Situation Room: Phishing and its cousins vishing and smishing - different methods to deliver the same trick - remain a persistent threat to election offices.
Resource Library: A newly released interactive online tool, AI Use: Dos and Don’ts, helps you craft customized AI use guidance for your election office.
Planning Desk: Testing the entire election process includes reviewing core post-election procedures and systems to reinforce the integrity of data all the way through canvass and retention.
Phishing, Vishing, Smishing: One Trick, Three Delivery Methods
In September 2024, theDepartment of Justice indicted three Iranian nationals, members of the Islamic Revolutionary Guard Corps, for running a targeted phishing operation against people connected to the U.S. presidential campaigns. They set up fake websites with fake login pages and then created “fraudulent email accounts in the names of prominent U.S. persons and international institutions.” From these accounts, they sent emails directing campaign staff back to those fake pages to gain unauthorized access to staffers’ accounts.
At least one staffer was fooled by this phishing schemeand entered real user credentials into a fake login page. The actors used that information to steal confidential campaign documents, which they then tried to leak to the media and to another U.S. presidential campaign.
In January 2026, Google Threat Intelligence documented a wave of phishing-style attacks delivered by phone, called vishing(voice-phishing). The malicious actors called employees at several corporate offices, posing as IT support. They directed staff to visit fraudulent websites designed to resemble their companies’ login pages and instructed them to enter their credentials. The attackers used those stolen credentials to harvest sensitive corporate data and internal communications, and to bulk-export customer records, then used the stolen data to extort companies and individuals.
And late last year, Google accused a criminal network based in Chinaof a different spin on phishing, using normal text message channels to deliver fake web addresses. Because text messages travel over “Short Message Service,” or SMS, these attacks are called smishing.
Since early 2024, the FBI has logged tens of thousands of complaints about fake toll and delivery texts that malicious actors used to compromise credit cards (“you owe a small unpaid fee, click here”). In October 2024, the Bureau warned that scammers were using election themes, candidate names, and logos to phish for personal information and donations by text. A text feels casual and personal, which is exactly why people tap the link.
What It Means For Your Office
Phishing, vishing, and smishing are the same trick. Someone pretends to be a person or an office you trust, sprinkles in a sense of urgency, and asks you to click, maybe call or text back, share a password, or provide payment. All three work against jurisdictions large and small.
A single clicked link in an official’s email can hand an attacker the keys to a vendor portal, a payroll system, or confidential details.
A caller posing as IT support or a state official checking on a system asks an employee or poll worker to confirm a login or read back a security code.
A text purporting to be from the website service provider tells an employee to log in again through a specific link for mobile access to the office website or email.
The defense is the same for all three attack types:
Slow down. Manufactured urgency is the tell. Take9 says it pretty plainly: Pause nine seconds before you act on a message that wants you to move fast.
Verify through trusted channels. Hang up and call the office back on its published number. Do not use the link, phone number, or callback in the message itself.
Never give a password, code, or payment just because someone contacted you first.
Report it. Send suspicious election-related messages to your state or local election office and to the FBI’s Internet Crime Complaint Center at ic3.gov.
Practice With Your Team
Your staff and poll workers can practice spotting phishing, vishing, and smishing for free. The Exchange offers no-cost election security training, including phishing awareness, at election-security-training.securingelections.org. Do the basics, and do them well.Most attackers will move on to an easier target.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see thenewsletter archive.
AI Use: Dos and Don'ts
Artificial Intelligence (AI) is already part of the daily work in many election offices. Whether it's drafting a social post, analyzing turnout data, summarizing a document, or powering the phishing attempt on the other end of an email, staff encounter AI daily. A clear, shared reference for what is and is not appropriate helps your team make responsible decisions when they matter most.
It’s easy to use. Drag a card from the suggestion rail into the “Do” or “Don’t” column. You can add your office logo, name of your jurisdiction, and set the date. Once the sheet reflects how your office works, you can print it, save it as a PDF, or email it.
Remember, this tool is a starting point, not a substitute for your organization’s policies, applicable state law, or advice from legal counsel. It’s meant to guide your team as you build your dos and don’ts.
The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.
Week E-14: Protecting the Integrity of Records
Part 3: Early Testing of Post-Election Systems and Processes
Once polls close, the work of securing election records continues. Data transfer, verification, and documentation are essential parts of the post-election phase and ensure accurate, secure, and well-documented certification.
This installment of our four-part series on testing the entire election process walks through core post-election processes with a security lens. We’re highlighting where risks emerge and how election offices can reinforce the integrity of their data all the way through canvass and retention. All workflows benefit from testing and refinement well before the post-election period.
Absentee Processing:Securing Ballot Flow
In some jurisdictions, absentee processing continues beyond Election Day, and every step must preserve the chain of custody and accuracy of voter participation records. You can test absentee workflows today by walking through the data transfer and reconciliation steps you’ll rely on later.
Run a mock reconciliation of issued, returned, and counted ballots to confirm your reports match across systems.
Test how absentee status updates move into voter registration and canvassing systems.
Validate that late-arriving UOCAVA and provisional ballots have a clear, documented workflow.
Ensure your documentation of absentee processing supports both internal review and public transparency.
These checks help you confirm that your data flows cleanly, your reports are accurate, and staff know how to handle exceptions.
Provisional Ballots: Curing, Processing, and Documenting Decisions
Provisional ballots introduce manual decision‑making, which means you can test the security of these workflows in advance.
Review and test your curing workflow with sample cases.
Confirm that each decision point has clear ownership and documentation requirements.
Practice entering provisional decisions into voter registration and canvass systems, then verify the results.
Errors here cascade. A single mis-entered status can affect participation records, reporting, and audit trails. This early testing helps ensure that high‑risk, exception‑driven work is consistent and defensible.