Back to news
Cybersecurity Alert
July 30, 2026 by EmailMeNow IT Consulting

DNC Lost Nearly $29,000 to Email Scammer Posing as Chair Ken Martin

NOTUS reports a February 2025 email scammer posing as DNC Chair Ken Martin stole $28,860.92; only $7,000 recovered via Wells Fargo. Domain audits (ideal 100%): fec.gov 85%, gop.com 77%, democrats.org 68%; dems.org just 32% — none at 100%.

Source: NOTUS

NewsBusiness Email CompromisePolitical CommitteesCEO FraudWire FraudFECCybersecurity
Political finance desk with a suspicious urgent payment email and bank transfer confirmation

A thief scammed the cash-strapped Democratic National Committee out of nearly $29,000 last year — $28,860.92 on the FEC schedule — according to NOTUS interviews with committee officials and previously unreported federal records (July 28, 2026).

In February 2025, days after Ken Martin became DNC chair (February 1), an unknown party emailed a staffer pretending to be Martin. The staffer paid the fraudster. The committee says it caught the error within minutes, alerted Wells Fargo, and recovered only $7,000. Net loss: about $21,861. The staffer is no longer at the DNC. Law enforcement was notified. In an August 2025 letter to the FEC, the committee called it a “misdisbursement … [from] fraudulent activity by an external third party” and said it would take “further steps to avoid similar events.”

Political finance desk with a suspicious urgent payment email and bank transfer confirmation

Snapshot

FieldDetail
VictimDemocratic National Committee (DNC Services Corp.)
Fraud typeExecutive impersonation / BEC-style payment request by email
ImpersonatedChair Ken Martin (tenure began Feb 1, 2025)
WhenFebruary 2025 (days into Martin’s chairmanship)
Disbursement$28,860.92 (“Misdisbursement—seeking return of funds”)
Recovered$7,000 via bank (Wells Fargo, per federal records)
Net loss~$21,861
DetectionCommittee says caught within minutes
StafferNo longer at the DNC
Regulators / LEFEC correspondence (Jul–Aug 2025); law enforcement notified
Cash context (thru Jun 30)DNC ~$16.3M cash vs ~$18.5M debt; RNC ~$128.5M cash, $0 debt (FEC / NOTUS)

How the scam worked

Public reporting describes a classic authority-pressure payment fraud — not a disclosed ransomware or database breach:

StepWhat happened
1. Leadership changeMartin becomes chair Feb 1, 2025 — staff still learning his voice and habits
2. Spoofed requestFraudulent email pretends to be the chair asking a staffer to pay
3. Payment sentStaffer disburses $28,860.92 to the fraudster
4. Fast catchCommittee spots the error within minutes; notifies bank
5. Partial clawbackOnly $7,000 recovered — most funds already moved
6. DisclosureFEC asks about the Schedule B line; DNC replies Aug 2025 citing external fraud

Reporting does not publish the exact spoof technique (lookalike domain vs display-name spoof vs compromised mailbox). Treat that as unknown — the operational failure is the same: an urgent payment from “the boss” without a verified out-of-band callback.

Authority chain with one forged executive-email link enabling a fraudulent payment

Money, recovery, and why minutes still lose cash

AmountRole
$28,860.92Gross misdisbursement on FEC Schedule B
$7,000Recovered after bank notice
~$21,861Still gone

Banks can freeze or claw back only what has not already left the first hop. “Caught in minutes” is necessary — and often not enough once ACH/wire clears. Same lesson as Surfside Beach: speed helps; prevention (callback + dual control) stops the send.

Partial bank recovery after a fraudulent political-committee payment

Political committees are repeat targets

NOTUS notes this is one of many committee thefts this decade — cybertheft, mail fraud, and embezzlement across parties. Examples cited in that reporting:

Committee / campaign (per NOTUS)Reported loss / note
RNC (2020)$44,000 to fraudsters (coffee / agricultural shopping spree)
Multiple Senate / House campaignsThefts hitting both parties (Thune, Schumer, Warner, Kaine, Booker, AOC, Mike Johnson, and others named)
Mike Rogers (MI Senate, per NOTUS)$16,700 campaign cash to suspected cyberthief

Cash-strapped committees feel small losses harder. Through June 30, NOTUS cites DNC cash under debt while the RNC held a large surplus — context for why a ~$22K net hit still stings mid-cycle.

Independent cybersecurity audits

EmailMeNow domain audits on July 30, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — they do not prove whether the February email used a lookalike of democrats.org.

Organization / roleDomainOverallIdentityTransportWebsiteRisk
Federal Election Commissionfec.gov85%90%45%90%Strong
GOPgop.com77%75%15%89%Good
DNC alternatednc.org69%90%40%37%Above Average
Democratic National Committeedemocrats.org68%90%15%37%Above Average
Republican National Committeernc.org68%50%15%90%Above Average
Wells Fargo (recovery bank)wellsfargo.com67%50%15%87%Above Average
NOTUS (reporting)notus.org52%50%15%37%Average
Dems short domaindems.org32%0%15%40%Weak

Audit links: fec.gov · gop.com · dnc.org · democrats.org · rnc.org · wellsfargo.com · notus.org · dems.org

Pattern: Primary party brands score mid-to-high on identity (democrats.org / dnc.org at 90%) but transport is soft — 15% on democrats.org, rnc.org, gop.com, and wellsfargo.com. The short brand dems.org is the outlier: 32% overall, 0% identity — a weak public posture for any domain that could appear in donor or staff mail threads. FEC leads at 85%, still 15 points under the 100% ideal.

Website stack note

Passive website-tech probes on July 30, 2026 covered all eight domains (8 probed, 0 notable). democrats.org and dnc.org fingerprint as WordPress; no outdated CMS / PHP / short-horizon TLS alerts stood out in this pass. The story risk is payment-approval process + executive impersonation, not a public WordPress-core headline.

Cybersquat / lookalike scan

DoH lookalike scans on July 30, 2026 (registered-only; BEC profile on party brands):

Brand domainCheckedTo reviewBEC stagingHighlights
democrats.org182191democats.org — omission with MX (BEC staging); also democrat.org, democrats.com, demorats.org, …
dnc.org85612Short label → noisy set; dinc.org, dnc.cloud flagged BEC staging (NS+MX)
dems.org104572deams.org, eems.org BEC staging; many registered near-misses
rnc.org82603rnc.cloud, rnci.org, rnco.org BEC staging
gop.com66471gol.com BEC staging among many TLD/near swaps
notus.org91273notu.org, notue.org, notus.info BEC staging; notus.com redirects to brand

Party brands sit in a crowded lookalike space. Even if February’s email used a simple display-name spoof, live-MX near-misses like democats.org are exactly the infrastructure used for the next “chair needs a payment” lure — same class of risk as Surfside Beach.

Priority actions

  1. Committees / campaigns: Dual control on any payment change or new payee; phone callback on a known number for chair/ED/treasurer requests — especially in the first weeks of a leadership transition.
  2. IT / MSPs: Enforce DMARC on every public brand domain (democrats.org, dnc.org, and soft short domains like dems.org); monitor lookalikes with MX.
  3. Finance: Treat “caught in minutes” as recovery, not success — measure success as wires never sent.
  4. Insurance / counsel: Align social-engineering / funds-transfer coverage with how committees actually pay (Seventh Circuit BEC denial; Surfside municipal gaps).

Sources: NOTUS — Dave Levinthal (Jul 28, 2026) · New Republic · Mediaite. Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans July 30, 2026. Domain scores: audit.emailmenow.com only — not a determination of how the February email was forged.