Rising threats, evolving cyber risks, and exposure through everyday information all point to strengthening operational security and sharpening containment practices to stay ahead of incidents before they escalate. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
ESX News Header

May 20, 2026

TLP:CLEAR

In This Issue:

  • Situation Room: Threats and harassment directed at public officials in Ohio and Indiana exemplify the risk posed by the personal information trail and the importance of operational security.
  • Resource Library: First Things First: Operational Security Fast Wins is a new resource highlighting five core focus areas to protect against operational risks.
  • Planning Desk: In the Incident Response Process, containment describes the importance of stopping the spread of a cyber attack before attempting to fix it.
Header text: Situation Room

Threats and the Personal Information Trail

 

The case file from an April conviction in an Ohio federal court demonstrates how the availability of personal information can disguise threat actors, help them find their targets, and amplify the fear they provoke.

 

Recently, an Ohio man pleaded guilty to sending 92 threatening communications targeting more than 30 Ohio public officials, including the Governor, Attorney General, Secretary of State, and several members of Congress.

 

Through 2024 and 2025, he sent nearly 50 letters containing white powder he sometimes referred to as ricin. He mailed the letters to victims’ offices and homes, including seven different addresses for the Governor. In some, he included the names of spouses and often used return addresses for staffers, law firms and other individuals in the community. Last December, Ohio Secretary of State Frank LaRose and his family were forced to evacuate their home after receiving one of the letters containing a powder. Following that mailing, ... READ MORE HERE.

 

The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.

Header text: Resource Library

First Things First: Operational Security Fast Wins

 

First Things First: Operational Security Fast Wins from the Election Security Exchange is a quick-start guide that highlights common Operational Security (OpSec) risks and provides straightforward and easy ways to mitigate them.

  • Reduce details included in public staff directories and direct contact lists. Posted phone lists, email directories, and counter signage make it easy for outsiders to map a team and reach individuals directly. Use general email inboxes and main office numbers, and keep personal details out of email signatures.
  • Standardize responses to operational questions. Seemingly harmless procedural details, when combined, can build a useful intelligence profile. Train frontline staff to share only what is legally required, and route detailed process questions to designated supervisors.
  • Delay posts about travel and real-time location. Posting from a conference, a destination, or a daily routine tells anyone watching where staff are and when they are away from home or work. Disable geotagging, review social media privacy settings, and wait until after a trip to post.
  • Shield internal information from casual capture. Whiteboards, check-in sheets, monitors, and credentials in public-facing areas can be photographed or read at a glance. Reposition materials, use privacy screens, and place clear "Staff Only" signage where appropriate.
  • Rethink name badge practices. Full names paired with visible credentials make staff easy to identify, research, and target. Use first-name or last-name only where the law allows, limit titles, and remove badges as soon as the event ends.

Additional Resources:

  • Determine your level of vulnerability and pinpoint public information you need removed by using the Digital Footprint Self-Assessment Worksheet.
  • For a more detailed discussion on getting online information removed, see How to Mitigate Doxxing for information on services that can help keep your data off the web.
  • If you’re suffering a doxxing attack or want to learn more about how to respond, review Doxxing Incident Response, a step-by-step checklist that can help you protect yourself even after an incident has begun.

Your consistent OpSec habits make it harder for bad actors to map staff, facilities, and operations. A short, regular review of the website, the front counter, and the team's online presence is often where the most valuable adjustments can be made.

 

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.

Header text: Planning Desk

Week E-24: Containment: Stop the Spread Before You Fix Anything

 

When responding to an incident, after analysis tells you what happened, the pressure becomes immediate: get the office back to normal. Phones are ringing, leadership wants reassurance, the public wants results. The instinct is to jump ahead to recovery.

 

Resist it. The first step in Phase 3 of the Incident Response Process is containment, and skipping it is how a one-day incident becomes a two-week one. Rushing to get your network back online before the incident is fully contained can allow the threat actor to continue wreaking havoc, such as encrypting all of the systems. You cannot fix what is still spreading.

 

The principle of containment can be applied to physical incidents as well, though they are usually so extreme – active shooter, suspicious substance in mail – that large steps are taken immediately. In this issue, we are focusing on cyber incidents, what you should know about containment, and the actions you can take as an election official. ... READ MORE HERE.

 

The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.

Header text: Election Security News


Want to get daily updates on election news? Subscribe to electionline.

  • 2026: The Year of AI-Assisted Attacks | The Hacker News (May 4, 2026) // International
  • U.S. Senator Presses CISA on Election Security Rollbacks | GovInfoSecurity (May 8, 2026) // National
  • ODNI taps officials to coordinate response to foreign election threats | The Record (May 14, 2026) // National
  • What Americans think about election policy and how the 2026 elections will go | Votebeat (May 18, 2026) // National 
  • Future of Cybersecurity | Axios (May 19, 2026) // National
  • State lawmakers want to rein in artificial intelligence. Here's how. | Chicago Sun Times (May 12, 2026) // Illinois

 

LinkedIn
YouTube
Email
Website

Copyright © 2026 Election Security Exchange. All rights reserved. TLP:CLEAR

 

You are receiving this email because you subscribed to the Election Security Exchange Newsletter.

 

Find this useful? Pass it along and invite other election teams to subscribe.

Subscribe

Election Security Exchange

712 H Street NE, Suite 2456

Washington, DC, 20002, United States

Unsubscribe Manage Preferences