Phishing (not Fishing) and Why It Isn’t Phun

Don’t be duped by online criminals. Fake emails asking for money are as old as the internet. But cyber fraud is sophisticated, and it can be easy to be drawn in when a familiar name lands in your inbox. Democrats right here in Multnomah County and across the country are targets.

Email scams to Democrats

For at least the past year, MultDems volunteers — district and committee leaders — have been receiving emails purporting to be from the Chair or other officers, asking for personal information, help or money. These emails look like personal messages, but they are not. For example: some recent emails to MultDems purport to be sent from our County Chair, Salome Chimuku. But the sender email address did not match up to chair@multdems.org

“When you open up emails from MultDems colleagues, the first thing you should do is examine the actual sender’s email address,” says MultDems Chief Technology Officer Mike DiNapoli. “Make sure the email address (not just the name) is known to you. This is a habit every political organizer should follow faithfully. Cyber fraudsters can sound very personal, especially with the help of AI. Clicking links, or providing your phone number without verifying the sender can have bad outcomes.”

What looks like a harmless message may not be. Without verifying the email or the sender, a simple email could be a type of cyber-attack called Phishing, and it’s intended to make you click a link, hand over money or sensitive information to a bad actor.  If you click a link or open an attachment from an unverified email address, that link or an attachment could mean trouble. If you  click the email link, you  could open the door to password-stealing malware. The scammers can then hack into your computer, accessing emails and financial records. Alternatively, a sophisticated bad actor could convince you to buy gift cards, claiming it’s to pay for party activity, when in reality that money is going into the scammer’s own pocket.

“People who work in the Democratic ecosystem are considered high-risk internet users. This means your work and personal accounts are targeted at higher rates,” notes a  2026 Democratic National Committee (DNC) security advisory. “We strongly encourage anyone who works in politics, campaigns, or simply has a device or an account on the internet to take these precautions.”

Democrats have historically been a target of malicious online attacks. Back in 2016 Russian scammers used phishing attacks to obtain sensitive information from the DNC and the Clinton Campaign. Because this is an election year, we can expect similar attacks on Democrats from county parties on up.

Here are some recent news articles of note (click to bold face type to read):

DNC Russia hack during the election years of 2015-16.

Targeting Dem volunteers with phishing messages (2020)

Other county Democratic Party organizations are reporting similar scams where the email sender impersonates the party chair — e.g. in Westmoreland County, Virginia.

Volunteers and staff for Congressional campaigns may be at high risk. Tech Solidarity offers some basic tips to secure your computer and prevent hacking via email, along with some additional resources and advice.

Fake PACs (including the “National Democrats” asking for funds but they never actually fund any candidates (2025).

What you can do

— Don’t open any email from a sender name you don’t recognize. 

— If you do recognize the name, check the sender’s email address. Still, if the email message sounds “off” to you or the ask seems out of the ordinary, take further steps to verify.

— If it’s Phishy… Do not reply to the email.

Do not click any links or open attachments.

— Forward the scammy email to our technology officer: technology@multdems.org. Be sure to include a short note that you believe the email was a scam or phishing attempt.

Resources

Learn how to detect and avoid Phishing scams

DNC Security Checklist

Oregon Dept of Justice: Report online scams and fraud

Questions about emails and other tech? Contact the MultDems Technology officer at technology@multdems.org.