Check Point Software warns that phishing, domain impersonation and leaked credentials pose a major threat to the 2026 U.S. midterm elections by undermining trust in news outlets and election communications. Researchers documented sharp increases in "election" and "vote" domain registrations and flagged roughly 9,500 ActBlue and 6,500 WinRed credentials circulating on criminal markets. Experts urge campaigns, election officials and security teams to prioritize domain monitoring, credential hygiene and rapid response during this elevated-risk period.
Fake Reuters and Fox Sites Flood the Web Ahead of 2026 Midterms — Phishing, Domain Cloning and Credential Leaks Threaten Voter Trust

As the November 2026 midterm elections approach, cybersecurity researchers warn that the most pervasive threats may not be altered ballots or hacked voting machines but rather phishing campaigns, brand impersonation and leaked credentials designed to erode public trust.
Research from Check Point Software shows that bad actors are increasingly using look-alike domains, social posts and search-manipulation to spread deceptive narratives and counterfeit content that mimic respected news outlets and official election resources.
"Sophisticated operators have already cloned major media brands like Reuters, The Washington Post, and Fox News using look-alike domains that can fool even attentive readers at a glance," said Danielle Hess, Check Point cyber threat intelligence analyst, exposure management.
Hess added that in today’s AI-augmented disinformation environment, attackers often aim not to change vote totals directly but to make it difficult for voters to determine what is true.
Domain Registration Trends
Check Point’s Exposure Management team tracked surges in election-related domain registrations. In January, roughly 1,300 domains containing the word "election" and just under 3,000 containing "vote" were created. From mid-April to mid-May, registrations with "election" held near 1,140, while "vote" domains jumped to about 4,010. The shift toward voter-facing terminology increases the risk of phishing sites that impersonate voter information portals.
Credential Exposure And Fraud Risk
Compounding the danger, Check Point reported that as of May it had tracked roughly 9,500 leaked credentials tied to ActBlue and about 6,500 tied to WinRed being traded on criminal markets. Those credentials can enable account takeover, donor fraud and highly targeted social-engineering campaigns against fundraising platforms and campaign staff.
"The 2026 midterm threat environment is a trust infrastructure story, and the systems under pressure are ones security teams already manage: email, web properties, credential exposure, third-party platforms, and brand integrity," Hess said.
Practical Impact And Urgency
Because attackers can pre-register domains and activate them at decisive moments, disinformation campaigns can appear quickly and vanish before defenders can respond. This ephemeral infrastructure, combined with leaked credentials and convincing brand cloning, makes it easier to misdirect voters, siphon donations or impersonate officials.
The warning arrives amid a reported $707 million funding reduction for the Cybersecurity and Infrastructure Security Agency (CISA), described by the administration as a response to concerns about "weaponization and waste." Senator Mark R. Warner, vice chairman of the Senate Select Committee on Intelligence, cautioned that states cannot replicate the intelligence, expertise and real-time reporting that federal partners provide.
Security teams working with campaigns, election administrators, fundraising platforms and related organizations should treat this election cycle as a heightened-risk period for phishing, brand impersonation and credential-based attacks. Measures such as proactive domain monitoring, strong credential hygiene (including multi-factor authentication), rapid takedown coordination and public education about trusted information sources can help reduce harm.
This article was originally published on Forbes.com.
Help us improve.




























