Skip to content

Iran 2024 U.S. Hack-and-Leak Campaign

APT42 2024 election targeting · IRGC 2024 hack-and-leak

Google documented IRGC-associated APT42 phishing against people affiliated with both 2024 U.S. presidential campaigns. A federal indictment separately alleges that three IRGC employees compromised accounts associated with Donald Trump's campaign, stole campaign material and tried to release it through journalists and people associated with the opposing campaign.

This record separates observed platform findings from criminal allegations. Google confirmed and disrupted credential-phishing attempts, including unsuccessful attempts against people affiliated with President Biden, Vice President Harris and former President Trump. The document theft and attempted leak are allegations in an indictment and are not presented as adjudicated facts. Neither source says voting or tabulation systems were compromised or that any vote total changed.

Elections

People

Actors

Evidence Library

IndictmentU.S. Department of JusticeSeptember 27, 2024
Three IRGC cyber actors indicted for alleged 2024 U.S. election hack-and-leak operation
OriginalArchive pending
Platform reportGoogle Threat Analysis GroupAugust 14, 2024
Iranian-backed group steps up phishing campaigns against Israel and the U.S.
OriginalArchive pending

Share links open the network’s own composer. Nothing is embedded here, so no third party learns which pages you read.