Sotera Digital Security | Blog | Mobile Security

Secure Phones for Political Campaigns: Why the Candidate Isn't the Only Target

Written by Sotera Digital Security | Jul 22, 2026 4:21:31 PM

From now until the end of 2027, more than 15 countries will hold direct presidential elections.1 Each one puts campaign staff and candidates' devices squarely in the crosshairs of foreign intelligence services, political rivals, and opportunistic attackers alike. Most campaigns think about security as protecting the candidate. The evidence from the last several election cycles says that's the wrong unit of protection.

The Entry Point Isn't Who You'd Expect

Attackers don't target campaigns by going after whoever holds the most power. They go after whoever has access — and on a campaign, that's rarely just the candidate. Campaign managers and communications directors routinely carry the same sensitive material as the candidate: strategy documents, opposition research, unreleased polling, donor communications. A phone belonging to a senior staffer can be just as valuable to an attacker as one belonging to the candidate, and it's often less scrutinized.

That's the case for securing the small circle around the candidate, not just the candidate's own device. A single hardened phone at the top of the org chart doesn't close the gap if the people who see the same material are working from consumer-grade security.

Three Campaigns, One Pattern

The last decade of election cycles offers a consistent playbook, confined to no single country or ideology.

Poland, 2019. Senator Krzysztof Brejza, who was running the opposition's national campaign, had his phone compromised with Pegasus spyware 33 times over the course of the race. Stolen personal data later surfaced on state television as a compilation of doctored text messages, timed to air just before the vote.

Spain, 2021. At least 65 people connected to the Catalan separatist movement — including elected officials — were infected with Pegasus and Candiru spyware between 2017 and 2020. The scandal didn't stay contained to one side of the political spectrum: Spain's own prime minister and defense minister later had their phones breached by Pegasus as well.

Mexico, 2018–2022. Phone numbers tied to Morena party members, including Claudia Sheinbaum — then mayor of Mexico City, now the country's president — appeared in leaked Pegasus targeting data. A sitting opposition lawmaker, Agustín Basave Alanís, was confirmed infected in 2021, years after the government had publicly claimed the practice had stopped.

Three countries, three different political contexts, one throughline: campaign devices are treated as high-value intelligence targets regardless of party, ideology, or incumbency.

The Leak Is the Point

In both the Poland and Spain cases, stolen material didn't sit in an intelligence file — it surfaced publicly, timed for maximum political effect. When espionage is paired with a leak timed to the news cycle, the operation isn't just gathering intelligence; it's shaping an election outcome. Securing campaign devices isn't only about privacy. It's about denying an adversary the raw material for an information operation.

A Third Phone for the Inner Circle

Because senior staff — not just the candidate — have access to a campaign's most damaging material, device security can't stop at a single hardened phone for the person on the ballot. The practical approach isn't a phone for everyone on staff; it's a device for whoever regularly touches the material that would do the most damage if it leaked — typically the candidate, the campaign manager, and the communications director. Most people in this small group are already carrying two phones: personal and work. Sotera recommends a third — not a replacement for either, but a dedicated channel reserved for a campaign's most sensitive conversations.

This is a practice known as device segmentation: separating high-sensitivity communications onto a purpose-built device with a deliberately reduced attack surface, while routine business continues on the tools staff already use. Day-to-day scheduling, press outreach, and general coordination stay on commercial phones and encrypted messaging apps. The secure device is reserved for what would do the most damage if it leaked, such as the candidate's real-time schedule and movements, opposition research before it's ready to deploy, debate prep, and surprise endorsements still under wraps.

The Sotera SecurePhone is built for that narrow job: a hardened device architecture closing off the kind of device-level compromise seen in the Pegasus and Candiru cases above, with encrypted calling and messaging built in rather than layered on a consumer OS. The reduced attack surface isn't abstract — there's no app installation capability, no email client, and no support for third-party messaging apps; the device runs only its own proprietary encrypted applications. Camera, Wi-Fi, and Bluetooth hardware are disabled at the firmware level. None of that is a limitation for what this device is for: a small number of people and a narrow set of conversations.

The logic is the same one intelligence and defense organizations have used for years: the fewer sensitive conversations that touch a general-purpose device, the smaller the target that device presents.

Talk to Us Before Your Next Cycle Starts

If your campaign is heading into a contested race, now is the time to talk to Sotera about securing your inner circle's communications.

1: Count includes direct presidential elections in UN member states, August 2026–December 2027; excludes indirect parliamentary selections and unrecognized states.