In September 2024, the Department of Justice indicted three Iranian nationals, members of the Islamic Revolutionary Guard Corps, for running a targeted phishing operation against people connected to the U.S. presidential campaigns. They set up fake websites with fake login pages and then created “fraudulent email accounts in the names of prominent U.S. persons and international institutions.” From these accounts, they sent emails directing campaign staff back to those fake pages to gain unauthorized access to staffers’ accounts.
At least one staffer was fooled by this phishing scheme and entered real user credentials into a fake login page. The actors used that information to steal confidential campaign documents, which they then tried to leak to the media and to another U.S. presidential campaign.
In January 2026, Google Threat Intelligence documented a wave of phishing-style attacks delivered by phone, called vishing (voice-phishing). The malicious actors called employees at several corporate offices, posing as IT support. They directed staff to visit fraudulent websites designed to resemble their companies’ login pages and instructed them to enter their credentials. The attackers used those stolen credentials to harvest sensitive corporate data and internal communications, and to bulk-export customer records, then used the stolen data to extort companies and individuals.
And late last year, Google accused a criminal network based in China of a different spin on phishing, using normal text message channels to deliver fake web addresses. Because text messages travel over “Short Message Services”, or SMS, these attacks are called smishing.
Since early 2024, the FBI has logged tens of thousands of complaints about fake toll and delivery texts that malicious actors used to compromise credit cards (“you owe a small unpaid fee, click here”). In October 2024, the Bureau warned that scammers were using election themes, candidate names, and logos to phish for personal information and donations by text. A text feels casual and personal, which is exactly why people tap the link.
What It Means For Your Office
Phishing, vishing, and smishing are the same trick. Someone pretends to be a person or an office you trust, sprinkles in a sense of urgency, and asks you to click, maybe call or text back, share a password, or provide payment. All three work against jurisdictions large and small.
- A single clicked link in an official’s email can hand an attacker the keys to a vendor portal, a payroll system, or confidential details.
- A caller posing as IT support or a state official checking on a system asks an employee or poll worker to confirm a login or read back a security code.
- A text purporting to be from the website service provider tells an employee to log in again through a specific link for mobile access to the office website or email.
The defense is the same for all three attack types:
- Slow down. Manufactured urgency is the tell. Take9 says it pretty plainly: Pause nine seconds before you act on a message that wants you to move fast.
- Verify through trusted channels. Hang up and call the office back on its published number. Do not use the link, phone number, or callback in the message itself.
- Never give a password, code, or payment just because someone contacted you first.
- Report it. Send suspicious election-related messages to your state or local election office and to the FBI’s Internet Crime Complaint Center at ic3.gov.
Practice With Your Team
Your staff and poll workers can practice spotting phishing, vishing, and smishing for free. The Exchange offers no-cost election security training, including phishing awareness, at election-security-training.securingelections.org. Do the basics, and do them well. Most attackers will move on to an easier target.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.
