Arizona Agencies Targeted in Phishing Campaign
Threat actors deployed impersonation domains mimicking state and county authorities to solicit information.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?
State and county authorities in Arizona have issued a warning regarding a phishing campaign that utilized fraudulent .us domains. The attackers registered lookalike websites to impersonate government managers and administrators.
Why it matters
The campaign highlights risks associated with domain spoofing that targets public sector infrastructure. It underscores the importance of verifying official communication channels during interactions with government agencies.
The attackers utilized lookalike .us domains, including az-doa.us for state impersonation and Maricopa-az.us for county targeting. These domains were designed to masquerade as legitimate government portals and administrators.
The players
Arizona Procurement Portal
The state-run digital infrastructure hub that manages government contracts and official procurement communications.
Maricopa County
The most populous county in Arizona, acting as a primary target for impersonation efforts within this phishing campaign.
The details
The campaign functions by registering deceptive web addresses that mimic official Arizona state and county agency designations. By using these lookalike domains, the threat actors attempt to solicit sensitive information by impersonating government managers and administrators. Users are typically deceived when official-looking digital communication leads them to these spoofed interfaces.
Timeline
October 3, 2026: The Arizona Procurement Portal issued a formal warning regarding the campaign.
The Tech Race
This campaign follows the well-documented trend of threat actors utilizing lookalike domains to bypass traditional authentication checks. It reflects the ongoing challenge of securing public sector communication paths against spoofing techniques.
Arizona residents should verify the legitimacy of any email or web link claiming to originate from state or county offices before entering credentials. Always inspect domain names for subtle variations that deviate from official .gov or state-verified site structures.
The takeaway
The campaign demonstrates the necessity of cross-referencing domain names against known government agency lists. Readers should remain vigilant for domain variations and verify all agency communications through official government portals.
Further reading
For more information on current digital threats, visit Cybersecurity.
More information
To report suspicious activity to state authorities, email the official state authorities contact address.
Source note: This article includes information reported by Your Valley.
Live Poll
Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?







