Photo: Saul Loeb/AFP/Getty Images

The DNC walked back an assertion that it had detected a "sophisticated" hacking attempt early Thursday, announcing instead that it was simply a subcontractor's unauthorized security test.

Why it matters: While this is a slight black eye for the DNC, who look a little foolish for riling up the press over what turned out to be an internal matter, it's a massive victory for Lookout, the third-party security firm that caught the "attempt" with its unique approach to discovering phishing sites.

What actually happened:

  • The DNC uses the contractor NGP VAN to manage its digital voter operations — specifically, a product known as VoteBuilder.
  • Lookout discovered what appeared to be a newly-registered phishing site meant to look like the NGP VAN site and alerted several stakeholders.
  • After an FBI investigation, it turned out that, according to the DNC's chief security officer Bob Lord, a third party "not authorized by the DNC or its vendors" set up the site to test Democrats' resiliency to phishing attacks.
  • Michael Kan, a reporter for PCMag, determined that the unauthorized third party was the Michigan Democratic Party — technically a separate entity from the national group.
  • It's not uncommon for organizations to try to phish their own members as both an educational experience and security audit.

The tech behind the hullabaloo:

  • "Most people in security want to know why a mobile security company discovered the phishing site," Aaron Cockerill, chief strategy officer at Lookout, told Axios. "There are dedicated products to protect organizations from phishing. Lookout is not one of them."
  • Cockerill said Lookout, which protects mobile phones, got into the phishing protection buisness because phishing remains a key mobile threat. Lookout caught the site where others didn't because it uses a different apparatus than other phishing protection services.
  • Most products run checks on a site after links are sent to clients. "We call that the 'sacrificial lamb approach,'" said Cockerill. "The links won't be detected as phishing sites until someone first sees them, which may be too late for that person."
  • Lookout, on the other hand, uses AI to detect if any newly-registered sites are phishing sites. In the NGP VAN case, Cockerill said, it identified the site half an hour after it launched.

Go deeper: Inside the Democratic war against hacks.

Get more stories like this by signing up for our cybersecurity newsletter, Codebook. 

Go deeper

Joe Biden introduces Kamala Harris in first joint appearance

Joe Biden formally introduced Sen. Kamala Harris as his running mate on Wednesday, telling a socially-distanced gymnasium in Wilmington, Del.: "I have no doubt that I picked the right person to join me as the next vice president of the United States of America."

Why it matters: Harris is a historic pick for vice president, becoming the first Black woman and first South Asian woman to be named to a major-party U.S. presidential ticket. "Kamala knows how to govern," Biden said. "She knows how to make the hard calls. She is ready to do this job on day one."

Updated 49 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Annelise Capossela/Axios

  1. Global: Total confirmed cases as of 4:30 p.m. ET: 20,439,274 — Total deaths: 744,941— Total recoveries: 12,632,604Map.
  2. U.S.: Total confirmed cases as of 4:30 p.m. ET: 5,180,226 — Total deaths: 165,510 — Total recoveries: 1,714,960 — Total tests: 63,252,257Map.
  3. Politics: Pelosi says Mnuchin called her, White House is "not budging" on stimulus position.
  4. Business: U.S. already feeling effects of ending unemployment benefits.
  5. Public health: America is flying blind on its coronavirus response.
  6. Education: New Jersey governor allows schools to reopenGallup: America's confidence in public school system jumps to highest level since 2004.
Updated 2 hours ago - Politics & Policy

Pelosi says Mnuchin told her White House is "not budging" on stimulus position

Democrats and the Trump administration remain "miles apart" on negotiations over a coronavirus stimulus deal, House Speaker Nancy Pelosi (D-Calif.) said on Wednesday.

The latest: Around 3 p.m., Pelosi and Senate Minority Leader Chuck Schumer (D-N.Y.) issued a statement saying that Treasury Secretary Steven Mnuchin had initiated a phone call and made clear that the White House is "not budging from their position concerning the size and scope of a legislative package."