Pentagon's Midterm Election Security Memo, Explained: What Cyber Command Will Do

- 🔑 Defense Secretary Pete Hegseth has directed U.S. Cyber Command, the National Security Agency, the Defense Intelligence Agency and the National Geospatial-Intelligence Agency to use cyber and intelligence tools to find and stop foreign interference in the 2026 midterms, coordinating with the Department of Homeland Security on election-infrastructure threats.
- The memo does not order troops, National Guard personnel, or any physical security presence at polling places — it directs intelligence and cyber operations through Cyber Command, not a domestic deployment, even though some lower-quality coverage has blurred that distinction since the story broke.
- Multiple accounts of the memo date it to around 22 September 2026, though the Pentagon did not publicly disclose its existence until Monday, 28 September 2026 — roughly five weeks before the 3 November 2026 midterms, and after weeks of reporting on gaps in federal election-security readiness.
- The order responds partly to a gap flagged in April 2026, when Gen. Joshua M. Rudd, who leads both Cyber Command and the NSA, told lawmakers he was not certain whether the Election Security Group — the NSA-Cyber Command hub active every election cycle since 2020 — had been reactivated for this one.
- The memo follows earlier cuts to federal election-security capacity: the Cybersecurity and Infrastructure Security Agency has lost roughly a third of its workforce since January 2025, and two Democratic lawmakers publicly demanded restored funding for state-level election-security support on 3 September 2026.
- Whether the Election Security Group has since been formally confirmed as stood up for this cycle, and whether any specific foreign interference attempt gets disclosed before 3 November 2026, both remained unresolved facts as this article was written and are worth rechecking closer to Election Day.
Defense Secretary Pete Hegseth has ordered U.S. Cyber Command and three defense intelligence agencies to use cyber and intelligence tools — not troops — to find and shut down foreign interference in the November 2026 midterms. The Pentagon disclosed the directive on Monday, 28 September 2026, roughly five weeks before Election Day, after months of public uncertainty over whether a key election-security team had even been reactivated for this cycle. Here is what the memo covers, what it does not, and why it landed now.
What does the memo actually direct Cyber Command to do?
The memo instructs U.S. Cyber Command and the wider Defense Intelligence Enterprise to deploy intelligence and cyber capabilities to “identify, disrupt, and neutralize foreign interference” in U.S. elections, then work with the Department of Homeland Security on threats that touch election infrastructure specifically. Four organizations are named directly: Cyber Command itself, the National Security Agency, the Defense Intelligence Agency and the National Geospatial-Intelligence Agency. The memo’s own language, quoted across multiple accounts of it, frames the goal in sweeping terms: “In America, the people rule — and we must ensure that their voice remains sovereign, secure, and entirely undiluted.” A second line sets the timing explicitly: “As we approach this election cycle, we must prove that we can and will protect the integrity of our democratic processes from any threat.”
| Agency | Role |
|---|---|
| Cyber Command | Leads cyber operations against foreign threats |
| NSA | Signals intelligence, shares a commander with Cyber Command |
| DIA | Defense intelligence analysis |
| NGA | Geospatial intelligence |
| DHS | Coordinates on election-infrastructure threats |
Does this mean troops are being sent to polling places?
No — the memo itself contains no order to send military personnel, National Guard troops, or any physical security presence to polling places. It is a cyber-and-intelligence directive, executed through a military command structure but aimed at foreign digital interference, not at securing physical voting locations. That distinction matters because some lower-quality coverage of this story has blurred a cyber directive with a domestic troop deployment, which this memo is not. Separately, some Democratic lawmakers and election-security advocates have voiced broader unease about the administration’s approach to the military’s role near elections in other contexts — but that concern is distinct from, and not raised by, anything in this specific memo.
When was the memo actually signed?
Reporting on the memo’s exact signing date is not fully consistent, so it is worth stating plainly what is and is not confirmed. Most accounts describe the document itself as dated around 22 September 2026, with the Pentagon only making its existence public five days later, on Monday, 28 September 2026. At least one account instead describes Hegseth as signing it that same Monday. No primary Defense Department release with a visible signature date was available to confirm either timeline definitively. What is confirmed is the disclosure date — Monday, 28 September 2026 — which puts the announcement about five weeks ahead of the 3 November 2026 midterms.
What is the Election Security Group, and has it been reactivated?
The Election Security Group is a standing coordination hub between the NSA and Cyber Command that has operated ahead of every general and midterm election since 2020, sharing intelligence and, in past cycles, acting directly against foreign disinformation networks. In 2024, for instance, Cyber Command operations disrupted a Russian troll-farm influence campaign targeting American voters. The concern driving this week’s story is that the group’s status for 2026 was, until now, genuinely unclear: in April 2026 congressional testimony, Gen. Joshua M. Rudd — who leads both Cyber Command and the NSA — said he did not know whether the group had been stood up for the midterms. A former Cyber Command official who worked on the 2020 cycle has noted publicly that the group’s preparatory work normally takes months and happens well before Election Day, which is why a late activation would limit its impact. As of this writing, no source confirms the group has since been formally reactivated — the new memo directs the underlying agencies to act, but does not by itself answer whether that specific coordination structure is now running.
Why is this considered notable, rather than routine election-cycle housekeeping?
It follows a documented reduction in the federal government’s broader election-security capacity since early 2025. The administration previously disbanded or downsized units within the FBI and the Office of the Director of National Intelligence that had focused on countering foreign influence operations. Separately, the Cybersecurity and Infrastructure Security Agency — the civilian agency that supports state and local election officials — has lost roughly a third of its workforce, from about 3,400 employees in January 2025 to around 2,300. On 3 September 2026, two Democratic members of Congress publicly demanded that the administration restore funding to a state-level election-security information-sharing program. Against that backdrop, a memo explicitly directing military cyber and intelligence agencies to prioritize election interference reads, to the officials and former officials quoted across multiple accounts of this story, as an attempt to close a gap that had been publicly flagged for months rather than as a new capability being built from scratch.
What happens between now and Election Day?
The memo sets a direction, not a finished operation, and several open questions will only be answered as 3 November 2026 approaches. Whether the Election Security Group is confirmed as fully operational, whether Cyber Command discloses any specific foreign interference attempt before the midterms, and whether Congress presses the Pentagon or CISA for further detail on staffing and readiness are all still unresolved as of this writing. This is a live policy story rather than a closed one, and the details here should be treated as a snapshot of where things stood in the last days of September 2026.
The mechanism is worth remembering above all: this is a cyber and intelligence directive, aimed at foreign actors and routed through defense agencies working with DHS on election infrastructure — not a domestic security deployment to polling places. We’ll follow this one through to Election Day.
How we verified this
What the memo orders was checked against several independent accounts of it — wire-service political reporting, a defense-trade outlet, and congressional-policy reporting — which agree on the four agencies named (Cyber Command, the NSA, the DIA and the NGA), the coordination role given to the Department of Homeland Security, and the “identify, disrupt, and neutralize foreign interference” language that multiple accounts quote directly from the memo’s text.
The exact signing date is reported inconsistently, so it is hedged rather than stated as settled fact. Most accounts date the memo itself to around 22 September 2026 and describe the Pentagon as publicly disclosing it on Monday, 28 September 2026; at least one wire account instead describes Hegseth as signing it on the 28th. No primary Defense Department document showing a signature date was available to this writer, so this piece treats 22 September as the reported drafting date and 28 September as the confirmed public-disclosure date, and does not assert a single date as certain.
The Election Security Group’s current operational status for 2026 is unconfirmed. Gen. Joshua M. Rudd’s April 2026 testimony that he did not know whether it had been reactivated is on the record from congressional-hearing reporting. No source found since then confirms the group has since stood up, so this piece states that status as still open rather than assuming the new memo has settled it.
CISA’s staffing figures (a drop from roughly 3,400 employees in January 2025 to about 2,300) and the 3 September 2026 congressional letter demanding restored state-level election-security funding are both drawn from federal-technology and cybersecurity-policy reporting and are consistent across more than one such account.
No betting odds, spreads, prediction-market prices, or win-probability models appear anywhere on this page. This is a policy directive and its documented context, not a forecast of any election outcome.