Connecting election experts, advancing security
Situation Room insights from the Election Security Exchange

Situation Room: Threats and the Personal Information Trail

The case file from an April conviction in an Ohio federal court demonstrates how the availability of personal information can disguise threat actors, help them find their targets, and amplify the fear they provoke.

Recently, an Ohio man pleaded guilty to sending 92 threatening communications targeting more than 30 Ohio public officials, including the Governor, Attorney General, Secretary of State, and several members of Congress.  

Through 2024 and 2025, he sent nearly 50 letters containing white powder he sometimes referred to as ricin. He mailed the letters to victims’ offices and homes, including seven different addresses for the Governor. In some, he included the names of spouses and often used return addresses for staffers, law firms and other individuals in the community. Last December, Ohio Secretary of State Frank LaRose and his family were forced to evacuate their home after receiving one of the letters containing a powder. Following that mailing, the Secretary received a series of threatening letters and emails from the same man. The perpetrator used a Swiss email service that allowed encryption and anonymity.  

As with the threats against Indiana lawmakers that we reported several issues ago, the use of home addresses and other personal information conveys a message that “we know where you live and how to get to your family,” which makes the experience all the more chilling for targets. Additionally, using information like return addresses of staffers can disguise a threat letter, leading a victim to open it, where a stereotypical threat with words and letters cut from a magazine, or even just an unknown return address, might prompt the target to set it aside for investigation. 

We return to this issue of threats and personal information because it’s one of the concerns election officials raise most often. Public servants increasingly face intimidation outside of the office. Swatting, bomb threats, and other tactics targeting individuals all share a common requirement: the attacker has to know where to find the target. That information is often pieced together from public records, social media posts, and other small details that, on their own, look unremarkable.

Both the Committee for Safe and Secure Elections’ (CSSE) Combatting Swatting Attempts and CISA’s Swatting Prevention and Response Guidance for Election Workers and Law Enforcement point to the same underlying issue: the more personal information about an election worker that is publicly accessible, the easier it becomes for a bad actor to combine those pieces into a targeting profile.

That aggregation effect is what makes day-to-day information practices matter: a staff directory on a website, an internal extension on an email signature, a social media post tagging a hotel during a conference, a name badge worn strolling outside. The practical implication is that reducing exposure is rarely a single decision. It is a set of small habits applied consistently.  

The disturbing attacks in Ohio and Indiana are another reminder that targeting tactics are not theoretical and that the personal information trail enables them. Election workers need to consistently practice operational security, or OpSec – the process of identifying and protecting sensitive information, data, and capabilities. Thoughtfulness about what personal information they are putting online, what is on the office website unnecessarily, and small adjustments to everyday habits will make themselves, their family, and their staff harder for a bad actor to map. 

For additional guidance on OpSec, review the resources highlighted in the Resource Library section of this newsletter.​​​​​​​


The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.