Arizona Secretary of State Adrian Fontes used a federal election security briefing Monday to publicly berate the Trump administration’s cybersecurity agency, telling officials “I don’t trust you.” But Fontes’s own handling of a real cyberattack on his office last year—one he chose not to report to that same agency—raises questions about who’s actually failing to hold up their end of election security.
On the call hosted by the Cybersecurity and Infrastructure Security Agency (CISA), Fontes told acting Director Nick Andersen and Assistant Director Jim Harrell: “I don’t trust you. Your boss came out there and said: We are going to criminalize the work you do. Why should we trust you?” He later told reporters CISA had “wholly and completely abandoned their duties,” and accused the agency of working “against” the states it’s supposed to serve.
CISA officials used the briefing to walk state election offices through federal expectations ahead of November, according to participants — an approach some Democratic secretaries characterized as too general for their liking. Washington’s Steve Hobbs struck a notably different tone than Fontes, calling it “a positive step” and asking for continued engagement rather than confrontation.
Homeland Security Secretary Markwayne Mullin has said states seeking federal homeland-security dollars need to actually meet the administration’s security standards to get them—a basic accountability condition that Fontes and allied Democratic secretaries have cast as a “threat.” DHS attached election-related conditions to three FEMA homeland-security/anti-terrorism grant programs not originally designed for election security, with 20% of awards withheld pending compliance. Mullin’s department has also pushed back on the Biden-era arrangement under which CISA’s previous director, Chris Krebs, publicly contradicted election-integrity concerns before the administration pushed him out; Krebs remains under review for his conduct in that role.
Fontes’s outrage is harder to square with his own record. Last summer, a suspected Iranian hack replaced candidate photos on Arizona’s campaign portal with images of Ayatollah Khomeini—a genuine cyberattack on state election infrastructure. Fontes didn’t report it to CISA. Asked why, he said he considered the agency “politicized” and didn’t want the incident “politicized” further. Arizona said it was “moderately confident” Iran participated the attack His office also took eight days after discovering the breach to take the compromised portal offline, a delay state Rep. John Gillette, a Republican, turned into a formal complaint alleging Fontes had violated federal election-security reporting requirements.
Fontes’s Republican challenger in November, state Sen. Alex Kolodin, has argued for the past year that Fontes’s cybersecurity complaints are less about protecting elections than about building leverage. “Radical leftist Adrian Fontes is exploiting a cyberattack — using it as a pretext to rig future elections in Democrats’ favor,” Kolodin said after last year’s breach, calling on lawmakers to withhold funding from Fontes’s office. Kolodin has made Fontes’s cybersecurity record a central plank of his campaign since clinching the GOP nomination in July. Arizona Globe contacted him for a comment on Monday’s CISA call, but has yet to receive a response.
Seen against that backdrop, Monday’s confrontation looks less like a state going it alone against an indifferent federal government and more like a secretary of state who already declined federal help once, now complaining that the same federal government isn’t giving him a blank check. With Election Day less than 90 days away, voters will decide in November whether Fontes or Kolodin should be the one answering CISA’s calls.
- Fontes Blasts Federal Election Agency–After Downplaying a Real Cyberattack - August 18, 2026
- Lake Mead’s New Low Makes AZ First for Colorado River Cuts - August 13, 2026
- CAMPAIGN PREVIEW: Fontes, Kolodin Frame SOS Race as Election Trust Battle - August 12, 2026