Security researchers document over 5,000 election-related domains and 17,000 exposed credentials tied to political organisations ahead of US midterm elections.
Summary
- Check Point identified 5,140 newly registered election-themed domains between April and May, potentially enabling phishing and impersonation attacks
- Over 17,000 exposed credentials discovered linked to political fundraising platforms, parties, and government services
- Voter information from multiple states appearing on criminal forums, including free distribution of Colorado election data
- AI capabilities are amplifying the speed, cost-effectiveness and scale of election-related fraud operations
The primary threat to upcoming US midterm elections may not be sophisticated nation-state attacks on voting infrastructure, but rather basic phishing and impersonation schemes that exploit the expanding election ecosystem. Check Point research reveals a concerning surge in potentially malicious election-related infrastructure and credential exposure.
Domain Registration Spike
Between April 13 and May 14, researchers documented approximately 1,140 newly registered domains containing “election” and 4,010 containing “vote.” This represents a significant increase from January figures of 1,300 and 2,957 respectively. While domain registration alone doesn’t guarantee malicious use, these domains commonly serve as infrastructure for phishing pages impersonating voter information sites, candidate websites, donation scams, and misinformation campaigns designed to mimic official election communications.
Widespread Credential Exposure
The security firm identified approximately 17,000 exposed credentials in May linked to political and government organisations. The exposure spans major fundraising platforms including 9,500 compromised ActBlue.com credentials, 6,500 from WinRed.com, plus hundreds from official party websites democrats.org and gop.com. An additional 150 credentials from the usa.gov citizen services site were also discovered.
“Election-related domains and leaked credentials represent two sides of the same problem: infrastructure and access,” explained Danielle Hess, cyber threat intelligence analyst at Check Point Software. The combination creates expanded opportunities for attackers to conduct convincing and scalable election-related operations.
Voter Data on Criminal Forums
Beyond organisational credential exposure, voter information is actively circulating on dark web forums. In January, BreachForums featured free distribution of Fremont County, Colorado election division data including names, email addresses, IP addresses, and portal submission information. More recently, criminal forum Spear.cx advertised a multi-state voter database covering over two dozen states and Washington DC.
Campaign-Level Risks
Individual campaign infrastructure showed minimal credential exposure across swing-state candidates from both parties, indicating current risks concentrate in centralised platforms rather than campaign-specific systems. One notable exception involved approximately 90 leaked credentials associated with Rep. Tom Kean Jr.’s campaign, though these appeared in infostealer malware logs suggesting opportunistic rather than targeted compromise.
The threat landscape is further complicated by AI capabilities that accelerate and reduce costs for phishing, impersonation, and misinformation operations. This technological amplification makes election-related fraud more accessible and scalable for threat actors with varying skill levels.
Why it matters
Election infrastructure presents an expanded attack surface combining high-value targets, emotional manipulation opportunities, and fragmented security oversight. The concentration of credential exposure in centralised political platforms creates single points of failure that could enable broad compromise of election-related communications and fundraising operations.
What to do now
- Monitor for phishing attempts targeting election-related credentials and implement additional authentication controls for political organisation accounts
- Review domain registration patterns for potential impersonation of your organisation’s election-related communications
- Assess credential exposure across political and government service platforms your organisation may use
