Arizona Agencies Targeted in Phishing Campaign

Threat actors registered fraudulent domains to impersonate officials across Arizona and Maricopa County.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of a structured lattice grid compromised by a sharp, angular geometric intrusion.
Arizona and Maricopa County authorities have issued a warning regarding a phishing campaign utilizing fraudulent domains to impersonate government agency officials. AI Illustration. Upload story photo >

Live Poll

Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?

State and county authorities have issued a warning regarding a phishing campaign utilizing deceptive .us domains. Attackers are currently impersonating various agency administrators and managers.

Why it matters

The impersonation of government officials poses a significant security risk by attempting to gain sensitive information through illegitimate communications. Officials have identified specific domains being used to deceive employees and the public.

Threat actors registered .us domains such as az-doa.us and Maricopa-az.us to masquerade as legitimate government entities. These fraudulent domains were specifically designed to mimic the digital presence of state and county administrators.

The players

Arizona Procurement Portal

This state entity serves as the official hub for government contracting and issued the warning regarding the phishing campaign.

The details

The campaign utilizes lookalike domains to bypass initial scrutiny and pose as agency managers. The Arizona Procurement Portal has officially alerted stakeholders to this activity to prevent further fraudulent interactions.

Timeline

  1. October 3, 2026: The Arizona Procurement Portal issued a formal warning regarding the ongoing phishing campaign.

The Tech Race

This campaign leverages the .us domain registry to create a false sense of institutional legitimacy, highlighting a persistent vulnerability in government digital communications. It follows a pattern where attackers exploit national domain structures to mirror official agency digital ecosystems.

Residents and contractors should be hyper-vigilant when receiving emails from domains ending in .us that claim to be from government offices. Verifying the sender address against official channels is essential to avoiding potential data theft or fraud.

The takeaway

Phishing remains a primary threat to government operations through the simple but effective tactic of domain spoofing. Always confirm the authenticity of official requests by visiting verified government portals directly rather than clicking links in unsolicited emails.

Further reading

For more information on current regional threats, visit the Cybersecurity section.

More information

To report suspicious activity to state authorities, report suspicious activity to state authorities.

Source note: This article includes information reported by Your Valley.

Live Poll

Do you find it increasingly difficult to distinguish between official government communications and fraudulent phishing attempts?