Connecting election experts, advancing security
Newsletter insights from the Election Security Exchange

Newsletter: Issue 34

Published: September 30, 2026

In this issue:

  • Situation Room: A Russian influence campaign is spoofing well-known celebrities in an attempt to sway voters ahead of the midterms.
  • Resource Library: Explore a menu of resources to help combat spoofing in all of its forms.
  • Planning Desk, E-5: As we enter the final month before the election, quickly strengthen your pre-election cyber defenses this week with six easy steps.
  • New Exchange Webinar October 14 at 3:00 PM ET! Register here to join us for the Exchange-hosted webinar: Secure Your People, Secure Yourself: Getting Yourself and Your Staff Ready to Face Any Situation on Election Day and Beyond.

Situation Room

Spoofed Celebrity Videos Target the Midterms

Earlier this month on September 11, several media outlets reported that a Russian influence operation known as Matryoshka (Operation Overload) was posting doctored videos aimed at influencing voters ahead of the midterms. In the clips, actors such as Julia Roberts and Sarah Jessica Parker appear to denounce the Democratic Party. The visual footage is real, pulled from old ads and Cameo videos; the voices are AI clones; and a CNN logo sits in the corner without the network’s permission. Fortunately, engagement was small, and Bluesky has since banned the accounts.

The Institute for Strategic Dialogue (ISD) studied the same operation during Germany’s regional elections this summer. It found 269 posts on X, Bluesky, and TikTok, with the branding of 31 news outlets spoofed, and roughly 40% of the videos using AI voiceovers. Engagement typically spiked within an hour of posting, with little sign of further discussion. These operations spread only when real users share the clips or when coverage repeats the claims.

What is Spoofing?

Spoofing means faking a message so it looks like it came from someone you trust, using a borrowed logo, voice, phone number, or badge. Election officials face all the following common forms—each designed to pressure staff into reacting quickly:

  • Deepfakes and Branding as Reputable Organizations: Use of real footage, altered videos, and a trusted logo, such as in the Matryoshka clips.
  • Cloned Voices: Recordings of public meetings and media interviews can give an impostor audio to mimic. The FBI has tracked AI voice/text impersonation of officials since 2023.
  • Faked Caller ID: The number on your phone screen can be forged; FBI Boston warned of this in August.
  • Look-alike Websites and Email: Web addresses might be one letter off or use a different domain extension (e.g., .com, .org, etc.), built to look like your office’s website. A spoofed email can put a name you know in the “From” line.
  • Impostor Social Media Accounts: Accounts use your office’s or another trusted office’s name and seal.
  • Fake Credentials: Someone posing as law enforcement, federal agents or staff, state staff, or vendors. Badges, seals, and letterhead can be forged.

Verify Before You Act

The defense for all of these is the same: confirm the request through an alternate, trusted channel before doing anything else. Staff and poll workers should be trained on these indicators and verification procedures so they can recognize spoofing.

  • Treat urgency and secrecy as red flags. Whether by email, phone, or face-to-face, the spoofer will likely try to get you to act or respond immediately or ask you to keep the conversation secret. When this happens, pause for 9 seconds and contact them through another method, such as calling the person back on a known number. 
  • Check the badge, then check the office. Ask for ID, which office the person works for, and their supervisor’s information. Never trust the number or email the person provides; instead, call that office using a number you found yourself. CISA and the FBI have issued alerts, warning the public of scams impersonating government officials.
  • Ask for the request in writing. Anyone seeking access to equipment, voter data, or secure areas should make a formal request. For law enforcement, the Brennan Center for Justice points to warrants, grand jury subpoenas, and federal demand letters as examples. Consult your jurisdiction’s attorney before granting access.
  • Train your staff now on verification and reporting steps, so they aren’t improvising under pressure. Inform your election workers on acceptable credentials and who to call if something seems out of the ordinary. 

Make Your Office Easy to Find

When a fake clip about your jurisdiction turns up, people will look for your official channels. Consider these four steps to help them find you quickly:

  1. Move your website and email to a .gov domain (free through CISA’s get.gov).
  2. Verify your official social media accounts and list them on your website.
  3. Tell voters now where official election information lives.
  4. Prepare a short holding statement (e.g., “That video did not come from us.”) so it is ready when needed.

The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.

Resource Library

Resource Menu for Combating Spoofing

The spoofed celebrity videos highlighted in this issue’s Situation Room remind us how easily trusted voices, logos, and news brands can be faked to mislead voters and pressure election staff into acting fast. Spoofing tactics are designed to slip past your defenses in moments of urgency.

The upside: you have strong tools at your disposal. These resources can help you, your staff, and your poll workers stay alert and ready.

The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.

Planning Desk

Week E-5: Covering Your Cyber Bases with High-Impact Steps for the Final Stretch

We are 34 days out from Election Day, and you are making your lists and checking them twice. You are not alone—election officials nationwide are counting down, working to ensure that everything goes smoothly. Now is not the time to get complacent.

At the Exchange, we’ve walked in your shoes. We are flagging the things that separate a resilient, storm-ready operation from the kind that ends up in the papers on Wednesday.

Here are six security best practices you can still do between now and November that truly move the needle:

  1. Refresh and strengthen passwords (yes, again).
    1. Why now: Credential theft spikes in the final weeks before elections. A fresh round of password updates (especially for admin accounts, email, voter‑registration systems, and pollbook management portals) closes the door on old or compromised credentials.
    2. To-dos: Require staff to update passwords this week. Enforce length (14-16 characters) over complexity. Eliminate shared passwords. Confirm MFA is turned on wherever possible.
  2. Run updates on devices that touch election work.
    1. Why now: Patching is still one of the most effective defenses against ransomware and remote exploitation. It’s absolutely doable in the final month.
    2. To-dos: Update laptops, office desktops, tablets, browsers, VPN clients, and antivirus tools. Restart devices after updates. Validate that automatic updates are enabled on systems where it makes sense (probably not on e-pollbook systems; follow state/vendor guidance there).
  3. Re-check access: Who still has accounts, keys to buildings, or permissions?
    1. Why now: Dormant accounts and outdated permissions are a gift to attackers. A quick access audit is one of the easiest pre‑election cleanups.
    2. To-dos: Disable accounts for former staff, temps, or vendors. Remove admin privileges from anyone who doesn’t need them. Confirm who has access to voter‑registration systems, ENR, and shared drives. Review physical keys and badge access as well as any accounts that have not been used for six months or more to determine if they still need to be active.
  4. Have staff take a 10-minute phishing refresher.
    1. Why now: Phishing attempts increase sharply as Election Day approaches, and not just by email. Text messages and phone calls are also two likely ways someone may try to get you to click on a link or share sensitive information. A short refresher keeps staff alert without requiring a full training cycle.
    2. To-dos: Use our 10-minute phishing assessment. Remind staff to report suspicious messages and Take9 seconds to think before they click. See our issue 25 to inform staff of the ways you may be phished, smished, and vished.
  5. Validate backups and incident-response basics.
    1. Why now: If something goes wrong in the final stretch (ransomware, website outage, device failure), the office needs confidence that recovery is possible.
    2. To-dos: Confirm backups exist, are recent, and can be restored. Print or save offline copies of critical procedures and data. Ensure staff know who to call and what to do if something looks wrong. Verify the people in your cyber incident response plan are who you would contact if an incident occurs. Confirm that each email and phone number is current and accurate, and test them. Make sure these partners know you will call them if a cyber issue arises.
  6. Review your technology baseline.
    1. Why now: Knowing what normal operations look like helps you identify when something abnormal is happening.
    2. To-dos: Reach out to your IT support partners to ask whether they have seen or heard about any concerning threats or trends, and what they are doing about it. Unusual spikes in website traffic? New AI-powered exploits in the news? Suspicious emails being reported? How have your critical systems been performing over the last 30 days? Ask them if they need anything to help support your office.

These activities can be completed without introducing any last-minute additions or changes. They can also help you sleep easier. Take a breath, stop for a beat, and consider what you can do in the time we have left before the big day.

The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.

Election Security News

Want to get daily updates on election news? Subscribe to electionline.

Get the Exchange in your inbox →

Join the List