Thirty Briefings to Zero
Russia, China and Iran want different things from an American election. The apparatus that used to tell the difference has been taken apart between cycles.
Georgia’s Secretary of State put the change in one sentence this year. “If you go back to 2020, we had 30 different federal threat briefings. This year we received none.”
Brad Raffensperger is a Republican who certified an election against his own party’s sitting president and absorbed the consequences. He is not lodging a partisan complaint. He is describing an instrument that used to exist and no longer does, roughly six weeks before Americans vote in a midterm that three foreign intelligence services have separate and specific reasons to care about.
Foreign interference is usually argued at the altitude of belief — whether it happens, whether it works, whether anyone’s mind is actually changed. Those are real questions and they are not the operator’s questions. On the ground the question is narrower and more answerable: when something happens, who sees it, and how long does it take to reach a person with the authority to act?
Three adversaries, three different bets
The most common error in this conversation is treating foreign interference as a single phenomenon. It is three phenomena, run by three services with different objectives, and the differences dictate what a defense would even look like.
Russia plays the top of the ticket. In the 2024 cycle, US intelligence assessed that Russian operations were aimed at the presidential race, and the tradecraft was manufactured media — AI-generated video alongside cruder staged spoofs, impersonating legitimate outlets including fabricated material attributed to Fox News and to the FBI. The objective is not to make Americans believe a particular falsehood. It is to leave them unsure which things are real, which is a lower bar and a more durable effect.
China plays down-ballot. The same assessments described Chinese operations concentrating on state and local races and on candidates with records critical of Beijing. The Spamouflage network ran inauthentic accounts against Republicans including Representatives Barry Moore and Michael McCaul and Senators Marsha Blackburn and Marco Rubio. This is the quieter investment and I think the more consequential one. A sitting senator has a press operation and a national profile. A state legislator in a district nobody is covering has neither.
Iran plays the seam. Iranian operations have worked the fault line in American opinion over Israel, using fake personas to inflame both sides of it rather than to argue one. Iran is also the service with the clearest record of reaching voters directly: in 2020, Iranian actors sent intimidating emails to American voters spoofed to appear as though they came from the Proud Boys.
A countermeasure tuned to one of these does not detect the other two.
That is the operational point, and it is why “foreign interference” as a category does more harm than good. Detecting AI-fabricated presidential media is a content-authentication problem. Detecting a coordinated inauthentic network working a county commission race is a network-analysis problem at a scale no county possesses. Detecting voter-intimidation email spoofed from a domestic extremist group is a mail-authentication and attribution problem. These are different disciplines, different tooling, different people.
Separate services, converging effects
It would be convenient if these three operated in isolation. They do not.
The congressional US–China Economic and Security Review Commission described the arrangement carefully: the relationships among China, Russia, Iran and North Korea “may not constitute an alliance as traditionally conceived,” but the partnerships allow each country to “act in ways they could not sustain on their own.” The alignment rests “more on shared interests and expediency than trust and binding obligation.”
In the information domain that translates into something concrete and documented. Chinese state media reshare Russian narratives. Iranian outlets cite Chinese sources to make the case for American decline. Russian platforms reinforce North Korean messaging. None of that requires a joint planning cell. A narrative launched by one is laundered through the others until its origin is unrecoverable, and each retelling adds the appearance of independent corroboration.
I want to be precise here, because this is where commentary usually overreaches. I have seen no public evidence of a combined operations center for election interference, and the limits of the alignment are real — China and Russia did not come to Iran’s aid when the United States struck its nuclear facilities. These are not allies. They are services with overlapping interests and the professional sense not to duplicate each other’s work.
But convergence does not require coordination to produce a coordinated effect. And I would assess this with confidence: they are methodical, they read the same public polling everyone else reads, and effort will concentrate where margins are thin. Targeting close races is not a sophisticated insight. It is the first thing any competent targeting officer does, and all three services have competent targeting officers.
The operational implication is the uncomfortable part. A jurisdiction’s exposure has nothing to do with its size and everything to do with its margin. The contested state house district is a better target than the safe Senate seat, and it is precisely the jurisdiction with no analyst, no threat feed, and nobody to call.
Iran industrialized the proxy. Watch who is using it now.
Iran did not invent the idea of achieving an effect through somebody else’s hands, but it industrialized it. Hezbollah is the case study taught everywhere — an organization Tehran funds, arms, trains and directs, and can disclaim in the same week it resupplies. The value was never that Hezbollah could do things Iran could not. It is that Hezbollah could do things Iran could not be blamed for. Attribution is the cost that matters. A proxy is a machine for lowering it.
Now look at the architecture China has built with Iran and ask what it resembles.
China buys roughly 90 percent of Iran’s exported oil — about 1.4 million barrels a day in 2025, discounted eight to ten dollars a barrel, worth on the order of $31 billion a year to the Iranian state. It granted Iran’s military full access to the BeiDou satellite navigation system in 2021. Chinese sensors, voltage converters and semiconductors turn up inside Iranian drones. Reporting this year describes direct Chinese arms sales including attack drones and near-final anti-ship cruise missile deals, and Iranian state vessels loading solid rocket fuel precursors at a Chinese port in March. The two signed a 25-year comprehensive strategic partnership in 2021 covering economy, security and technology.
Then look at what China has conspicuously not done. It has avoided formal defense commitments. Its last bilateral military meeting with Iran was in 2022. When the United States and Israel struck Iranian facilities, Beijing’s support amounted to statements about international law.
That combination is the whole point. China funds the state, equips it, guides its missiles, and shields its oil revenue through an evasion network that by late last year had placed 366 Chinese and Hong Kong entities under Iran-related sanctions — while holding a posture from which it can credibly say it is not a party to anything. The distance is not an accident of the relationship. It is a feature of it, and it is maintained on purpose.
I want to be fair to the competing reading, because it is the mainstream one. Analysts who study this closely describe Iran as a strategic partner and a testbed rather than a proxy, and note that China uses the conflict to observe American and Israeli systems performing under real conditions. That is a defensible reading of the same facts.
Mine is different, and it comes from the direction of the leverage. Hezbollah is not Iran’s equal either, and nobody calls that a partnership of convenience. When one party supplies ninety percent of the other’s export earnings, its satellite navigation, and components for its strike systems, while declining every reciprocal obligation, the word for the weaker party is not partner.
A proxy is a machine for lowering the cost of attribution. China has more to lower than anyone.
If that reading is right, the implication for an American election is not that Chinese officers will be caught running an operation. It is that they will not be. China’s exposure from attribution is categorically greater than Iran’s — Iran is already sanctioned, already isolated, already accused of interference in 2020. China is still trading. A state in that position pursues what it can through hands that are already dirty, and Iranian services have both the motive and an existing footprint inside the United States, built over years for entirely different purposes.
Let me be exact about what that last paragraph is. It is an assessment built from structure and incentive, not a finding, and I would not present it as one. I am not asserting that it is happening. I am saying that if I were sitting in Beijing with a hundred-year horizon and a low tolerance for embarrassment, it is what I would do — and that the relationship required to do it is already built, already funded, and already in the open.
China is not running on our clock
There is a structural reason China gets underestimated in this conversation, and it has nothing to do with capability.
Western democracies plan in two, four and six year increments, because that is how long anyone holds the job. Every strategy is hostage to the next election. A program begun under one administration is reviewed by the next and cancelled by the one after. We do not have a mechanism for sustaining an idea longer than the career of the person who had it.
China is not under that constraint, and the evidence is not theoretical.
In 1972 the People’s Republic opened to the United States. The conventional reading is that both sides wanted leverage against the Soviet Union, and that is true as far as it goes. What followed was fifty years of access — to American markets, American capital, American universities, American technology, American supply chains — that took a poor agrarian country and produced the only peer competitor the United States has.
Whether every step of that was foreseen in Beijing in 1972 is something historians can argue about. I would observe only that the outcome is indistinguishable from a plan that worked, and that the burden of proof has moved. Name a policy a Western democracy adopted fifty years ago that arrived on time, intact, and produced what its authors intended. I cannot think of one.
Fifty years is five presidential cycles and twenty-five congressional ones. On the Chinese planning horizon it is a rounding error.
The relevance to an election is this. The United States has spent three decades bracing for a foreign interference campaign shaped like an attack — an event, dated, attributable, survivable. The likelier shape is an investment. Not bullets and not missiles, but patience applied to the seams of a society that argues in public and forgets quickly. Fifty years from now somebody may write that China had a plan in 2020 and collected on it in 2070, and that sentence will read as obvious in a way it does not read today.
What 2026 actually looks like
The tradecraft has moved since 2024, and in each case it has moved toward cheaper and more scalable.
Russian operations have run in part through the Social Design Agency, a state-linked public relations firm building fake personas at volume, and in May of this year extended to compromising existing Bluesky accounts — a meaningful shift, because a hijacked account with real history and real followers defeats most of the heuristics built to catch new fake ones.
Chinese operations have paid people to pose as Western journalists and influencers, documented in a European Council report in March, and have begun using AI-driven audience analysis platforms to target message amplification rather than spray it.
Iranian operations have leaned hardest into synthetic media, running AI-generated influencers and fabricated news sites, and in February amplified a fake video of a US military aircraft crash.
None of this is exotic. All of it is detectable. Detection requires somebody to be looking, with tooling and an intelligence feed, on behalf of jurisdictions that have neither.
The defense came apart between cycles
Here is what changed on the American side since the last presidential election.
Federal funding for the Multi-State Information Sharing and Analysis Center ended. States that want to stay in it now pay their own membership fees; Georgia, Minnesota, Washington and New Mexico are among those doing so. Congress cut hundreds of millions of dollars from CISA’s budget, the agency reduced its election-security personnel, and the regular intelligence briefings to states stopped — the thirty that became none.
The Election Threats Executive role, the position whose job is to coordinate exactly this, sat vacant until May of this year. The election security group that NSA and Cyber Command were to stand up had not been established as of July. This is the first cycle since 2016 in which federal support for election security is substantially absent.
I want to be careful here, because this is where analysis usually turns into advocacy. I am not arguing that these decisions were made in bad faith, and reasonable people can hold that the federal government had grown too involved in policing election-related speech. That is a legitimate argument and it is not the one I am making.
The argument I am making is narrower. Whatever one believes about the content-moderation fights of the last cycle, threat briefings to state election officials are a different function. Telling Georgia that a specific foreign network is probing its voter registration portal is not moderating speech. It is the ordinary work of counterintelligence, and it has stopped.
What a state can buy and what it cannot
States have replaced what money can replace. Minnesota substituted private-sector vendors for federal cybersecurity testing. Several states absorbed the membership fees. Washington’s Secretary of State describes running the same operation “with far less resources than we did before.”
But the thing that mattered most is the thing no state can procure. Minnesota’s Secretary of State, Steve Simon, named it precisely: “One area that is very difficult to replace is intelligence briefings. That is not something that we can just go to a store and buy.”
He is right, and the reason is structural. A foreign intelligence service operating against a county election office is visible from two places: inside that service, and inside the US intelligence community. It is not visible from the county. No vendor sells it, because no vendor has collection against the GRU or the MSS or the IRGC. A state can buy a penetration test. It cannot buy the knowledge that a specific adversary is currently interested in it.
This is the asymmetry that should worry people. The offensive side got cheaper and more scalable. The defensive side lost the one input it could not generate for itself.
The constraint was never knowledge
Everything in this piece is already known. The three adversaries and their distinct objectives are documented in unclassified intelligence assessments. The tradecraft is described in public reporting. The dismantling of the federal support structure is on the record, complained about on the record by Republican and Democratic secretaries of state alike.
Nobody lacks information. What is missing is capacity — somebody positioned, funded, and accountable for turning what is known into something a county clerk in a contested district can act on before the first Tuesday in November.
That gap between knowing and being able to act is where most security failures live. It is where this one is living now. Six weeks is not enough time to rebuild an intelligence-sharing relationship that took eight years to construct and one budget cycle to take apart.
The question for November is not whether Russia, China and Iran will try. They will, separately, for their own reasons, and the effects will converge whether or not anyone coordinated them. The question is who will be positioned to notice.
The answer to a patient adversary is not a better tool. It is the one thing an adversary betting on our short horizon does not expect us to produce: a decision that outlasts the people who made it. Election security was a bipartisan function for eight years because a foreign service probing a voter registration database is not a partisan event. It became a partisan football, and the capability went with it. Rebuilding it requires politicians to behave, on this narrow question, as something other than politicians. That is a low bar and we are not currently clearing it.
Sources
- NOTUS, “States Are Struggling to Replace the Election Cybersecurity Infrastructure Trump Dismantled” — Raffensperger, Simon and Hobbs quotes; MS-ISAC funding and state fees. notus.org
- Brennan Center for Justice, “Threat of Foreign Influence on U.S. Elections Remain as Federal Defenses Recede” (July 2026) — 2026 tradecraft; Election Threats Executive vacancy; NSA and Cyber Command election security group. brennancenter.org
- PBS NewsHour, “Report: Efforts by Russia, Iran and China to sway U.S. voters may escalate” — distinct objectives by country; Spamouflage targeting of down-ballot candidates; Iranian use of the Israel–Gaza fault line. pbs.org
- U.S.–China Economic and Security Review Commission, “Axis of Autocracy: China’s Revisionist Ambitions with Russia, Iran, and North Korea” — degree of alignment; mutual amplification of state narratives; limits of the partnership. uscc.gov
- U.S.–China Economic and Security Review Commission, “China–Iran Fact Sheet: A Short Primer on the Relationship” — oil purchase volumes and discounts, the 25-year partnership, BeiDou access, dual-use components, arms transfers, sanctions designations. uscc.gov
- Irregular Warfare Initiative, “Chinese Eyes, Iranian Missiles: Intelligence Cooperation in the US/Israel–Iran War 2026” — the partner-and-testbed reading of the relationship. irregularwarfare.org
- Nextgov/FCW, “Federal drawdown of election support ‘destroyed’ ongoing relationships, experts say” (April 2026). nextgov.com