Newsletter: Issue 34
Published: September 30, 2026
In this issue:
- Situation Room: A Russian influence campaign is spoofing well-known celebrities in an attempt to sway voters ahead of the midterms.
- Resource Library: Explore a menu of resources to help combat spoofing in all of its forms.
- Planning Desk, E-5: As we enter the final month before the election, quickly strengthen your pre-election cyber defenses this week with six easy steps.
- New Exchange Webinar October 14 at 3:00 PM ET! Register here to join us for the Exchange-hosted webinar: Secure Your People, Secure Yourself: Getting Yourself and Your Staff Ready to Face Any Situation on Election Day and Beyond.
Situation Room
Spoofed Celebrity Videos Target the Midterms
Earlier this month on September 11, several media outlets reported that a Russian influence operation known as Matryoshka (Operation Overload) was posting doctored videos aimed at influencing voters ahead of the midterms. In the clips, actors such as Julia Roberts and Sarah Jessica Parker appear to denounce the Democratic Party. The visual footage is real, pulled from old ads and Cameo videos; the voices are AI clones; and a CNN logo sits in the corner without the network’s permission. Fortunately, engagement was small, and Bluesky has since banned the accounts.
The Institute for Strategic Dialogue (ISD) studied the same operation during Germany’s regional elections this summer. It found 269 posts on X, Bluesky, and TikTok, with the branding of 31 news outlets spoofed, and roughly 40% of the videos using AI voiceovers. Engagement typically spiked within an hour of posting, with little sign of further discussion. These operations spread only when real users share the clips or when coverage repeats the claims.
What is Spoofing?
Spoofing means faking a message so it looks like it came from someone you trust, using a borrowed logo, voice, phone number, or badge. Election officials face all the following common forms—each designed to pressure staff into reacting quickly:
- Deepfakes and Branding as Reputable Organizations: Use of real footage, altered videos, and a trusted logo, such as in the Matryoshka clips.
- Cloned Voices: Recordings of public meetings and media interviews can give an impostor audio to mimic. The FBI has tracked AI voice/text impersonation of officials since 2023.
- Faked Caller ID: The number on your phone screen can be forged; FBI Boston warned of this in August.
- Look-alike Websites and Email: Web addresses might be one letter off or use a different domain extension (e.g., .com, .org, etc.), built to look like your office’s website. A spoofed email can put a name you know in the “From” line.
- Impostor Social Media Accounts: Accounts use your office’s or another trusted office’s name and seal.
- Fake Credentials: Someone posing as law enforcement, federal agents or staff, state staff, or vendors. Badges, seals, and letterhead can be forged.
Verify Before You Act
The defense for all of these is the same: confirm the request through an alternate, trusted channel before doing anything else. Staff and poll workers should be trained on these indicators and verification procedures so they can recognize spoofing.
- Treat urgency and secrecy as red flags. Whether by email, phone, or face-to-face, the spoofer will likely try to get you to act or respond immediately or ask you to keep the conversation secret. When this happens, pause for 9 seconds and contact them through another method, such as calling the person back on a known number.
- Check the badge, then check the office. Ask for ID, which office the person works for, and their supervisor’s information. Never trust the number or email the person provides; instead, call that office using a number you found yourself. CISA and the FBI have issued alerts, warning the public of scams impersonating government officials.
- Ask for the request in writing. Anyone seeking access to equipment, voter data, or secure areas should make a formal request. For law enforcement, the Brennan Center for Justice points to warrants, grand jury subpoenas, and federal demand letters as examples. Consult your jurisdiction’s attorney before granting access.
- Train your staff now on verification and reporting steps, so they aren’t improvising under pressure. Inform your election workers on acceptable credentials and who to call if something seems out of the ordinary.
Make Your Office Easy to Find
When a fake clip about your jurisdiction turns up, people will look for your official channels. Consider these four steps to help them find you quickly:
- Move your website and email to a .gov domain (free through CISA’s get.gov).
- Verify your official social media accounts and list them on your website.
- Tell voters now where official election information lives.
- Prepare a short holding statement (e.g., “That video did not come from us.”) so it is ready when needed.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.
Resource Library
Resource Menu for Combating Spoofing
The spoofed celebrity videos highlighted in this issue’s Situation Room remind us how easily trusted voices, logos, and news brands can be faked to mislead voters and pressure election staff into acting fast. Spoofing tactics are designed to slip past your defenses in moments of urgency.
The upside: you have strong tools at your disposal. These resources can help you, your staff, and your poll workers stay alert and ready.
- Exchange Advisory Vigilance Against Social Engineering and Impersonation: Offers verification steps, guidance on transitioning to .gov domains, and practical tips to counter impersonation attempts.
- Exchange Newsletter Issue 24
- Situation Room: AI as a Social Media Threat Multiplier: Outlines proactive measures to reduce the risks of AI-driven content shaping public perception or undermining trust.
- Resource Library: Can You Trust What You’re Seeing? Tools for Your AI Toolbelt: Helps election officials quickly assess whether online content is authentic and decide whether to monitor, escalate, or respond publicly.
- Don’t Fall for the AI Fake: A lightweight, interactive 10-question quiz that builds resilient operational habits against deepfakes, voice cloning, and social engineering.
- Take9 Seconds for a Safer World: A simple habit: pause for nine seconds before clicking, downloading, or sharing to stay ahead of increasingly sophisticated scams.
- Phishing Assessment Resources: A curated list of free and paid phishing-assessment tools, with vendor contacts, approximate costs, and implementation effort.
- Phishing Threats: Essentials for Safeguarding Election Infrastructure: Explains why election officials are frequent targets and highlights common tactics across email, text, phone, and QR codes – plus mitigation steps.
- First Things First: Website Security Fast Wins for Election Offices: Free-to-low-cost actions that strengthen website security this election cycle.
- Training Opportunities: The Exchange offers several course topics, including AI Mitigations in Elections, Doxxing and Swatting, and The Trusted Line: Communication as a Security Strategy. Request a training here.
The Resource Library section of the newsletter spotlights election security resources. All highlighted resources are available online in the Resource Library.
Planning Desk
Week E-5: Covering Your Cyber Bases with High-Impact Steps for the Final Stretch
We are 34 days out from Election Day, and you are making your lists and checking them twice. You are not alone—election officials nationwide are counting down, working to ensure that everything goes smoothly. Now is not the time to get complacent.
At the Exchange, we’ve walked in your shoes. We are flagging the things that separate a resilient, storm-ready operation from the kind that ends up in the papers on Wednesday.
Here are six security best practices you can still do between now and November that truly move the needle:
- Refresh and strengthen passwords (yes, again).
- Why now: Credential theft spikes in the final weeks before elections. A fresh round of password updates (especially for admin accounts, email, voter‑registration systems, and pollbook management portals) closes the door on old or compromised credentials.
- To-dos: Require staff to update passwords this week. Enforce length (14-16 characters) over complexity. Eliminate shared passwords. Confirm MFA is turned on wherever possible.
- Run updates on devices that touch election work.
- Why now: Patching is still one of the most effective defenses against ransomware and remote exploitation. It’s absolutely doable in the final month.
- To-dos: Update laptops, office desktops, tablets, browsers, VPN clients, and antivirus tools. Restart devices after updates. Validate that automatic updates are enabled on systems where it makes sense (probably not on e-pollbook systems; follow state/vendor guidance there).
- Re-check access: Who still has accounts, keys to buildings, or permissions?
- Why now: Dormant accounts and outdated permissions are a gift to attackers. A quick access audit is one of the easiest pre‑election cleanups.
- To-dos: Disable accounts for former staff, temps, or vendors. Remove admin privileges from anyone who doesn’t need them. Confirm who has access to voter‑registration systems, ENR, and shared drives. Review physical keys and badge access as well as any accounts that have not been used for six months or more to determine if they still need to be active.
- Have staff take a 10-minute phishing refresher.
- Why now: Phishing attempts increase sharply as Election Day approaches, and not just by email. Text messages and phone calls are also two likely ways someone may try to get you to click on a link or share sensitive information. A short refresher keeps staff alert without requiring a full training cycle.
- To-dos: Use our 10-minute phishing assessment. Remind staff to report suspicious messages and Take9 seconds to think before they click. See our issue 25 to inform staff of the ways you may be phished, smished, and vished.
- Validate backups and incident-response basics.
- Why now: If something goes wrong in the final stretch (ransomware, website outage, device failure), the office needs confidence that recovery is possible.
- To-dos: Confirm backups exist, are recent, and can be restored. Print or save offline copies of critical procedures and data. Ensure staff know who to call and what to do if something looks wrong. Verify the people in your cyber incident response plan are who you would contact if an incident occurs. Confirm that each email and phone number is current and accurate, and test them. Make sure these partners know you will call them if a cyber issue arises.
- Review your technology baseline.
- Why now: Knowing what normal operations look like helps you identify when something abnormal is happening.
- To-dos: Reach out to your IT support partners to ask whether they have seen or heard about any concerning threats or trends, and what they are doing about it. Unusual spikes in website traffic? New AI-powered exploits in the news? Suspicious emails being reported? How have your critical systems been performing over the last 30 days? Ask them if they need anything to help support your office.
These activities can be completed without introducing any last-minute additions or changes. They can also help you sleep easier. Take a breath, stop for a beat, and consider what you can do in the time we have left before the big day.
The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.
Election Security News
- No evidence of successful foreign meddling in 2024 election, spy agencies found | The Record (September 23, 2026) // International
- Fact Check Team: How AI agents can run foreign influence campaigns across social media | KTUL News (September 21, 2026) // National
- Election officials are showing what AI adoption looks like when accountability comes first | Federal News Network (September 25, 2026) // National
- Arizona Supreme Court says hackers stole residents’ personal data | The Record (September 29, 2026) // Arizona
- Entire Searcy County Election Commission resigns over voter database concerns | KTLO News (September 23, 2026) // Arkansas
- Iowa Poll Worker Charged With Election Misconduct Attends Pre-Trial Hearing | KCAU News (September 28, 2026) // Iowa
- Sample Ballots with printing errors were mailed to Montgomery County voters | 7News (September 23, 2026) // Maryland
Want to get daily updates on election news? Subscribe to electionline.
