There is a story that circulates whenever someone wants to argue that an election could be taken away. It goes like this: a cybersecurity company ran a simulation of an attack on election day, federal agents took part, the attackers flooded the 911 lines and drove a self-driving bus into a queue of voters, and at the end the election was cancelled, everyone was sent home, and martial law was declared.
The exercise is real. The agencies are real. Most of the tactics are real. The ending is not.
We went back to what the company published at the time, including pages that are now only available through the Internet Archive, and read the results of each run. Nobody cancelled an election. Nobody declared martial law. What the exercise did find is less dramatic, already measurable in the real world, and considerably more useful to know, especially in Canada, where the defences are built differently.
What Operation Blackout actually was
Cybereason, a security firm based in Boston, ran a series of tabletop exercises about attacks on election day. A tabletop exercise is a structured role-play. No systems are touched and no code is run. Teams take turns declaring moves, and a control team decides what each move does to the scenario.
The setting was always the same: a fictional American city called Adversaria, in the weeks leading to a national election. The attacking side, the red team, was made up of Cybereason employees, white hat hackers, academics and university students. The defending side was real law enforcement. For the 2019 run that meant staff from the Department of Homeland Security, the US Secret Service, the Massachusetts State Police, the Rhode Island State Police and Boston Police. Cybereason staff ran the game and adjudicated it.
It ran more times than most people realise. Two exercises took place in Boston in 2018, one of them in September, ahead of the US midterms. Further exercises followed in 2019 and early 2020 in Washington DC, San Francisco, Manchester in New Hampshire, Paris and London. A virtual edition was held on August 19, 2020. None of them was run in a Canadian city.
The one rule that made it interesting
The rule that shaped everything was that the attackers were not allowed to touch the election equipment. No hacking voting machines, no tampering with the voter roll.
That was deliberate, and it is the most useful thing about the whole project. Almost every public conversation about election security is about machines and ballots. By taking those off the table, the exercise asked a different question: how much damage can you do to a vote without going anywhere near it?
The answer was: quite a lot, and cheaply. Across the runs the red team spread false information through fake social accounts, took over a municipality’s own social media so its misinformation arrived through a trusted channel, turned off a city’s closed-circuit cameras, hit a 911 call centre with a denial of service attack, interfered with self-driving cars and navigation apps to create gridlock, sent robocalls telling mail-in voters their ballots were already counted so they should stay home, and tried to provoke violence at a polling place.
So the specific images that travel online are not invented. Self-driving vehicles really were part of it, in the September 2018 Boston run. The 911 attack was real. The deepfake capability was a move a team could develop and then spend.
How each one actually ended
Here is where the story breaks, and it breaks in three different ways.
In the September 2018 exercise in Boston, the defending side was police officers from Massachusetts towns alongside state and local officials, and their objective was simply to keep the city’s polls open. Cybereason wrote that the exercise was not designed to name a winner or a loser, but that the hackers had the advantage.
In the 2019 exercise, the one announced as Operation Blackout 2020, the outcome was the opposite. Cybereason’s own announcement says the defending team scored a solid victory, that election integrity was preserved, and that there was no long term controversy over the results.
In the August 2020 virtual edition, the election went ahead. The published summary records a marginal result decided by a coin toss. Robocalls went out telling mail-in voters to stay home and were largely ignored by everyone else. Some voters were re-routed to the wrong district, but most had voted from home anyway. An attempt to start violence at the polls was handled by a strong police presence, with the mayor, the governor and the police chief all appearing in person.
No cancelled election. No state of emergency. No martial law. In every published run, the city voted.

What they were actually trying to do
The reason this matters is not that a viral claim got the ending wrong. It is that the real ending is the more alarming one, and it gets lost.
The hackers' goal was not to manipulate or stop the vote, it was to get voters to question the validity of the system itself. Sam Curry, then chief security officer at Cybereason, July 31, 2019
Read the 2020 results again with that in mind. The election was held and a winner emerged. Then a party filed a class action the next day, and the validity of the result was questioned for a full year by 30 percent of one side’s voters, with a “Not My President” movement outrunning the city’s own messaging.
By the standard people apply to these stories, the defenders won. By the standard the attackers set for themselves, they got exactly what they came for. You do not need to stop a vote if you can make a third of the country refuse to believe it.
Cybereason’s own lessons from the exercises say the same thing in plainer language. Communications are the new battleground, because controlling a city’s social accounts let false information arrive through channels people already trusted. Causing confusion is cheap, commoditised and does not require a nation state, just someone motivated with a little knowledge. And defenders cannot prepare for every scenario, because an attacker can act across a huge range of options while law enforcement has to stay inside the law.
What Canada actually has
Canada never hosted one of these exercises, which is worth saying plainly given how often the story is repeated as though it describes something here. What Canada has instead is a standing structure, and it is less theatrical.
The Security and Intelligence Threats to Elections Task Force was created in 2019 as part of the federal plan to protect democracy. It brings together the Canadian Security Intelligence Service, the Communications Security Establishment, Global Affairs Canada and the RCMP. It reviews intelligence on interference in democratic processes, briefs Elections Canada, assesses cyber threats to election systems and investigates related criminal activity. Since July 2024 it has monitored by-elections on a permanent basis rather than standing up only for general elections.
Alongside it, the Canadian Centre for Cyber Security publishes an assessment of cyber threats to the democratic process, and its numbers are more concrete than anything in the simulation. In its update based on information available as of January 27, 2025, the Centre counted 102 reported cases of generative AI being used to interfere with or influence 41 elections worldwide across 2023 and 2024, which is 27 percent of the elections it examined. Of the 151 elections assessed, it identified 60 synthetic disinformation campaigns and 34 cases of social botnets. It also assessed that it is very unlikely, which it defines as roughly a 10 to 30 percent chance, that AI-enabled disinformation would fundamentally undermine the integrity of Canada’s 2025 general election.
That is the shape of the real risk. Not a bus driven into a polling queue, but a steady volume of cheap synthetic content, most of it unattributed, aimed at the part of the process that runs on trust.
Why this is on a crypto site
Two reasons, and the first is the one that should matter to anyone who holds digital assets.
The playbook the red team used is the same one that makes crypto fraud work: manufacture urgency, arrive through a channel the target already trusts, and move faster than anyone can verify. The Cyber Centre’s finding that it does not take much time, money or effort to cause confusion is exactly what we found when we went through how AI crypto scams work in Canada. The defence is identical too, and it is unglamorous: slow down, and check the claim at its source.
The second is a rule change most people missed. The Strong and Free Elections Act received Royal Assent on June 18, 2026 and amended the Canada Elections Act to bar federal parties, candidates and registered third parties from accepting contributions in crypto assets, along with money orders and prepaid cards, on the grounds that they are hard to trace and could conceal foreign money. Penalties reach $25,000 for individuals and $100,000 for organizations. It is in our law tracker with its dates and primary source.
The part worth remembering
The people who ran Operation Blackout were not trying to prove that democracy is fragile. They were trying to show local police and city officials what a bad day looks like before they have one, which is the entire point of a tabletop exercise.
What they found, over six runs and three years, is that an attacker who cannot touch a single ballot can still win, provided the goal is doubt rather than votes.
So does the simulation come true? Not the version in the retelling. The cancelled election and the martial law are not in the record, and nothing since suggests they are coming. But the finding the exercise actually produced is no longer hypothetical. The Cyber Centre has counted 102 real cases of generative AI used to interfere with 41 elections around the world in two years, most of it unattributed and none of it requiring anyone to go near a ballot. The 2020 run ended with a valid result and a third of one side refusing to accept it for a year, which is a description of several real elections since.
That is the uncomfortable part. Operation Blackout was a rehearsal, and the thing it rehearsed is happening. It just does not look like the story people tell about it. We took the same approach to the video that put this story back in circulation in our fact-check of the AI financial crisis theory, where the pattern is identical: the documented parts are strong enough that an invented ending rides along unchallenged.
