The memorandum was released publicly on Monday, September 28, 2026. It is addressed to the leaders of U.S. Cyber Command, the National Security Agency, the Defense Intelligence Agency, and the National Geospatial-Intelligence Agency.

The directive instructs the defense intelligence enterprise to gather and analyze information on foreign election threats. It directs intelligence work to comply with applicable laws and policies. The directive emphasizes cooperation with the Department of Homeland Security. The memo does not identify particular adversaries or operations, specify additional staffing or funding, or set implementation deadlines.

Gen. Joshua M. Rudd is the head of U.S. Cyber Command and the National Security Agency. Cyber Command and the NSA "regularly counter actions by malicious foreign cyber actors including those with the intent to interfere with our democratic process," Rudd said in a statement on Monday.

In April 2026, Gen. Joshua M. Rudd told lawmakers he did not know if a specialized military and intelligence team dedicated to thwarting foreign threats to elections had been stood up for the midterm elections. The second Trump administration reduced election security support at the Cybersecurity and Infrastructure Security Agency (CISA). David Becker, a former U.S. Justice Department attorney who heads the nonprofit Center for Election Innovation Research, stated that the administration dismantled federal election cybersecurity capacity and fired experts in early 2025.

The second Trump administration has dismantled the FBI’s Foreign Influence Task Force. The second Trump administration reorganized the intelligence community’s coordination of foreign influence tracking. An overhaul at the Office of the Director of National Intelligence shifted many responsibilities of the Foreign Malign Influence Center to other offices.

The Office of the Director of National Intelligence has assigned two officials to coordinate election threat intelligence. CISA released an election security plan on September 24, 2026, identifying its 10 regional directors as election security advisers. The CISA election security plan describes a free threat-sharing platform connecting election officials, state intelligence hubs, and federal partners. The 2026 CISA election security plan emphasized expanding a threat-sharing platform to include 50 state-level intelligence hubs, building on 2022 midterms' collaborative frameworks. Election systems were designated as "critical infrastructure" in 2017. The Department of Defense Fiscal Year (FY) 2026 Budget Estimates include funding for hardware for cyberspace operations, indicating ongoing investment in capabilities that could be used to defend against foreign election threats.

Why It Matters

The directive comes after administrative changes that reduced federal election security support, including the dismantling of the FBI’s Foreign Influence Task Force and reduced support at CISA. The memo relies on existing authorities and capabilities without specifying new funding or staffing, leaving implementation details open. The events described span 9 years, from 2017 to 2026, reflecting a long-standing focus on election infrastructure protection.

Timeline

In April 2026, he told lawmakers he did not know if a specialized military and intelligence team dedicated to thwarting foreign threats to elections had been stood up for the midterm elections. Defense Secretary Pete Hegseth signed a memorandum on September 22, 2026, directing U.S. Cyber Command and military intelligence agencies to prioritize countering foreign threats to the upcoming elections. On that same date, Hegseth wrote, "I am therefore directing the entire [Defense Intelligence Enterprise] to mobilize every authorized asset, capability, and partnership under your command to defend our election infrastructure from foreign malign influence." The memo calls protecting elections a "no-fail mission." The directive orders U.S. Cyber Command to use its existing authorities and capabilities to counter potential cyberattacks by foreign actors targeting the elections. The memo is addressed to the leaders of U.S. Cyber Command, the National Security Agency, the Defense Intelligence Agency, and the National Geospatial-Intelligence Agency. The directive directs intelligence work to comply with applicable laws and policies.

What's New

Cyber Command and the NSA "regularly counter actions by malicious foreign cyber actors including those with the intent to interfere with our democratic process," he said in a statement on Monday. The Election Security Group (ESG), a joint NSA-Cyber Command initiative, has operated continuously since the 2020 election to coordinate cybersecurity and intelligence efforts against foreign election threats.

In the 2024 election, secret U.S. cyber operations were used to shield the election from foreign trolls, but the Trump administration later gutted these protections, reducing election security support at the Cybersecurity and Infrastructure Security Agency (CISA). In 2018, U.S. Cyber Command disrupted Internet access to the Russian Internet Research Agency, a troll factory linked to Vladimir Putin, during midterm elections, marking its first offensive cyber operation against foreign election interference. U.S. Cyber Command's election security role originated in 2018, when it formed a 'Russia Small Group' to counter foreign interference, later expanding into the Election Security Group (ESG) for the 2020 election under the 'Defend Forward' strategy. U.S. Cyber Command was elevated to a unified combatant command in May 2018, under the leadership of a four-star general who also serves as the director of the National Security Agency (NSA) and chief of the Central Security Service. The Election Security Group (ESG), a joint team of NSA and Cyber Command officials, has operated for every general and midterm election since 2020, coordinating cybersecurity, intelligence, and operations to defend electoral processes.