organizations have previously combined those capabilities through a joint Election Security Group. In a description of its work during the 2022 midterms, NSA explained that intelligence about an attack originating abroad could be shared with domestic agencies to help them defend against it, while Cyber Command could use offensive operations to disrupt the foreign attacker.
Hegseth’s memo does not specify whether the same organizational model will be used this year. It directs intelligence work to comply with applicable laws and policies and tells Cyber Command to operate under its existing authorities.
The directive also emphasizes cooperation with DHS as that agency’s civilian cyberdefense agency outlines how it will assist election officials following staffing and program reductions.
Two days after Hegseth signed the memo, CISA — housed within DHS — released an election security plan identifying its 10 regional directors as election security advisers and describing a free threat-sharing platform connecting election officials, state intelligence hubs and federal partners. That plan followed warnings from state officials that earlier cuts had weakened their access to federal security expertise.
The 2026 elections come as rapid advances in AI allow foreign influence operators to automate more of their work. Such capabilities could let adversaries run larger campaigns with fewer people, adding to the challenge of identifying coordinated manipulation ahead of the midterms.


