❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Election official says Tina Peters would be consultant, won’t have access to election systems

By: djohnson
26 August 2026 at 09:30

The top election official for Shasta County, Calif. said he has offered convicted felon and former Mesa County, Colo. clerk Tina Peters a position as a consultant to help with the 2026 elections, but that she hasn’t accepted the position yet.  

Earlier this month, Shasta County registrar Clint Curtis told local news outlets that he intended to hire Peters as assistant registrar of voters to help with the upcoming 2026 elections, months after she was released from prison in Colorado.

In an interview with CyberScoop this week, Curtis said he was looking to hire Peters as a consultant, citing the length of time involved in hiring her as a full-time employee and the need for immediate help running the upcoming midterm elections.

Curtis said that he initially believed Peters had accepted the position, only to later hear from her that she needed to consult her legal team after her prison sentence was commuted in June.

“She’s got to check it all out, make sure it’s okay, make sure there’s not any roadblocks in there that we don’t know about [or are] illegal, so you got to walk through the whole mess,” said Curtis.

A Colorado Department of Corrections official told CyberScoop that as part of her parole conditions, Peters must be employed and live in Colorado. Peters can request a transfer to another state, but she must first receive permission from both states and go through a formal review process.

According to Curtis, hiring Peters as a consultant means she would not have local access to county email or election systems. Peters’ past conviction “doesn’t matter” because her access to county IT would be limited.

“If she’s on staff she’d have logins to the network, logins in the system, she’d basically have full access,” Curtis said in a phone interview. “But consultants don’t have any of that, nor should they, right?”

Consultants “are basically there to actually watch other people do it and make sure they do it right rather than do it themselves,” he added.

At the same time, when asked what responsibilities Peters would have, Curtis described an expansive role, with Peters helping him oversee the registrar’s office and direct his full-time staff of about 12.

Asked what drew him to Peters, Curtis said “well, she’s out [of prison] and I have this position become available [and] I need somebody that can actually supervise and knows something about elections.”

In 2024, Peters was convicted of seven felony crimes related to the theft of voting machine software from Mesa County election facilities, in a failed attempt to prove that the machines had been involved in election fraud during the 2020 election.

She served less than two years of that sentence, as legal appeals, relentless pressure from the Trump administration and eventually a commutation by Colorado Governor Jared Polis saw her released from prison in June.

Curtis said he did not reach out to any Mesa County officials before offering Peters the job, but did cite conversations with her that impressed him and his confidence that he would remain in control of the county’s elections.

“I talked to her and basically, she’s very even tempered, she’s not wild and crazy which is good,” said Curtis. “And so basically I’d still be in charge so it wouldn’t really be a problem…there’s no way she would get out of bounds on me.”

A request to Mesa County’s press office seeking comment was not returned. At Peters’ sentencing hearing in 2024, multiple Mesa County officials testified about the negative impact her crimes and behavior had on the county’s elections, finances and reputation.

When reached for comment, a representative for Peter Ticktin, Peters’ lawyer, provided CyberScoop with a statement from last week regarding Peters’ intentions.

“Tina Peters is giving consideration to helping in the efforts in Shasta County as there most definitely has been monkey business in the way the election was handled,” Ticktin said. “Tina is one of the key voices leading the effort to get the invasive machines out of our election process.”

Earlier this month, Curtis was censured by the Shasta County Board of Supervisors following investigations into  allegations of verbal abuse and threatening language to staff.

Curtis, who was appointed county registrar in 2025, also made a number of claims about what he called suspicious mail-in ballots used during the 2024 election. He claimed the ballots were different sizes and looked, felt and “smelled” different from normal mail-in ballots.

Curtis told CyberScoop he did not follow up with the county’s ballot manufacturer to ask if there was a credible explanation, saying he lacked investigative authority to do so. He also could not answer how many instances of voter fraud his office had confirmed. 

A day after speaking with CyberScoop, the Shasta County Board of Supervisors said Curtis’ claims were “frivolous” and that they “welcomed” investigations by state and federal authorities.

“Mr. Curtis was hired to enhance transparency, strengthen election integrity and restore trust. While some progress has been achieved, including the promotion of meaningful observation within the Elections Office, Mr. Curtis has failed significantly in other core responsibilities, undermining the very principles he was appointed to uphold.”

The press office for California Secretary of State Shirley Weber’s told CyberScoop that irrespective of whom a county employs or contracts with, they must comply with California law, security and confidentiality requirements, and “maintain the integrity of our state’s elections and election processes.”  

Weber also sharply questioned Peters’ involvement in California elections.

“As Secretary Weber has stated, ‘The mere thought of letting someone near any part of California’s elections when that person was convicted of serious election-related crimes while serving as an election official, is simply outrageous,’” Weber’s office wrote in an email. “Our office is monitoring the situation and, as always, will act within our authority and work closely with law enforcement officials to ensure that all elections in our state remain transparent, safe, and fair for all eligible voters.”

Curtis expressed frustration to CyberScoop at the delays, saying he needed immediate help and expressing concern that Peters’ legal roadblocks may make it harder to hire her at all.

“You know, if they stall sufficiently enough, then she won’t be able to get any help to me,” said Curtis. “So I need her fairly quickly. We start early voting in…30 days, something like that. So we need it quickly, we need to get her in here, tell her what to do, set people up and get it ready to go. Otherwise, I have to do it all, and that’s going to be a pain.”

The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

By: djohnson
22 August 2026 at 13:01

In a late Friday night posting to the Federal Register, the U.S. Postal Service said it is finalizing new regulations that would give the federal government potentially vast powers to control mail-in ballots for voters.

The changes are part of an executive order signed by President Donald Trump in March, which directed USPS to develop lists of residents “eligible” for mail-in voting — standards that would be defined by the federal government.

The U.S. Constitution vests states and Congress with the power to regulate elections, and the USPS rules have already been struck down by multiple lower courts. But as the White House appeals to the Supreme Court to reverse those decisions, it is still moving ahead in finalizing the regulations, though USPS says it will not move to implement them until after the Supreme Court rules.

But USPS said it must begin moving forward now in order to ensure the changes are in place by the mid-term elections.

“To ensure the faithful execution of federal law in connection with federal elections, this rule has an immediate effective date,” USPS wrote. “Delaying the effective date would jeopardize implementation of this rule in time for the 2026 general election, which will be held on November 3, 2026.”

According to the notice, USPS has received an astonishing 200,000 comments from the public in response to the proposed rule. It doesn’t provide a breakdown of how many comments were in support or opposition.

By the agency’s own admission, the vast majority of supportive comments appear to argue that the rules would help with the perception among voters that fraud is a “significant problem.”  Phrases like “strengthens confidence” and “reduce uncertainty” are peppered throughout the descriptions.

But no credible evidence of coordinated mail-in voter fraud is presented, and Trump and his allies have been the primary force in American politics spreading the perception that voter fraud by noncitizens, dead people and Democrats is rampant. Courts, post-election audits and independent experts have repeatedly debunked these arguments.

“Whether or not voter fraud is common or uncommon, the Postal Service has the legal authority to take the measures in this rule to facilitate enforcement of federal law, reduce the risk of fraud, and help protect the integrity of federal elections,” the notice stated.

According to the notice, the comments in opposition pointed out that two courts have already blocked the White House’s USPS rules, finding them unconstitutional. Others expressed concerns that the Postal Service “would refuse to accept certain ballots for federal elections that states tender without satisfying the data-entry obligations that the rule would impose,” echoing concerns that election experts have conveyed to CyberScoop in interviews.

The notice also dismisses comments “influenced by partisan political speculation,” that include “conjecture about the underlying intent” of the order, its impact on voter turnout and elections.

“Such remarks are speculative and exceed the scope of this proceeding,” USPS wrote in its notice. “In any event … this rule does not—nor is it intended to—facilitate any form of voter suppression, affect election outcomes, or target particular demographics, districts, or states.”

Last week the U.S. District Court of Massachusetts, which ruled against the administration’s USPS order in an ongoing lawsuit brought by states and voter groups, took the unusual step of issuing a second, separate injunction against the USPS rules. It’s not clear whether the Supreme Court will address both injunctions in the same ruling or separately ahead of election day in November.

“The court has already answered and will again resolve the question clearly and affirmatively,” Judge Indira Talwani wrote when issuing the second injunction. “The executive branch has no authority to regulate elections.”

Some voting groups quickly moved to condemn the Friday night posting, saying it will confuse voters about a state-led voting process that is, as of today, still the law of the land.

“For the 2026 election, voters can continue to rely on the voting rules established by their state unless and until a court orders otherwise,” said Michael McNulty, senior policy director at the nonprofit Issue One. “Yet, because the Trump administration continues its attempts to undermine trust in an effort to centralize control of elections, we all must remain vigilant and continue to build trust in our election system.”

The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

AI and the Hugging Face breach

31 July 2026 at 04:00
If you missed it the other day, SANS has a recording of its recent live-panel discussion of the OpenAI/Hugging Face breach. It points to nine questions to ask your security teams. But what about us as users of all of these systems where we don’t have a lot of control? For me, it gets back […]

What the World Cup can teach us about cybersecurity resilience

By: Greg Otto
21 July 2026 at 06:00

With the World Cup now complete, its biggest cybersecurity story may be what didn’t happen. While no major public cyber disruption has been reported, that shouldn’t be mistaken for a lack of risk. 

In the run-up to the tournament, the FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement warning organizations and fans about fraudulent, spoofed websites impersonating the FIFA event – a reminder that the absence of a headline-grabbing breach doesn’t mean bad actors weren’t trying. In many ways, it’s evidence of the planning, coordination, and resilience required to keep an event of this scale running securely.

A global event like the World Cup depends on far more than what happens inside the stadium. It relies on local governments, venues, transportation systems, telecom providers, payment platforms, hotels, vendors, public safety agencies, and law enforcement, all working together. 

When I worked at the FBI, I saw how fast major events test teamwork across agencies, regions, and businesses. The World Cup offered that test at a scale few events can match.

Successful resilience is built months before kickoff

Successful major-event security depends on what happens long before there is a visible incident: trusted relationships, clear roles, shared intelligence and response plans. Planning becomes even more important when an event is not limited to a single city or venue.

In the past, event security consisted of guards, gates, and stadium perimeters. Those still matter, but they’re only part of the picture. Today, an event this big that brings millions of people together depends on many systems working in concert. No single organization owns the full risk picture, which means resilience depends on how well these groups can share information, coordinate response plans, and keep essential services operating under pressure. This means security can’t be planned around one perimeter. The real perimeter is the full event ecosystem.

Resilience starts much earlier, with planning across organizations that may not normally operate as one team. The real test for major events is whether public- and private-sector partners know their roles before pressure hits. That includes who shares information, who validates threats, who communicates with the public, who has decision-making authority and how quickly partners can act if a system slows down or becomes unavailable.

Major events are only as resilient as the systems behind them

Attackers don’t need to compromise the most visible organization to create disruption. They can look for weaker points across the event ecosystem. A disruption may begin with a vendor, ticketing platform, transportation partner, payment provider, hotel, contractor or communications provider, but the impact can quickly become broader than any one organization.

Sports organizations now operate like large businesses, with ticketing systems, VIP data, sponsors, vendors, media partners, stadium operations, payment systems, and fan engagement platforms. They depend on networks of suppliers and partners, and that creates multiple possible entry points.

Operational technology (OT) deserves more attention than it typically gets in these conversations. A ransomware attack that disrupted stadium operations directly, rather than a ticketing site or a fan-facing app, would be one of the most damaging scenarios organizers could face. OT security has to sit alongside the more visible concerns like payment fraud and spoofed domains, not behind them.

Bad actors don’t let a good crisis go to waste. Fans are often an easy target. Excitement drives a fan to buy a last-minute ticket or check a score on an unknown site. That excitement is exactly what fraudsters count on.

This risk grows over time. As the event gets closer and attracts more eyes, it becomes a richer target. A fake FIFA ticket site is useless to a crook a month after the last game. Groups running these systems must act faster as opening day nears, and share threat intelligence without delay.

Threat intelligence turns planning into proactive defense

The World Cup may be over, but the work isn’t. Cities, governments, and private-sector organizations will continue supporting large-scale public events that depend on complex digital and physical ecosystems. The question isn’t whether another major event will face cyber threats, it’s whether the planning starts early enough.

Organizations involved in future major events should focus on resilience, not just prevention. That means planning for what happens if a critical system slows down, goes offline, or becomes unreliable, and ensuring partners know how to coordinate before an incident occurs.

Every major event forces defenders to prepare for known risks. The harder challenge is anticipating the ones that haven’t emerged yet.

The next major disruption may not come from the attack that organizations spent months preparing for. It could target a new dependency, exploit emerging technology, or capitalize on a moment when public attention is at its highest. That’s why resilience can’t be built around yesterday’s playbook. It has to be informed by continuous threat intelligence, regular coordination across public- and private-sector partners, and the flexibility to adapt as the threat landscape changes.

The World Cup demonstrated what’s possible when that preparation comes together. As cities, governments, and private organizations look ahead to future global events, success won’t be measured solely by the attacks they stop. It will be measured by how effectively they can maintain critical operations, share information, and adapt under pressure when the unexpected happens.

The post What the World Cup can teach us about cybersecurity resilience appeared first on CyberScoop.

State officials, election experts pan Trump speech: ‘This is what desperation looks like’

By: djohnson
17 July 2026 at 11:37

State and local officials and election security experts largely panned a Thursday night primetime speech by President Donald Trump, saying it was reflective of White House “desperation” to find any credible evidence to support their claims that U.S. elections have been rigged against the two-term president.

While the White House teased explosive new claims about the potential compromise of U.S. elections by China, Trump’s speech was a rehash of claims that both have no supporting evidence and have been repeatedly debunked when investigated. 

David Becker, executive director of the Center for Election Innovation and Research and a former voting and civil rights attorney at the Department of Justice, said none of Trump’s claims or allegations were new or substantively different from previous theories he’s been espousing over the past six years.

“The White House promised a bombshell and they delivered a dud,” Becker said on a call with reporters Friday. “There was nothing that even calls into question past elections — certainly not the 2020 election.”

The administration declassified a huge tranche of documents from the intelligence agencies, and news outlets continue to sift through them, but thus far nothing has been found that remotely validates the administration’s claims about foreign interference from China costing Trump the 2020 election.

In fact, some of the most relevant documents found at this point have supported the opposite conclusion, with agencies assessing that while China engaged in influence campaigns around the election, it was not attempting to outright interfere with U.S. election infrastructure, hack voting machines or manipulate ballots.

John Solomon, a former journalist and opinion writer at The Hill brought in by the White House to lead the investigation, also told reporters Thursday that his search hasn’t turned up evidence that the 2020, 2022 or 2024 elections were affected by fraud.

The one new major claim by Trump — that the Department of Homeland Security determined hundreds of thousands of noncitizens were registered to vote across four states — is almost certainly false or overinflated, given that it contradicts post-election state audits that have routinely found single or double-digit numbers of noncitizens registered to vote within a single state across multiple elections.

Over the past six years, similar claims by GOP secretaries of state and political activists purporting to find mass numbers of noncitizens registered to vote have turned out to be grossly inflated due to shoddy data analysis, and the vast majority of cases involving “suspected noncitizens” turn out to be U.S. citizens who are legally registered to vote.

The White House has provided little to no information on the methodology used to flag and identify supposed noncitizen voters, other than alluding to the use of “commercial data” and federal databases. A federal court recently ordered DHS to dismantle the SAVE database, its primary database for verifying the citizenship status of U.S. voters, because it was unreliable and violated longstanding privacy laws. 

 Apart from DHS admitting its own data on citizenship is incomplete, Becker said using a list that relies on matching voter files with commercial data is not a reliable way of determining citizenship.

“It is impossible to take a public voter file with very little information that is uniquely identified, like a driver’s license number, and compare it to a commercial database and say for sure the Maria Rodriguez or the John Lee or the Shawn O’Hara you have on that is the same person,” he said.

Election officials also responded forcefully. Nevada Democratic Secretary of State Francisco Aguilar said that Trump has spent a decade attempting to manufacture a crisis around voter fraud and the president’s speech Thursday night was an extension of that effort. 

“As Nevada’s chief elections officer, it’s my job to call balls and strikes — so when the President lies, I am obligated to call him out,” Aguilar said in a statement. “The facts have not changed: Nevada’s elections are among the safest, most secure and accessible in the nation.”

It’s not just Democrats that have objected to the administration’s efforts. GOP states have gone to court to block the Department of Justice from obtaining their voter data, and Idaho’s Republican secretary of state responded to a DOJ letter threatening prosecution of election officials as “not well met” and potentially illegal under state ethics laws. 

Trump’s speech potentially casts additional light on recent White House decisions, such as firing all three commissioners on the Election Assistance Commission. The agency helps certify voting machines for security, and all three commissioners have served across administrations and maintain close relationships with state and local election officials.  

Pamela Smith, CEO of the nonprofit Verified Voting, said that while the EAC can’t take certain actions that need commissioner approval, “critical functions like voting system testing and certification can continue under the existing framework and should not be affected.”

In 2020, Trump’s initial claims of widespread election fraud were undercut by leaders at the Cybersecurity and Infrastructure Security Agency, which said there was no evidence the election was compromised. The removal of EAC commissioners could represent an attempt to preempt any efforts to rebut or criticize White House claims that elections and voting machines have been compromised.

Some have worried that Trump could use the speech as a pretext to declare a national emergency or cancel elections.

Tom Lopach, CEO of the Voter Participation Center, said “you don’t dismantle election security infrastructure if you’re serious about protecting elections.”

“You dismantle it if you’re planning to claim, without evidence, that the system failed you,” he said. 

While Becker takes Trump’s broadsides against state election authority seriously, he also said it’s important not to lose sight of the fact that, in his view, the administration is losing the argument across the board.

More than a dozen federal courts have unanimously rejected the federal government’s attempts to forcibly obtain state voter data, while other courts have rejected core pieces of his election-related executive orders. State officials have publicly — and at times, angrily — pushed back on the administration’s demands as blatant federal overreach. 

Becker predicted that such an act would be quickly shot down by courts as well, noting that the U.S. has never canceled or postponed an election in its 250-year history, including when British troops were marauding on American soil during the War of 1812 or even at the height of the Civil War.

It’s important not to conflate the White House’s bluster and intentions with its actual authorities or capability to seize control of U.S. elections.

“This is what panic and desperation look like,” Becker said. “They’ve had 18 months in total control of the federal government and they have found nothing that would support President Trump’s lies about the 2020 election, and so they’re just trying to grab as much garbage as they can and throw it up against the wall, and it’s not sticking.”

The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appeared first on CyberScoop.

States are building their own election defense networks as federal support evaporates 

By: djohnson
13 July 2026 at 16:59

The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new legal peril for officials who run, administer and secure elections.

The EAC is an obscure but important agency that oversees testing and standards for voting machines, including around security. While federal certification is voluntary, states have until now relied upon their stamp of approval when purchasing voting machines. 

On July 10, Democratic Commissioners Ben Hovland and Thomas Hicks were fired by the White House, while reports indicate that a third Commissioner, Republican Christy McCormick, resigned. While Congress mandated the commission be bipartisan, the Supreme Court has recently given the President broad authority to fire executive branch officials at will.

In an interview with NPR, Hovland said he worried the firings would further erode trust that the commission was working in a bipartisan manner.

“And as you eliminate things – or if you get rid of commissioners, for example – or as you eliminate some of these other sort of safeguards or norms, it certainly strains the system,” said Hovland. “And it certainly also likely causes people to lose faith in our democracy and in the process and their confidence in our elections. And that’s very concerning.”

A letter also sent last week to all 50 states by the DOJ said the department will investigate and prosecute any election official “who knowingly retains non-citizens on the state’s voter registration list or facilitates noncitizens in receiving and casting ballots.”

CyberScoop spoke with several Secretaries of State who said that the number one threat facing elections in their state is not from a foreign country or AI but their own federal government. 

Tobias Read, the Democratic Secretary of State for Oregon, told CyberScoop that his office is focused on providing the state’s 36 county clerks with the resources and support they need to carry out a smooth election. But he acknowledged that his office is “playing defense in a lot of ways [from] the intrusion from the federal government” that continues to assert its authority over local elections.

“If the president were actually serious about election security, he would be sending more resources to local election officials and bolstering the system rather than cutting it,” said Read.

This year, several counties in Oregon will offer voters access to a new ballot tracking system that provides text or email updates when a voter’s ballot is moving through mail and has been certified.  Reed estimated at “pennies per voter per election” and called it a good option for cash-strapped counties to assure voters their ballots are secure and properly tracked.

At the same time, Read said federal agencies like the Cybersecurity and Infrastructure Security Agency – which once regularly deployed cybersecurity and technical expertise to help states fix vulnerabilities and share threat intelligence – have largely gone quiet.

Oregon ranks in the top ten states for voter participation and relies heavily on mail-in voting.  However, state officials like Read lack confidence in the US Postal Service. Though a recent Supreme Court decision blocked an executive order giving the service control over mail-in ballot distribution, officials like Read are urging voters to take other measures to use drop boxes instead as a  safer alternative to ensure their vote is counted.

Adrian Fontes, Arizona’s Secretary of State and a Democrat running for reelection, said his office is focused on primary elections and processing the mail ballots that have been arriving “for a while.”

After Iranian hackers defaced Arizona’s candidate bio portal last year, Fontes moved to fill a widening gap: the Trump administration’s withdrawal of federal foreign interference training and support. His office is now directly supporting local jurisdictions on election security while coordinating more closely with state law enforcement, intelligence agencies, and other states.

But it’s being done with a fraction of the resources and coordination that the federal government brought to bear under both the Biden and first Trump administrations. While Fontes said he maintains positive personal relationships within the Department of Homeland Security, his office does not have a formal relationship with CISA.

“We’ve hobbled together a loose and often informal network of information sharing – that doesn’t violate any rules, it doesn’t break any laws – but it is certainly not anywhere near as robust as it would be if we had a responsible federal agency that was interested in the security of American elections,” said Fontes.

He said even if CISA offered such services today, he wouldn’t accept it, citing the lack of trust between states and the Trump administration.

“They have proven through their actions that they don’t want to be effective partners in protecting the American electorate and protecting American voters,” said Fontes. “Because of that, the clear answer, the only sensible answer for someone like me, would be to say ‘No, I don’t want the help of people I cannot trust.’ People who have demonstrably and explicitly threatened me and local election administrators of all political stripes with criminal prosecution.”

After this story’s initial publication, CISA acting director Nick Andersen said the agency remains committed working with “with critical infrastructure owners and operators to assist them in securing both the physical security and cybersecurity of the systems and assets that support the nation’s election process.”

“We provide state and local election officials, upon request, no-cost voluntary services such as the sharing of threat information, technical expertise, vulnerability scanning, and resilience-building support,” said Andersen in a statement sent to CyberScoop. “Our regional teams assist partners across the country by assessing risks, helping entities bolster defenses and improve resilience, and responding promptly to threats. We are committed to supporting state and local elections officials to protect election infrastructure and safeguard our democracy.”

Secretaries of State in Colorado, Nevada, Minnesota, Rhode Island, and others have also called the DOJ letters an attempt at federal intimidation of election officials. 

Others, like West Virginia Republican Secretary of State Kris Warner, have reiterated their refusal to hand over state voter data. On Monday, a federal judge upheld his right to do so. 

Warner wrote to the DOJ in response to say the state was “available to discuss our existing voter registration list maintenance” but “West Virginia law prohibits the disclosure of sensitive personally identifiable information contained in voter registration records.”

It’s leading some states to take new precautions. 

Read said he was working with Oregon county officials to make sure “county clerks have the number of their county counsel on speed dial” and know how to distinguish between a legitimate and illegitimate federal warrant or subpoena.

Additionally, FBI raids of election offices around the country to seize ballots records related to the 2020 and 2024 elections have been a cause for Read’s concern. By state law, Oregon and other states must keep copies of the ballot records and other election data they receive from counties for a certain time according to state law, after which they must eventually archive or destroy them according to ballot retention schedules.

Read emphasized that “it’s important to destroy those ballots at the appropriate time,”  The Trump administration has used the raids to further the impression of electoral fraud, despite the absence of credible evidence. 

“We can see when people are not on top of that, then you expose yourself to other vulnerabilities like the federal government seizing those ballots in Maricopa County [Arizona] and Fulton County [Georgia] as well,” said Read.

A former CISA official estimated that on Election Day in 2024, more than 1,000 representatives from federal, state and local governments, election technology vendors and other election stakeholders sat together in a room to communicate and coordinate.

Less than two years later, Read called his office’s interactions with CISA “minimal.” He recalled that upon taking office as Secretary of State in Jan 2025, one of his first conversations was with one of CISA’s regional advisors. A week later, those advisors were summarily fired by the Trump administration.

UPDATE: 7/14/2026, 11:15 a.m.: Updated with comments from CISA acting director Nick Andersen.

The post States are building their own election defense networks as federal support evaporates  appeared first on CyberScoop.

SMS Phishers Pivot to Points, Taxes, Fake Retailers

4 December 2025 at 18:02

China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.

Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.

An instant message spoofing T-Mobile says the recipient is eligible to claim thousands of rewards points.

The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitor’s name, address, phone number and payment card data to claim the points.

A phishing website registered this week that spoofs T-Mobile.

If card data is submitted, the site will then prompt the user to share a one-time code sent via SMS by their financial institution. In reality, the bank is sending the code because the fraudsters have just attempted to enroll the victim’s phished card details in a mobile wallet from Apple or Google. If the victim also provides that one-time code, the phishers can then link the victim’s card to a mobile device that they physically control.

Pivoting off these T-Mobile phishing domains in urlscan.io reveals a similar scam targeting AT&T customers:

An SMS phishing or “smishing” website targeting AT&T users.

Ford Merrill works in security research at SecAlliance, a CSIS Security Group company. Merrill said multiple China-based cybercriminal groups that sell phishing-as-a-service platforms have been using the mobile points lure for some time, but the scam has only recently been pointed at consumers in the United States.

“These points redemption schemes have not been very popular in the U.S., but have been in other geographies like EU and Asia for a while now,” Merrill said.

A review of other domains flagged by urlscan.io as tied to this Chinese SMS phishing syndicate shows they are also spoofing U.S. state tax authorities, telling recipients they have an unclaimed tax refund. Again, the goal is to phish the user’s payment card information and one-time code.

A text message that spoofs the District of Columbia’s Office of Tax and Revenue.

CAVEAT EMPTOR

Many SMS phishing or “smishing” domains are quickly flagged by browser makers as malicious. But Merrill said one burgeoning area of growth for these phishing kits — fake e-commerce shops — can be far harder to spot because they do not call attention to themselves by spamming the entire world.

Merrill said the same Chinese phishing kits used to blast out package redelivery message scams are equipped with modules that make it simple to quickly deploy a fleet of fake but convincing e-commerce storefronts. Those phony stores are typically advertised on Google and Facebook, and consumers usually end up at them by searching online for deals on specific products.

A machine-translated screenshot of an ad from a China-based phishing group promoting their fake e-commerce shop templates.

With these fake e-commerce stores, the customer is supplying their payment card and personal information as part of the normal check-out process, which is then punctuated by a request for a one-time code sent by your financial institution. The fake shopping site claims the code is required by the user’s bank to verify the transaction, but it is sent to the user because the scammers immediately attempt to enroll the supplied card data in a mobile wallet.

According to Merrill, it is only during the check-out process that these fake shops will fetch the malicious code that gives them away as fraudulent, which tends to make it difficult to locate these stores simply by mass-scanning the web. Also, most customers who pay for products through these sites don’t realize they’ve been snookered until weeks later when the purchased item fails to arrive.

“The fake e-commerce sites are tough because a lot of them can fly under the radar,” Merrill said. “They can go months without being shut down, they’re hard to discover, and they generally don’t get flagged by safe browsing tools.”

Happily, reporting these SMS phishing lures and websites is one of the fastest ways to get them properly identified and shut down. Raymond Dijkxhoorn is the CEO and a founding member of SURBL, a widely-used blocklist that flags domains and IP addresses known to be used in unsolicited messages, phishing and malware distribution. SURBL has created a website called smishreport.com that asks users to forward a screenshot of any smishing message(s) received.

“If [a domain is] unlisted, we can find and add the new pattern and kill the rest” of the matching domains, Dijkxhoorn said. “Just make a screenshot and upload. The tool does the rest.”

The SMS phishing reporting site smishreport.com.

Merrill said the last few weeks of the calendar year typically see a big uptick in smishing — particularly package redelivery schemes that spoof the U.S. Postal Service or commercial shipping companies.

“Every holiday season there is an explosion in smishing activity,” he said. “Everyone is in a bigger hurry, frantically shopping online, paying less attention than they should, and they’re just in a better mindset to get phished.”

SHOP ONLINE LIKE A SECURITY PRO

As we can see, adopting a shopping strategy of simply buying from the online merchant with the lowest advertised prices can be a bit like playing Russian Roulette with your wallet. Even people who shop mainly at big-name online stores can get scammed if they’re not wary of too-good-to-be-true offers (think third-party sellers on these platforms).

If you don’t know much about the online merchant that has the item you wish to buy, take a few minutes to investigate its reputation. If you’re buying from an online store that is brand new, the risk that you will get scammed increases significantly. How do you know the lifespan of a site selling that must-have gadget at the lowest price? One easy way to get a quick idea is to run a basic WHOIS search on the site’s domain name. The more recent the site’s “created” date, the more likely it is a phantom store.

If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments — particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.

But it’s not just outright scammers who can trip up your holiday shopping: Often times, items that are advertised at steeper discounts than other online stores make up for it by charging way more than normal for shipping and handling.

So be careful what you agree to: Check to make sure you know how long the item will take to be shipped, and that you understand the store’s return policies. Also, keep an eye out for hidden surcharges, and be wary of blithely clicking “ok” during the checkout process.

Most importantly, keep a close eye on your monthly statements. If I were a fraudster, I’d most definitely wait until the holidays to cram through a bunch of unauthorized charges on stolen cards, so that the bogus purchases would get buried amid a flurry of other legitimate transactions. That’s why it’s key to closely review your credit card bill and to quickly dispute any charges you didn’t authorize.

Lawrence’s List 090216

By: BHIS
2 September 2016 at 13:14

Lawrence Hoffmann // Election fraud is something I’ve mentioned here recently. The reality we must face here is that any time a digital system is used for voting there is […]

The post Lawrence’s List 090216 appeared first on Black Hills Information Security, Inc..

Potential Surge in Cryptocurrency Leaks

27 August 2024 at 01:00

Increase in Cryptocurrency Leaks After Trump Supports Bitcoin

Recently, Constella Intelligence has observed an increase in attacks and data breaches resulting in cryptocurrency leaks. This surge could be partly attributed to comments made by former President Donald Trump in support of Bitcoin, which may have heightened hackers’ interest in these sites.

Former President Donald Trump has recently positioned himself as a pro-crypto presidential candidate. During his keynote speech at the Bitcoin 2024 conference in Nashville, Tennessee, held from July 25-27, 2024, Trump emphasized the transformative potential of cryptocurrencies. He pledged to make the United States a leader in Bitcoin mining and digital asset management.

These comments could have caused crypto-related sites to increase in value, making them more attractive targets for cybercriminals. As Bitcoin prices surge, the incentive for attacks on these platforms grows, highlighting the need for robust security measures.

Crypto Leaks Overview

In the first half of 2024, over 250 possible breaches or leaks related to cryptocurrencies, NFTs, and Bitcoin have been reported. These potential breaches could have affected users of various cryptocurrency platforms, including Bitcointalk, Crypto.com, Binance, eToro, and others.

Below are examples of how threat actors are offering information about these crypto-related sites on the Dark Web

Zuelacoin Data Leak:

zyelacoin cryptocurrency leak

This information was published on March 31, 2024. According to the threat actor the data includes:

  • Emails
  • Names
  • Social media profiles (Twitter, Facebook, Telegram)

Binance Cryptocurrency Leak:

Binance Cryptocurrency Leak

The post was made on May 27, 2024. The exposed information includes:

  • Emails
  • Full names
  • Phones
  • Countries

Mobile Apps like CashCoin, Coinbase, and KuCoin:

Mobile Apps like CashCoin, Coinbase, and KuCoin

The threat actor “whix” published this on March 26, 2024. The exposed information includes:

  • Emails
  • Usernames
  • Passwords
  • Countries
  • IP Addresses
  • Payment methods

eToro Cryptocurrency Leak:

eToro Cryptocurrency Leak

The same threat actor also reported this on March 25, 202, where the following information could be found:

  • Full names
  • Emails
  • Countries
  • IP Addresses
  • Amounts
  • Payment methods

Bitcointalk Cryptocurrency Leak:

Bitcointalk Cryptocurrency

According to the threat actor on March 25, 2024, a database exposing the following information was published:

  • Emails
  • Usernames
  • Ethereum Addresses

These platforms are integral to the crypto ecosystem, providing services such as trading, wallet management, and social interaction for crypto enthusiasts.

Extent of Infostealer Exposures

Constella Intelligence has checked if the information published could have been produced as the effect of infostealer infections. This check resulted in nearly 4 million users of these cryptocurrency companies being exposed to infostealer data. Most exposures have impacted major cryptocurrency exchange platforms:

  1. Binance: More than 2M users exposed.
  2. EToro: More than 500k users exposed.
  3. Crypto.com: More than 300k users exposed.
  4. Localbitcoins: More than 200k users exposed.

Digging into the infostealer exposures, Constella Intelligence also identified what seems to be infostealer infections of potential employees of some of those companies, including Binance.com, eToro.com, Crypto.com, and Localbitcoins.com, among others.

Implications of Crypto-Related Breaches

The exposure of such extensive and sensitive information has significant and far-reaching implications as it endangers the financial security and privacy of millions of users. The compromised data can be exploited for various malicious activities:

  1. Identity Theft: Personal information such as full names, addresses, and birthdays can be used to steal identities.
  2. Financial Fraud: Payment methods and transaction histories can be exploited to conduct unauthorized transactions.
  3. Phishing Attacks: Email addresses and social media profiles can be used to create convincing phishing scams.

Recommendations for Users

To mitigate the risks associated with the recent breaches, users should adopt the following security practices:

  1. Use Strong, Unique Passwords: Ensure that each cryptocurrency account has a strong, unique password. Consider using a password manager to generate and store complex passwords securely.
  2. Enable Two-Factor Authentication (2FA): Adding an extra layer of security through 2FA can significantly reduce the risk of unauthorized access to accounts.
  3. Monitor Crypto Transactions Regularly: Keep a close watch on your cryptocurrency transactions and wallet activity to detect any unauthorized activities. Early detection can help prevent significant financial losses.
  4. Be Wary of Phishing Attempts: Be cautious with emails and messages requesting personal information or directing you to log in to your accounts. Verify the authenticity of such requests through official channels.
  5. Update Security Settings on Crypto Platforms: Regularly review and update your security settings on cryptocurrency exchanges and wallets. Ensure that all recovery options are up-to-date and secure.
❌
❌