Use and Abuse of Personal Information -- Politics Edition

Black Hat USA 2025 · Day 1 · Briefings

Overview

Virginia Tech researchers created 1,400 fake identities and enrolled them with candidates across the 2024 U.S. election cycle — from primary through six months post-election — to systematically measure how politicians collect, use, and share personal information. They received over 34,000 phone calls, 7,000 voicemails, and hundreds of thousands of emails. Key findings: Democrats sent nearly twice as many emails as Republicans; Joe Biden averaged 10.2 emails per day per account; roughly 5% of candidates provably shared contact data with third parties; and political campaigns treat personal data as a disposable commodity rather than a privacy-protected asset. ---

Watch on YouTube

Visual summary for Use and Abuse of Personal Information -- Politics Edition
Visual summary for Use and Abuse of Personal Information -- Politics Edition

Key moments

  1. 1:59 Scale: 1,400 fake IDs signed up to 2024 US election candidates across 18 months
  2. 3:59 Surprising finding: demographic identity politics had zero effect on outreach targeting
  3. 6:00 Methodology: each fake ID used once so third-party sharing is instantly attributable
  4. 9:59 Key stat: received 34,000 calls and 7,000 voicemails; over half were scams not politics
  5. 11:00 Finding: reserved phone numbers immediately tainted by prior scammer use
  6. 11:59 Email volume: Democrats sent nearly 2x more emails than Republicans per campaign
  7. 12:59 Event-driven email spikes: Biden-Trump debate triggered same-day surge across both parties

Use and Abuse of Personal Information — Politics Edition

Speakers: Multiple researchers from Virginia Tech (led by the project PI, with co-presenter Jaron)

Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas

YouTube: Watch the full talk

Reading time: ~9 minutes

Type: Briefing

TL;DR

Virginia Tech researchers created 1,400 fake identities and enrolled them with candidates across the 2024 U.S. election cycle — from primary through six months post-election — to systematically measure how politicians collect, use, and share personal information. They received over 34,000 phone calls, 7,000 voicemails, and hundreds of thousands of emails. Key findings: Democrats sent nearly twice as many emails as Republicans; Joe Biden averaged 10.2 emails per day per account; roughly 5% of candidates provably shared contact data with third parties; and political campaigns treat personal data as a disposable commodity rather than a privacy-protected asset.

Introduction

Every election cycle, voters hand their contact details to political campaigns with little idea of what happens next. Do those campaigns share the data? Sell it? Guard it carefully? The Virginia Tech research team behind the "Use and Abuse of Personal Information" project — a five-year effort spanning 130 undergraduates from 21 majors — set out to answer these questions empirically, at scale, during the $16 billion 2024 U.S. election cycle.

Their methodology is deceptively simple: create synthetic fake identities, use each one exactly once to sign up with a political candidate, and then observe every communication that arrives. Because each identity is used only once, any email or call arriving from a party other than the original signup target proves that the data was shared. The scale — 1,400 fake IDs, 18 months of monitoring — makes this one of the most comprehensive empirical studies of political data practices ever conducted.

The talk, delivered with an opening parody of Eurythmics' "Sweet Dreams," maintains a self-consciously apolitical tone while surfacing findings that implicate both major parties.

The Methodology: 1,400 Synthetic Identities

Each fake identity is generated using a purpose-built framework that produces realistic demographic attributes — names, addresses, phone numbers — calibrated to population averages. Addresses are cross-checked against USPS records to ensure they are non-deliverable (preventing anyone from actually receiving physical mail). Phone numbers are provisioned as VoIP lines with automated webhooks to handle two-factor authentication challenges during signup.

▶ Watch: Identity generation and signup methodology (06:00)

Enrollment was handled by a team of undergraduate research assistants — typically 2-3 minutes per signup — using a custom interface that displayed the fake ID attributes for copy-paste. Because the team recorded exactly what PII was used for each enrollment, any subsequent communication can be attributed with certainty to the candidate originally given that identity.

For the 2024 election experiment, 1,400 accounts were enrolled pre-primary across candidates at the presidential, Senate, and House levels, with approximately equal numbers signed up to Democratic and Republican candidates. In some cases, multiple identities with one deliberately varied attribute (e.g., age, ZIP code, gender) were enrolled with the same candidate to test for AB-testing or demographic targeting. The result: campaigns showed no differentiation whatsoever based on demographic variables.

Phone Results: 34,000 Calls, Mostly Scams

▶ Watch: Phone data analysis (10:00)

The team received over 34,000 calls and 7,000 voicemails across their VoIP infrastructure over 18 months. The temporal distribution followed call-center patterns: Monday through Friday, 8 AM to 6 PM. The peak volume occurred in June 2024, during the primary season.

The most striking finding from the phone data: when researchers manually reviewed all voicemails, they found that only 203 were actually political in nature. More than half — over 50% — were scams. The pattern strongly suggests that phone number lists used by political campaigns are routinely shared with or sold to third-party actors, including bad actors. A simple infrastructure-level fix could eliminate nearly all of this: if telcos checked whether a called number is actually allocated to an active exchange before routing the call, roughly 99% of spam would be blocked.

Email Volume: Democrats Send Twice as Much

The email data was far richer. Democrats sent nearly twice as many emails as Republicans across equivalent signups — a pattern that held at both the presidential and Senate levels. Republicans underperformed relative to Democrats in email volume in all branches; only in the presidential independent category did another party exceed Democratic send rates.

▶ Watch: Email volume and timeline analysis (12:00)

The timeline of email sends correlated directly with campaign events. When Donald Trump won the Michigan primary, both parties spiked send volume. After the Biden-Trump debate, Democratic send volume spiked sharply the following day. In the run-up to election day, Republicans reached their single-day maximum send volume.

Joe Biden was the highest-volume sender, averaging 10.2 emails per day across enrolled accounts — a pace that would require a recipient to spend 93 hours reading Senate Democrat emails alone over the campaign duration. The researchers' conclusion: nobody is actually reading this content, making the volume economically puzzling.

What Campaigns Actually Wrote About

Rather than policy substance or issues from party platforms, email content analysis revealed that campaigns talked primarily about three things: themselves, their opponents, and donations.

▶ Watch: Content analysis and word clouds (16:01)

Democrats mentioned Donald Trump over 11,000 times in their emails. Republicans mentioned Joe Biden roughly 9,000 times. In a notable finding, Kamala Harris was mentioned less often than Joe Biden in emails from both parties — even from Democratic campaigns — and Democrats mentioned RFK Jr. more than they mentioned Harris. The researchers interpret this as evidence that the 2024 election was, in content terms, a "cult of personality" contest organized around Donald Trump.

Security-related keywords were almost absent. Despite the researchers' decade-long attendance at Black Hat, they searched for "CISO," "cyber," and related terms across the entire corpus. The result: political campaigns discussed cybersecurity less than they discussed UFOs.

The most prominent keyword shared across both parties was NATO, mentioned 7,184 times in 4,367 emails. But the single most important word in terms of campaign priority was donate, mentioned more than NATO, more than any policy issue, and more than any candidate name other than Trump.

PII Sharing: 5% Provably Shared, and the Worst Cases

The team's core finding on data sharing: roughly 5% of candidates provably shared personal information with third parties. Because each identity was used only once, any email from a non-enrolled sender is direct proof of sharing.

▶ Watch: Sharing analysis (26:01)

The top three sharers were Joe Biden, Adam Schiff, and Kim Klasek:

  • Biden: Because the team enrolled in Biden's campaign but not Harris's, the over-1,000 emails they received from the Harris campaign — after Biden dropped out — demonstrate that the Biden campaign's entire email list was transferred to Harris. The transition was seamless; joebiden.com now forwards to her website.
  • Adam Schiff: Shared with three other California Democratic politicians, an abortion advocacy group, and a Democrat in Maryland.
  • Kim Klasek: Exposed her entire email list by sending a reply-all email, including a response from a Baltimore martial arts studio. Emails to enrolled Klasek accounts also included messages from domains flagged as malware and one claiming to be from a foreign government.

One Arizona candidate, Mark Lamb (a county sheriff), was the source of the only foreign-domain email in the entire dataset — an advertisement for Japanese insoles — along with six additional senders, three of which registered as malware in threat intelligence databases.

A notable operational security failure: one candidate, John Lencioni, identified the research team within 24 hours of enrollment. He traced the signup IP address to Blacksburg, Virginia, performed his own OSINT, identified the lead researcher by name, and sent a direct email. He appears to have been a former NSA contractor.

Notable Quotes

"Short answer: they care less about the aggregate of all cyber than they do UFOs."

— Presenter, on searching for cybersecurity keywords in campaign emails [[▶ 18:01]](https://www.youtube.com/watch?v=Lf2k8QPEPqs&t=1081s)

"The real takeaway here is nobody's actually reading the content, so to some degree, I don't know why they're sending it so many times."

— Jaron, co-presenter [[▶ 14:01]](https://www.youtube.com/watch?v=Lf2k8QPEPqs&t=841s)

"Sharing is probably to be expected. The five percent I've told you about — those are only the ones that I can concretely prove."

— Presenter [[▶ 32:02]](https://www.youtube.com/watch?v=Lf2k8QPEPqs&t=1922s)

"Eighty-five percent of the candidates that shared [data] lost their races."

— Presenter [[▶ 28:01]](https://www.youtube.com/watch?v=Lf2k8QPEPqs&t=1681s)

Key Takeaways

  • Political campaigns treat PII as a disposable asset. Roughly 5% provably shared data — and 85% of those sharers lost their races, suggesting it may correlate with poor campaign discipline generally.
  • Donating makes you a significantly bigger target. Enrolled identities that made $5 FEC-compliant donations received markedly more contact than non-donors, in a measurable and statistically provable pattern.
  • Campaign emails are almost entirely about fundraising, not issues. "Donate" was the single most important keyword; policy issues from party platforms barely registered. Security professionals should have near-zero expectation that politicians read or respond to cybersecurity messaging sent through campaign channels.
  • Phone spam from political sources is predominantly non-political. More than half of the voicemails received were scams, pointing to systematic leakage of campaign phone lists to bad actors.
  • Active OSINT carries real re-identification risk. By enrolling with a real IP and interacting with campaign websites, the researchers were identifiable — one candidate's staff found them within 24 hours. Privacy researchers and red teamers conducting similar work should use clean infrastructure.

Slides PDF not available for this talk.

Reviews

Dr. Zero (Offensive Security Researcher) — ACCEPTABLE

Virginia Tech ran a legitimately clever empirical study — 1,400 fake identities, 18 months, 34,000 calls — and the data on PII sharing and phone spam is genuinely interesting. But this is a privacy research paper pretending to be a security talk, and Black Hat is an odd venue for finding that 'donate' is the most important word in campaign emails.

Heather Calloway (CISO) — SOLID

Political campaigns treat voter personal data as a disposable commodity — this research proves it systematically, at scale, over 18 months. The phone data finding about voicemails being over 50% scams tells the real story about what happens to contact data after a political signup.

→ Top-rated talks at Black Hat USA 2025

All talks from Black Hat USA 2025