Trellix report: phishing emails targeting county election workers surged in battleground states Arizona and Pennsylvania ahead of their 2022 primary elections
Research conducted by cybersecurity firm Trellix found that county election workers in Arizona and Pennsylvania saw an increase … Source: Trellix .
Context & Ripple Effects
The Trellix findings extend a pattern that has been building since at least 2016, when the FBI warned that suspected foreign hackers had breached two state voter registration databases — including Arizona's own registration system. The new report shows the target has shifted downward: rather than state databases, the aim is now the inboxes of county election workers in the same two battleground states.
That shift matters because county email systems have repeatedly proven to be the softest entry point. A rural Texas county's compromised email server was used to send fake messages to voters in 2020, and grand jurors had earlier flagged unsecured election officials' email as a channel for disseminating false voting instructions.
First-order effects
- County election offices in Arizona and Pennsylvania face a heavier phishing load heading into their primaries, forcing staff time and limited local budgets toward email filtering, verification procedures, and incident response.
- Trellix gains a concrete data point positioning threat intelligence reporting as a service election jurisdictions may buy, alongside volunteer efforts like Election Cyber Surge that match local officials with cybersecurity experts.
Second-order effects
- State-level authorities in both states — already active on adjacent fronts, with Arizona's attorney general suing Kalshi over election betting and Pennsylvania litigating chatbot impersonation of doctors — face pressure to extend oversight to local election communication channels they do not directly control.
- Vendors of email security and managed detection services see county governments as an underserved market segment, since most counties lack in-house security teams and cannot replicate state-level defenses.
Third-order effects
- If targeting keeps migrating from state databases to county workers, election security structurally fragments across thousands of small offices, making shared services, volunteer pipelines like Election Cyber Surge, and federal support programs the de facto backstop.
- Even unsuccessful phishing fits the 'perception hack' scenario officials were warned about in 2020 — attacks too small to change outcomes but exploitable if exaggerated — meaning disclosure and attribution of these campaigns become politically charged in battleground states.
The trend: Election cyberattacks are moving down the administrative stack from state voter-registration databases to county-level workers, where defenses are thinnest and a single compromised inbox can reach voters directly.