Arizona Agencies Targeted in Phishing Campaign
Threat actors registered fraudulent domains to impersonate officials across Arizona and Maricopa County.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?
State and county authorities have issued a warning regarding a phishing campaign utilizing deceptive .us domains. Attackers are currently impersonating various agency administrators and managers.
Why it matters
The impersonation of government officials poses a significant security risk by attempting to gain sensitive information through illegitimate communications. Officials have identified specific domains being used to deceive employees and the public.
Threat actors registered .us domains such as az-doa.us and Maricopa-az.us to masquerade as legitimate government entities. These fraudulent domains were specifically designed to mimic the digital presence of state and county administrators.
The players
Arizona Procurement Portal
This state entity serves as the official hub for government contracting and issued the warning regarding the phishing campaign.
The details
The campaign utilizes lookalike domains to bypass initial scrutiny and pose as agency managers. The Arizona Procurement Portal has officially alerted stakeholders to this activity to prevent further fraudulent interactions.
Timeline
October 3, 2026: The Arizona Procurement Portal issued a formal warning regarding the ongoing phishing campaign.
The Tech Race
This campaign leverages the .us domain registry to create a false sense of institutional legitimacy, highlighting a persistent vulnerability in government digital communications. It follows a pattern where attackers exploit national domain structures to mirror official agency digital ecosystems.
Residents and contractors should be hyper-vigilant when receiving emails from domains ending in .us that claim to be from government offices. Verifying the sender address against official channels is essential to avoiding potential data theft or fraud.
The takeaway
Phishing remains a primary threat to government operations through the simple but effective tactic of domain spoofing. Always confirm the authenticity of official requests by visiting verified government portals directly rather than clicking links in unsolicited emails.
Further reading
For more information on current regional threats, visit the Cybersecurity section.
More information
To report suspicious activity to state authorities, report suspicious activity to state authorities.
Source note: This article includes information reported by Your Valley.
Live Poll
Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?










