Arizona Agencies Targeted in Phishing Campaign

Threat actors deployed impersonation domains mimicking state and county authorities to solicit information.

Updated on Oct. 3, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy, cream, and red, featuring a geometric network lattice representing digital infrastructure security threats.
Arizona state and county officials are investigating a sophisticated phishing campaign that impersonated government authorities using fraudulent web domains to solicit sensitive information. AI Illustration. Upload story photo >

Live Poll

Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?

State and county authorities in Arizona have issued a warning regarding a phishing campaign that utilized fraudulent .us domains. The attackers registered lookalike websites to impersonate government managers and administrators.

Why it matters

The campaign highlights risks associated with domain spoofing that targets public sector infrastructure. It underscores the importance of verifying official communication channels during interactions with government agencies.

The attackers utilized lookalike .us domains, including az-doa.us for state impersonation and Maricopa-az.us for county targeting. These domains were designed to masquerade as legitimate government portals and administrators.

The players

Arizona Procurement Portal

The state-run digital infrastructure hub that manages government contracts and official procurement communications.

Maricopa County

The most populous county in Arizona, acting as a primary target for impersonation efforts within this phishing campaign.

The details

The campaign functions by registering deceptive web addresses that mimic official Arizona state and county agency designations. By using these lookalike domains, the threat actors attempt to solicit sensitive information by impersonating government managers and administrators. Users are typically deceived when official-looking digital communication leads them to these spoofed interfaces.

Timeline

  1. October 3, 2026: The Arizona Procurement Portal issued a formal warning regarding the campaign.

The Tech Race

This campaign follows the well-documented trend of threat actors utilizing lookalike domains to bypass traditional authentication checks. It reflects the ongoing challenge of securing public sector communication paths against spoofing techniques.

Arizona residents should verify the legitimacy of any email or web link claiming to originate from state or county offices before entering credentials. Always inspect domain names for subtle variations that deviate from official .gov or state-verified site structures.

The takeaway

The campaign demonstrates the necessity of cross-referencing domain names against known government agency lists. Readers should remain vigilant for domain variations and verify all agency communications through official government portals.

Further reading

For more information on current digital threats, visit Cybersecurity.

More information

To report suspicious activity to state authorities, email the official state authorities contact address.

Source note: This article includes information reported by Your Valley.

Live Poll

Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?