A thief scammed the cash-strapped Democratic National Committee out of nearly $29,000 last year — $28,860.92 on the FEC schedule — according to NOTUS interviews with committee officials and previously unreported federal records (July 28, 2026).
In February 2025, days after Ken Martin became DNC chair (February 1), an unknown party emailed a staffer pretending to be Martin. The staffer paid the fraudster. The committee says it caught the error within minutes, alerted Wells Fargo, and recovered only $7,000. Net loss: about $21,861. The staffer is no longer at the DNC. Law enforcement was notified. In an August 2025 letter to the FEC, the committee called it a “misdisbursement … [from] fraudulent activity by an external third party” and said it would take “further steps to avoid similar events.”

Snapshot
| Field | Detail |
|---|---|
| Victim | Democratic National Committee (DNC Services Corp.) |
| Fraud type | Executive impersonation / BEC-style payment request by email |
| Impersonated | Chair Ken Martin (tenure began Feb 1, 2025) |
| When | February 2025 (days into Martin’s chairmanship) |
| Disbursement | $28,860.92 (“Misdisbursement—seeking return of funds”) |
| Recovered | $7,000 via bank (Wells Fargo, per federal records) |
| Net loss | ~$21,861 |
| Detection | Committee says caught within minutes |
| Staffer | No longer at the DNC |
| Regulators / LE | FEC correspondence (Jul–Aug 2025); law enforcement notified |
| Cash context (thru Jun 30) | DNC ~$16.3M cash vs ~$18.5M debt; RNC ~$128.5M cash, $0 debt (FEC / NOTUS) |
How the scam worked
Public reporting describes a classic authority-pressure payment fraud — not a disclosed ransomware or database breach:
| Step | What happened |
|---|---|
| 1. Leadership change | Martin becomes chair Feb 1, 2025 — staff still learning his voice and habits |
| 2. Spoofed request | Fraudulent email pretends to be the chair asking a staffer to pay |
| 3. Payment sent | Staffer disburses $28,860.92 to the fraudster |
| 4. Fast catch | Committee spots the error within minutes; notifies bank |
| 5. Partial clawback | Only $7,000 recovered — most funds already moved |
| 6. Disclosure | FEC asks about the Schedule B line; DNC replies Aug 2025 citing external fraud |
Reporting does not publish the exact spoof technique (lookalike domain vs display-name spoof vs compromised mailbox). Treat that as unknown — the operational failure is the same: an urgent payment from “the boss” without a verified out-of-band callback.

Money, recovery, and why minutes still lose cash
| Amount | Role |
|---|---|
| $28,860.92 | Gross misdisbursement on FEC Schedule B |
| $7,000 | Recovered after bank notice |
| ~$21,861 | Still gone |
Banks can freeze or claw back only what has not already left the first hop. “Caught in minutes” is necessary — and often not enough once ACH/wire clears. Same lesson as Surfside Beach: speed helps; prevention (callback + dual control) stops the send.

Political committees are repeat targets
NOTUS notes this is one of many committee thefts this decade — cybertheft, mail fraud, and embezzlement across parties. Examples cited in that reporting:
| Committee / campaign (per NOTUS) | Reported loss / note |
|---|---|
| RNC (2020) | $44,000 to fraudsters (coffee / agricultural shopping spree) |
| Multiple Senate / House campaigns | Thefts hitting both parties (Thune, Schumer, Warner, Kaine, Booker, AOC, Mike Johnson, and others named) |
| Mike Rogers (MI Senate, per NOTUS) | $16,700 campaign cash to suspected cyberthief |
Cash-strapped committees feel small losses harder. Through June 30, NOTUS cites DNC cash under debt while the RNC held a large surplus — context for why a ~$22K net hit still stings mid-cycle.
Independent cybersecurity audits
EmailMeNow domain audits on July 30, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — they do not prove whether the February email used a lookalike of democrats.org.
| Organization / role | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Federal Election Commission | fec.gov | 85% | 90% | 45% | 90% | Strong |
| GOP | gop.com | 77% | 75% | 15% | 89% | Good |
| DNC alternate | dnc.org | 69% | 90% | 40% | 37% | Above Average |
| Democratic National Committee | democrats.org | 68% | 90% | 15% | 37% | Above Average |
| Republican National Committee | rnc.org | 68% | 50% | 15% | 90% | Above Average |
| Wells Fargo (recovery bank) | wellsfargo.com | 67% | 50% | 15% | 87% | Above Average |
| NOTUS (reporting) | notus.org | 52% | 50% | 15% | 37% | Average |
| Dems short domain | dems.org | 32% | 0% | 15% | 40% | Weak |
Audit links: fec.gov · gop.com · dnc.org · democrats.org · rnc.org · wellsfargo.com · notus.org · dems.org
Pattern: Primary party brands score mid-to-high on identity (democrats.org / dnc.org at 90%) but transport is soft — 15% on democrats.org, rnc.org, gop.com, and wellsfargo.com. The short brand dems.org is the outlier: 32% overall, 0% identity — a weak public posture for any domain that could appear in donor or staff mail threads. FEC leads at 85%, still 15 points under the 100% ideal.
Website stack note
Passive website-tech probes on July 30, 2026 covered all eight domains (8 probed, 0 notable). democrats.org and dnc.org fingerprint as WordPress; no outdated CMS / PHP / short-horizon TLS alerts stood out in this pass. The story risk is payment-approval process + executive impersonation, not a public WordPress-core headline.
Cybersquat / lookalike scan
DoH lookalike scans on July 30, 2026 (registered-only; BEC profile on party brands):
| Brand domain | Checked | To review | BEC staging | Highlights |
|---|---|---|---|---|
democrats.org | 182 | 19 | 1 | democats.org — omission with MX (BEC staging); also democrat.org, democrats.com, demorats.org, … |
dnc.org | 85 | 61 | 2 | Short label → noisy set; dinc.org, dnc.cloud flagged BEC staging (NS+MX) |
dems.org | 104 | 57 | 2 | deams.org, eems.org BEC staging; many registered near-misses |
rnc.org | 82 | 60 | 3 | rnc.cloud, rnci.org, rnco.org BEC staging |
gop.com | 66 | 47 | 1 | gol.com BEC staging among many TLD/near swaps |
notus.org | 91 | 27 | 3 | notu.org, notue.org, notus.info BEC staging; notus.com redirects to brand |
Party brands sit in a crowded lookalike space. Even if February’s email used a simple display-name spoof, live-MX near-misses like democats.org are exactly the infrastructure used for the next “chair needs a payment” lure — same class of risk as Surfside Beach.
Priority actions
- Committees / campaigns: Dual control on any payment change or new payee; phone callback on a known number for chair/ED/treasurer requests — especially in the first weeks of a leadership transition.
- IT / MSPs: Enforce DMARC on every public brand domain (
democrats.org,dnc.org, and soft short domains likedems.org); monitor lookalikes with MX. - Finance: Treat “caught in minutes” as recovery, not success — measure success as wires never sent.
- Insurance / counsel: Align social-engineering / funds-transfer coverage with how committees actually pay (Seventh Circuit BEC denial; Surfside municipal gaps).
Related trackers
- Surfside Beach municipal BEC + lookalike domains
- Seventh Circuit: no coverage for OSD BEC wires
- Cyber insurance controls vs claim denials
- Hotel Wi-Fi DNS hijack → Microsoft 365
Sources: NOTUS — Dave Levinthal (Jul 28, 2026) · New Republic · Mediaite. Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans July 30, 2026. Domain scores: audit.emailmenow.com only — not a determination of how the February email was forged.