You spot a campaign shirt online that makes you laugh. The site carries the candidate's name. It also has polished product photos and a familiar checkout page. So, you assume the store supports the campaign.
A fake election website can copy enough campaign cues to make that assumption feel reasonable. Your money and personal information could then reach an operator with no verified campaign connection.
New research provided to CyberGuy by WhoisXML API, an internet intelligence company that analyzes domain, IP and DNS data, tracked 62,081 election-named domains created since September 2025. Researchers identified 13,645 addresses that read like campaign sites based on their names.
The research classifies only a portion of the domains as campaign-style addresses. Legitimate campaigns, supporters, merchants and domain investors may control many of them. However, researchers also found live storefronts that used candidates' names while selling merchandise and accepting donation-style payments. That smaller group creates the clearest risk for you.
FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK
CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist
Our free CyberGuy Live class, "Sick of Spam?," has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.
Get the free replay and checklist now at CyberGuyLive.com.
Why fake election websites surge before the midterms
National elections create a rush for online real estate. Campaign teams want memorable web addresses before someone else claims them. Supporters may launch fan pages, while merchants see an opportunity to sell political products. Impersonators can follow the same naming formula.
According to WhoisXML API, nearly 46% of the curated campaign-style set used structures such as "[name]for[office]" or "for[state]." Domains referencing congressional races appeared most often. Senate-themed names came next. State names also appeared across about one-third of the curated set. Texas led with 537 registrations. Florida, Georgia, Ohio and Colorado followed.
Those names feel familiar because real campaigns use the same structure. As a result, a questionable domain can look credible before you open the page. Across the domains studied, researchers said 90% hid the registrant's identity. In addition, 88% carried a one-year registration term. Privacy protection and short registration terms can have legitimate uses. Still, those details deserve more attention when a new site also copies campaign branding or asks for money.
A small change in a domain can hide in plain sight. WhoisXML API highlighted massiemoneybomb[.]us, which closely resembled the established massiemoneybomb[.]com fundraising address. The main difference appeared after the final dot.
That change may look obvious on a large computer screen. However, it becomes easier to miss on a phone, especially when a text or social media post opens the page directly. Researchers also examined kenpaxton[.]us. They said the domain was 58 days old when captured, while kenpaxton[.]com dated back to 2008.
The newer site reportedly sold supportive campaign products alongside merchandise criticizing the same candidate. That unusual mix offers a clue that the store may lack an official connection. Yet many shoppers will focus on the product photos or the price. A polished checkout can make the entire operation feel established. Alexandre François, the WhoisXML API domain scam researcher behind the study, told CyberGuy that AI can help operators build convincing websites quickly and at scale. That makes it even harder to judge a campaign page by its appearance alone.
Political merchandise may cost you more than the price on the screen. According to the research, some storefronts allowed visitors to add donation-style payments of up to $1,000 to a shopping cart. The sites then processed the payment through their own checkout flows.
One store reportedly continued accepting a donation-style payment after the candidate's official ActBlue page stopped taking contributions. The checkout requested a full name, street address, email address and phone number. It also collected payment card details.
A familiar payment processor can make that form feel safe. However, its presence only shows how the payment moves through the checkout. It cannot confirm that the candidate authorized the store or that the campaign receives the money.
François said the study found no direct evidence that donors lost money or had their data misused. "Only the payment platforms could see whether a donor lost money or had data misused, and their data was not part of this study," he told CyberGuy. The findings support caution rather than a claim that every highlighted site committed fraud.
Domain registration records can expose useful clues before or after a website launches. Researchers can review the creation date, registrar, paid registration period and privacy status. Sometimes, the records also identify the owner or registrant country. However, each clue has limits.
Many legitimate website owners use privacy services to keep home addresses and contact details out of public databases. Campaigns may also register several defensive domains so impersonators cannot claim them first. A one-year registration term also appears across ordinary websites. Price and convenience often drive that choice.
The risk grows when several details point in the same direction. A nearly copied domain may lead to a new storefront with an unofficial donation flow. A mismatched disclaimer adds another concern.
For federal political committees, public websites generally need a disclaimer that identifies who paid for the communication. The wording may also state whether a candidate authorized it. The FEC explains that disclaimer requirements cover political committee websites and online fundraising communications. A disclaimer cannot guarantee honesty. Still, a missing or mismatched statement gives you a strong reason to leave the page and verify the site elsewhere.
Campaigns also face limits when trying to secure every possible variation of a candidate's name. François said they should consistently promote one official domain and one donation link. He added that "the realistic option is monitoring" because registering every possible look-alike domain would be impractical. Monitoring new registrations can help campaigns find look-alike sites during their first days online. Campaigns can then report suspicious pages to the registrar, hosting company or payment provider.
SAME-NAME CANDIDATE DISQUALIFIED FROM KEY SENATE RACE OVER ALLEGED DEM SCHEME TO CONFUSE VOTERS
Before you buy campaign merchandise or make a political contribution online, use these checks to confirm that the site connects to the candidate or committee you intend to support.
Avoid starting with a link from an unexpected text, email, online ad or social media comment. Instead, search for the candidate independently. Then compare the result with links from the candidate's verified social media account or established public profile. "No single sign is enough, so it's best to check a few together and to reach the page from the campaign's own channel," François told CyberGuy.
You can also use a personal data removal service to reduce the personal information available through data brokers and people-search sites. This may limit the details scammers can use to make unexpected messages, targeted ads or social media comments feel more convincing. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.
For federal races, use the FEC's campaign finance database at fec.gov/data/ to look up candidates and registered committees. The database shows federal candidate and committee filings. For state or local races, check the appropriate state or local election authority. Many campaigns process contributions through ActBlue or WinRed. In those cases, the payment address should show secure.actblue.com or secure.winred.com. Some campaigns use other processors, so an unfamiliar payment provider alone does not prove the page is deceptive.
Tap or click the address bar before entering payment information. Check the spelling and domain ending. Then look for added words or letters that imitate the campaign's real address.
A scammer may replace ".com" with ".us." Another operator may add words such as "official," "store," "donate," or "support" to make the address feel authentic. François said the difference may also involve one word, a hyphen or an ending such as ".vote" or ".store."
Scroll to the bottom of the site and review the area around the donation form. A federal political committee website should identify who paid for the communication. Depending on the committee, the disclaimer may also explain whether the candidate authorized it.
Compare that committee name with the FEC database. Leave the page when the names conflict or the disclosure looks vague. Keep in mind that a deceptive page can copy a real committee's name. Treat the disclosure as one clue rather than proof that the page belongs to the campaign.
Open the candidate's established website in a separate tab. Look for a direct link to the merchandise store or donation page. If the official site sends you somewhere else, use the link it provides.
Also review the store's contact details and return policy. Be cautious if it sells products supporting a candidate alongside merchandise attacking that candidate. That unusual mix may signal the store has no official campaign connection. A page that keeps collecting contributions after a candidate withdraws also deserves closer scrutiny. The same applies when a store continues selling campaign merchandise after the official donation page closes.
The padlock in your browser means the site uses an encrypted connection. It offers no proof about the person or business behind the page.
CISA warns that phishing attacks may use malicious websites that impersonate trusted organizations to collect personal information. A professional design and secure connection still require you to verify the operator.
Pressure can push you past obvious warning signs. Be cautious when a site claims a donation match will disappear within minutes. A countdown clock that keeps resetting should also raise concern.
The FTC's broader donation-safety guidance recommends researching an organization and resisting pressure to give immediately.
WHAT A SCAMMER SEES THE MOMENT THEY GOOGLE YOUR NAME
A credit card generally offers stronger dispute protections than a debit card. It also keeps the payment away from funds in your checking account. The FTC says legal protections for credit cards exceed those for debit cards in billing disputes.
Save your receipt and take screenshots of the product page and checkout. Make sure the full domain appears in at least one image. After you pay, check your statement to confirm the amount and make sure the site did not enroll you in recurring contributions.
A fake campaign website may try to push a malicious download or send you to another harmful page. Strong antivirus software can help detect suspicious files and block some dangerous websites. However, you still need to verify the campaign connection before you pay. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
If a store asks you to create an account, use a unique password. A password manager can generate and save a strong password for you, so you do not have to remember it. Reusing a password could put your other accounts at risk if the login information gets exposed. Turn on two-factor authentication (2FA) when the site offers it.
Election season gives questionable websites a powerful disguise. A candidate's name can create trust before you verify who operates the page. The scale of this research should make every online donor slow down. Researchers found more than 62,000 election-named domains, though many may serve legitimate purposes. The clearest concern comes from active storefronts that copy campaign-style branding and collect money outside a verified campaign path. Take an extra minute before buying a shirt or making a contribution. Find the official campaign site through a trusted source. Then confirm the web address and committee disclosure before you enter personal or payment information.
Have you ever landed on a campaign website that looked real but left you wondering who was behind it? Write to us at CyberGuy.com and tell us what raised your suspicions.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.