Email Remains the Front Line in Campaign Security

Cloudflare’s work supporting democratic elections has centered on a simple premise: candidates should be able to focus on communicating with voters, not defending their inboxes. Email remains the primary vector attackers use against campaigns, and phishing alone accounts for the vast majority of organizational damage. A single well-crafted message can expose sensitive information, spread false narratives, or divert donations—making inbox protection a critical part of election security.

During the 2022 US midterms, Cloudflare extended this protection to more than 100 campaigns, election officials, and public organizations supporting elections. In the three months leading up to the vote, the company processed over 20 million emails and blocked roughly 150,000 phishing attempts. The campaigns served ranged from first-time local candidates to incumbents in national office.

Attackers Target Some Campaigns Repeatedly

Certain campaigns drew disproportionate attention. One incumbent US Senate campaign saw its staff receive an average of over 35 malicious emails per day. Another tactic involved impersonation: over 10,000 emails used the names of candidates without permission during the same three-month period.

A single Senate campaign’s metrics illustrate the scale of the threat:

BLOG-1538 Embedded Image - nY5cax

Disguising Malicious Emails as Internal Business

Attackers often craft messages that blend in with routine campaign operations. In one case, a US House candidate’s staff received an email with the subject “Staff Payroll Review” that asked recipients to access a link. The message included a plausible email footer and branding consistent with the campaign—making it difficult to distinguish from legitimate internal communication.

Cloudflare’s Area 1 models flagged the email as malicious by examining metadata. The sending domain was suspicious because it closely resembled the representative’s actual campaign domain—a pattern called domain proximity. The attached link pointed to a recently registered domain, adding to the evidence. The email never reached a single mailbox.

Malicious Attachments and Misdirection

Another common approach involves attachments carrying ransomware or data exfiltration tools. Attackers frequently obscure these files by changing extensions or describing them as something more innocuous in the email body. One campaign staffer received a targeted message asking them to download a purchase order.

Given that the recipient habitually processes many purchase orders per day, careful inspection isn’t always practical. Area 1 assessed the email and found multiple red flags. The attachment in question was a 7-Zip file named PO567.7z—purchase orders are almost always sent as PDFs. The message also contained poor sentiment, a grammatical error (“Dear Info,”), and lacked the common markers found in legitimate purchase order correspondence.

BLOG-1538 Embedded Image - tCWuoJ

Crucially, this was also the first communication ever received from that sender. The combination of signals led Cloudflare to block the message before delivery.

Deployable Protection Without Configuration Overhead

Cloudflare’s Area 1 product relies on preemptive campaign discovery and machine learning models that analyze attachment characteristics, sender domains, and email sentiment to determine risk. The solution is designed for rapid deployment—campaigns get protected immediately without installing hardware, agents, or appliances.

This matters because election cycles often prevent campaigns from implementing standard email authentication controls like SPF, DKIM, or DMARC. The short lifespan of a campaign makes setting up these measures difficult, so strong inbound filtering becomes even more important. For Cloudflare, securing inboxes is a core part of protecting democracy—allowing candidates to spread their message without worrying about phishing.