New CSC Research Finds Over 90% of Websites Linked to Donald Trump and Joe Biden Campaigns at Risk for Potential Redirection, Disinformation, and Data Theft
CSC, a world leader in business, legal, tax, and domain security, today released new research from their Digital Brand Services (DBS) division that reveals areas of risk for prominent election-related websites. The research indicates that web domains closely linked to the campaign websites for Joe Biden and Donald Trump lack basic domain security protocols and are being targeted for disinformation activities such as domain spoofing, and threats including domain name and domain name system (DNS) hijacking, and phishing.
On the heels of its recent Forbes Global 2000 research, CSC is seeing major risks related to the manipulation of web properties that voters rely on for information and donations. Findings show that over 90% of these web properties are not using registry locks to protect their domains from domain and DNS hijacking that can lead to phishing attacks, network breaches, and email compromise.
“As noted in our previous research, we’ve consistently seen domains emerge as a threat vector for enterprises, and an area that is continuously overlooked in cyber security. Due to the sensitivity and importance of the U.S. election process, domain security remains a major vulnerability for the potential of foreign interference, fraud, and misinformation,” says Mark Calandra, executive vice president for CSC DBS. “As an organization with the most visibility into the domain landscape, we advocate for the sanctity of voter trust and encourage both presidential candidates and other websites in the electoral ecosystem to prioritize domain security on their websites to ensure security and build confidence.”
"We have reached the point where awareness is not enough. Those responsible for managing domain registrations, including registrars and hosting companies, need to have an actionable plan that is aligned with best practices. Additionally, experiences must be shared between those within the industry for the good of the wider internet community," said Matthew Stith, industry liaison at Spamhaus. “Without this commitment, users will be open to continued manipulation and fraud."
In April of 2020 when domain names were at the center of many COVID-19 related fraud schemes, Senators Mazie K. Hirono (D-Hawaii), Cory Booker (D-N.J.), and Maggie Hassan (D-N.H.) called on domain name registrars and hosting sites to combat scams and misinformation. CSC’s research shows that domain security and preventing domain spoofing continue to be an oversight even with top election-related web properties. Our research shows that more than 75% of these election-related domains are using retail-grade domain registrars, which do not provide advanced security protocols.
Our research also showed that, of the typo domains related to joebiden.com and donaldjtrump.com, 60% are still available for registration, thereby posing future threats. Additionally, more than a third of those presidential candidate typo domains are linked to third parties; of that one third, nearly 70%:
- Are configured to send and receive emails, which can be used to lure donors to phishing sites
- Were registered in 2020 leading up to the November election
- Disguise the owner’s identity behind proxy or privacy services
With cyber criminals subverting activities on these websites to disseminate misinformation or commit fraud against web visitors, there is also the threat of ransomware. Simon Chassar, chief revenue officer at NTT Ltd.’s Security division states, "NTT's September Monthly Threat Report identified ransomware as a significant threat to the U.S. election infrastructure. With DNS, domains, and email being a potential vehicle to distribute malicious content, our NTT Ltd. Security division suggests focus in this area, ensuring it is secure by design."
For additional details on these findings, visit the CSC blog “U.S. Election-Related Web Properties Prone to Fraud and Misinformation Due to Lack of Domain Security.”
Note: CSC aggregated this data using SimilarWeb.com for the period of August 1 – August 30, 2020.
About CSC
CSC is the trusted provider of choice for the Forbes Global 2000 and the 100 Best Global Brands® in enterprise domain names, domain name system (DNS), digital certificate management, as well as digital brand and fraud protection. As global companies make significant investments in their security posture, CSC can help them understand known security blind spots that exist and help them secure their digital assets. By leveraging CSC’s proprietary solutions, companies can get secure to protect against cyber threats to their online assets, helping them avoid devastating revenue loss, brand reputation damage, or significant financial penalties because of policies like the General Data Protection Regulation (GDPR). CSC also provides online brand protection—the combination of online brand monitoring and enforcement activities—taking a holistic approach to digital asset protection, along with fraud protection services to combat phishing. Headquartered in Wilmington, Delaware, USA, since 1899, CSC has offices throughout the United States, Canada, Europe, and the Asia-Pacific region. CSC is a global company capable of doing business wherever our clients are—and we accomplish that by employing experts in every business we serve. Visit cscdbs.com.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20201008005203/en/
Contact information
For more information:
Christine Blake
W2 Communications
703-877-8114
CSC@w2comm.com
CSC® News Room
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Outpost24 Acquires Infinipoint to Power Its Entry into the Zero Trust Workforce Access Market9.12.2025 09:00:00 EET | Press release
Outpost24, a leader in exposure management and identity security, today announced the acquisition of Infinipoint, a specialist in device identity, posture validation, and secure workforce access. The acquisition marks Outpost24’s entry into the Zero Trust Workforce Access market and enhances its identity security division, Specops, by laying the foundation for a unified approach that evaluates both the user and the device before access is granted. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251208750630/en/ Ido Erlichman, Chief Executive Officer of Outpost24. As organizations advance their Zero Trust strategies, authentication alone is no longer enough. MFA and SSO confirm who the user is, but they do not validate the security of the device being used. In hybrid environments where employees, contractors, and partners rely on a mix of corporate and unmanaged devices, this gap has become a significant source of risk. Ensuri
VSO Submits VCP v1.0 to Nineteen Regulatory Authorities Across Thirteen Jurisdictions and Completes First Integrated Evaluation in a Production-Like Environment9.12.2025 09:00:00 EET | Press release
The VeritasChain Standards Organization (VSO) announced today that it has submitted the VeritasChain Protocol (VCP) v1.0 to nineteen regulatory authorities across thirteen jurisdictions, including the United States, United Kingdom, European Union, Singapore, Hong Kong, United Arab Emirates (DIFC), Australia, India, South Korea, Switzerland, Brazil, Liechtenstein, and Saudi Arabia. The submissions present VCP v1.0 as a cryptographic audit framework designed to address emerging supervisory requirements under the EU AI Act Article 12 for logging and traceability, and MiFID II / RTS 25 for timestamp integrity and event ordering in AI-driven and algorithmic trading systems. VSO also confirmed the first completed integration of VCP v1.0 within a controlled, production-like evaluation environment operating under its Early Access Program. The environment successfully generated cryptographically linked event chains, immutable hashing, and verifiable proofs using RFC-aligned structures, demonstr
ENGIE and NHOA Energy Expand Their Partnership in Belgium to Build a New 320 MWh Battery Energy Storage System9.12.2025 09:00:00 EET | Press release
NHOA Energy, global provider of utility-scale energy storage systems, has been awarded by ENGIE the contracts for the Supply, Commissioning and the Long-Term Service of a new 80 MW / 320 MWh Battery Energy Storage System (BESS) to be installed at the site of ENGIE’s Drogenbos power station, near Brussels. The Drogenbos BESS represents ENGIE’s third large-scale battery asset in Belgium and was selected in the country’s fifth Capacity Remuneration Mechanism (CRM) auction, securing a 15-year contract starting in November 2027. Designed to deliver essential flexibility services to the Belgian grid, enabling greater integration of renewable energy and supporting grid stability at national level, the BESS will be based on NHOA Energy’s NHEXUS platform, including 88 battery containers capable of providing up to 4 hours of discharge, corresponding to the average daily electricity demand of over 38,000 households. The project marks a significant new milestone in expanding the collaboration betw
2025 Sees Double-digit Increase in Tourists' Spending via Alipay+ in South Korea as Travellers Seek More Local Experiences9.12.2025 08:55:00 EET | Press release
Alipay+, Ant International’s global wallet gateway services, revealed an 18% increase in Alipay+-supported QR code payment transactions, with total payment volume (TPV) growing 16% year-on-year in South Korea, as more tourists use Alipay+ partner wallets and bank apps to make digital payments for a range of services, from beauty clinic treatments and transportation to night market food stalls. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251208351936/en/ Weixiao Jiang, General Manager North Asia and North America, Alipay+, Ant International South Korea is among the top destinations for tourists from regions such as Southeast Asia and the Chinese mainland, with the greatest number of tourists making transactions supported by Alipay+ in cities like Seoul, Jeju Island and Busan. In 2025, Alipay+ transactions for beauty clinic treatments, transportation and F&B were among the fastest-growing categories for tourists. Apart from
Interactive Brokers Expands Market Access with United Arab Emirates Equities9.12.2025 08:00:00 EET | Press release
Interactive Brokers (Nasdaq: IBKR), an automated global electronic broker, today announced the introduction of United Arab Emirates (UAE) equities through two leading exchanges in one of the world’s fastest-growing economic regions. Clients of Interactive Brokers worldwide can now access the Abu Dhabi Securities Exchange (ADX) and the Dubai Financial Market (DFM). This enables investors in the region to trade both local and international markets from a single platform while investors worldwide can build diversified portfolios across asset classes and geographies, including countries in the growing Gulf Cooperation Council (GCC). Interactive Brokers serves a global client base and is uniquely equipped to advance the financial goals of individual and institutional investors worldwide, including those in the Middle East. Adding UAE stocks further expands Interactive Brokers’ market access and enhances the investment opportunities available to local and global investors. Interactive Broker
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
