Situation Room: Threats and harassment directed at public officials in Ohio and Indiana exemplify the risk posed by the personal information trail and the importance of operational security.
Resource Library:First Things First: Operational Security Fast Wins is a new resource highlighting five core focus areas to protect against operational risks.
Planning Desk: In the Incident Response Process, containment describes the importance of stopping the spread of a cyber attack before attempting to fix it.
Threats and the Personal Information Trail
The case file from an April conviction in an Ohio federal court demonstrates how the availability of personal information can disguise threat actors, help them find their targets, and amplify the fear they provoke.
Recently, anOhio man pleaded guiltyto sending 92 threatening communications targeting more than 30 Ohio public officials, including the Governor, Attorney General, Secretary of State, and several members of Congress.
Through 2024 and 2025, he sent nearly 50 letters containing white powder he sometimes referred to as ricin. He mailed the letters to victims’ offices and homes, including seven different addresses for the Governor. In some, he included the names of spouses and often used return addresses for staffers, law firms and other individuals in the community.Last December, Ohio Secretary of State Frank LaRose and his family were forced to evacuate their home after receiving one of the letters containing a powder. Following that mailing, ... READ MORE HERE.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see thenewsletter archive.
First Things First: Operational Security Fast Wins
First Things First: Operational Security Fast Winsfrom the Election Security Exchange is a quick-start guide that highlights common Operational Security (OpSec) risks and provides straightforward and easy ways to mitigate them.
Reduce details included in public staff directories and direct contact lists. Posted phone lists, email directories, and counter signage make it easy for outsiders to map a team and reach individuals directly. Use general email inboxes and main office numbers, and keep personal details out of email signatures.
Standardize responses to operational questions. Seemingly harmless procedural details, when combined, can build a useful intelligence profile. Train frontline staff to share only what is legally required, and route detailed process questions to designated supervisors.
Delay posts about travel and real-time location. Posting from a conference, a destination, or a daily routine tells anyone watching where staff are and when they are away from home or work. Disable geotagging, review social media privacy settings, and wait until after a trip to post.
Shield internal information from casual capture. Whiteboards, check-in sheets, monitors, and credentials in public-facing areas can be photographed or read at a glance. Reposition materials, use privacy screens, and place clear "Staff Only" signage where appropriate.
Rethink name badge practices. Full names paired with visible credentials make staff easy to identify, research, and target. Use first-name or last-name only where the law allows, limit titles, and remove badges as soon as the event ends.
For a more detailed discussion on getting online information removed, see How to Mitigate Doxxingfor information on services that can help keep your data off the web.
If you’re suffering a doxxing attack or want to learn more about how to respond, reviewDoxxing Incident Response, a step-by-step checklist that can help you protect yourself even after an incident has begun.
Your consistent OpSec habits make it harder for bad actors to map staff, facilities, and operations. A short, regular review of the website, the front counter, and the team's online presence is often where the most valuable adjustments can be made.
The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.
Week E-24: Containment: Stop the Spread Before You Fix Anything
When responding to an incident, after analysis tells you what happened, the pressure becomes immediate: get the office back to normal. Phones are ringing, leadership wants reassurance, the public wants results. The instinct is to jump ahead to recovery.
Resist it. The first step in Phase 3 of the Incident Response Process is containment, and skipping it is how a one-day incident becomes a two-week one. Rushing to get your network back online before the incident is fully contained can allow the threat actor to continue wreaking havoc, such as encrypting all of the systems. You cannot fix what is still spreading.
The principle of containment can be applied to physical incidents as well, though they are usually so extreme – active shooter, suspicious substance in mail – that large steps are taken immediately. In this issue, we are focusing on cyber incidents, what you should know about containment, and the actions you can take as an election official. ... READ MORE HERE.
The Planning Desk is a running timeline of key election security tasks. You can find prior editions in thenewsletter archive.
Want to get daily updates on election news? Subscribe to electionline.