Election interlopers register 5K+ domains, hope to catch some voting phish
Check Point says more than 5,000 election-themed domains were registered in two months, alongside exposed credentials tied to political and government sites.
Intelligence analysis by GPT-5.4 Mini

Check Point sees a growing election-phishing ecosystem: thousands of fresh vote- and election-themed domains, plus leaked credentials tied to fundraising, party, and government services. The report frames phishing, impersonation, fraud, and misinformation as the main risks ahead of the US midterms.
A security company says a lot of new web addresses with words like "vote" and "election" have been set up before the US midterm elections. Some of these could be used like fake store signs to trick people into thinking they are real election sites.
The company also found many leaked passwords linked to political and government websites. That matters because a thief with a real password can sometimes pretend to be a real worker instead of just making a fake page.
It is a bit like someone putting up many fake front doors and also finding spare keys. Even if not every door is dangerous, having more doors and more keys makes tricking people much easier.
Analysis
What Check Point found
Check Point says election-related domain registrations rose sharply ahead of the US midterms. Between April 13 and May 14, it recorded about 1,140 newly registered domains containing the word "election" and roughly 4,010 containing "vote". The company says those names could be used for phishing, impersonation, fraud, misinformation, or influence activity.
Why the domains matter
The article stresses that registering a domain does not prove malicious intent. Even so, election-themed names are useful for fake voter-info pages, candidate lookalikes, donation scams, and messages that mimic official election communications. Danielle Hess of Check Point says the growth in election-themed domains and leaked credentials are "two sides of the same problem": infrastructure and access.
Credential exposure alongside the domain surge
Check Point also says it found about 17,000 exposed credentials tied to fundraising groups, political parties, and government-related services in May. The article cites approximately 9,500 leaked ActBlue credentials, 6,500 WinRed credentials, 600 from gop.com, 130 from democrats.org, and 150 from usa.gov citizen services. Hess notes these figures reflect what was visible on Check Point's External Risk Management platform as of May 2026, not necessarily credentials leaked during that month alone.
Election risk framing
The report argues the bigger threat is not attackers hacking voting machines, but phishing and election-official impersonation. It also says AI makes phishing and misinformation cheaper and easier to scale. The article ties this trend to reduced federal election-defense capacity, including cuts to CISA and the shutdown of the Elections Infrastructure Information Sharing and Analysis Center.
Key points
- Check Point documented more than 5,000 election-themed domains registered between April and May.
- The firm says those domains could support phishing, impersonation, fraud, misinformation, or influence operations.
- It also found about 17,000 exposed credentials linked to fundraising, political parties, and government-related services.
- The article says phishing and election-official impersonation are more likely risks than attacks on voting machines.
- Check Point says AI is making these scams easier to scale.
If election officials and campaigns harden their accounts and monitor these domains, the extra infrastructure could be identified and blocked before it is widely abused. The visibility from threat-intelligence reporting may also help voters and staff spot impersonation attempts earlier.
If the exposed credentials remain active or are reused, attackers could use them to make phishing and impersonation campaigns more convincing. The article also suggests that AI could make election scams faster, cheaper, and easier to scale ahead of November.



