A new listing on a cybercrime forum claims that a threat actor has obtained recent voter information associated with Iraq’s Independent High Electoral Commission (IHEC).
According to the threat actor, the dataset contains 2026 electoral information and is different from previously circulated Iraqi voter databases. Samples published with the listing reportedly show structured voter-registration records.
The alleged information may include:
- Full names and mothers’ names
- Dates of birth
- Voter card and family numbers
- Phone numbers
- Governorates, cities and districts
- Polling center numbers and registered school information
- Biometric registration status
- Voter-card issuance and receipt information
- Other indicators related to voter-card registration
Why This Could Be Serious
The main concern is not any single piece of information, but the combination of multiple personal and electoral details.
Cybercriminals can also combine information from a new leak with older databases obtained from previous breaches, telecom services, social media, or other sources. This process can create a much more detailed digital profile of an individual.
Such information could make targeted scams and social-engineering attacks more convincing. An attacker could, for example, pretend to be a government or election official and use real information about a person to gain their trust before requesting additional information, an OTP, or directing them to a malicious link.
Although the incident concerns Iraq, it provides an important lesson for the wider region. The protection of national databases containing citizens’ identity information is not only a national security responsibility; it is an important part of protecting individuals and societies from fraud and cybercrime.
Important Verification Note
The claim that the dataset is new, exclusive, and specifically contains 2026 information has not been independently verified. Its source, completeness, number of records, and freshness remain unclear.
The claimed date is also important because newer personal data can have greater value in criminal markets. Threat actors may sometimes exaggerate the freshness of information or repackage older datasets to increase their perceived value during private negotiations.
In addition, references to biometric information should not automatically be interpreted as the theft of actual fingerprints or biometric templates. Based on the published description, the information may refer to registration status or indicators associated with voter cards.
What Individuals Should Do
People should remain cautious about unexpected calls, messages, or emails that use personal information to appear legitimate.
Individuals should:
- Avoid trusting someone simply because they know personal information about them.
- Never share passwords, OTPs, or additional sensitive information with an unsolicited caller or message.
- Avoid clicking links asking them to verify voter or personal information.
- Verify government or election-related communications through official channels that they locate independently.
A data leak does not necessarily mean that an individual’s account has been compromised. However, the more information criminals have about a person, the easier it can become to make a future scam appear legitimate.
