In 2023, a U.S. Senate campaign sold its donor list to six different buyers at six different prices. When the discrepancy became public, the campaign couldn’t answer a simple question: who actually bought this political data, and what are they doing with it?
Table of Contents
That’s not just a one-off scandal; political data passes through dozens of vendors and brokers every week, and most organizations manage that massive asset with little more than “trust.”
We’ve talked with people who handle political data about how their process works, and what we’ve found is that it’s not systematic.
The List is the Business
For firms that manage many billions of dollars in political contributions every cycle, a client’s donor list is the lifeblood of the campaign. It’s the single most valuable asset an organization has and one of its biggest exposures.
Organizations should be planting staff names as “seed” or “decoy” contacts inside any list they trade or rent, specifically so they can catch misuse. That’s a real, still-active practice, and it’s usually a manual, spreadsheet-based version of what modern data-seeding technology (this is what we build at Assumed) now does automatically, continuously and at scale.
If you’re involved in for-profit vendors (CRMs, voter file co-ops, list brokers, fundraising platforms) or the nonprofits, PACs and campaigns that depend on them, here are some problems that are about to get a lot easier to solve:
FEC and watchdog scrutiny. Dozens of campaigns and parties have sold political data as a fundraising tactic, sometimes triggering “cannibalization” by other political groups looking to poach the same donors.
Donor privacy expectations are rising. The Supreme Court and more than a dozen states have affirmed donor privacy protections, and high-profile nonprofit data exposures have shown how quickly a leak can escalate into a federal matter.
Manual tools that don’t scale. The seed-name approach nonprofits already use has no real-time alerting, no automatic refresh, and depends on someone remembering to check whether a decoy contact was ever contacted.
Trust gaps as platforms change hands. When dominant CRM platforms are acquired or restructured, campaigns often have no independent way to confirm their political data isn’t being repurposed by the new owner.
Nonprofit and campaign firewalls. Crossing the data-sharing wall between affiliated 501(c)(3) and (c)(4) organizations risks immediate loss of tax-exempt status, a rule that’s easy to state and hard to prove compliance with after the fact.
Fundraising platform scrutiny. The largest fundraising processing platforms continue to face public scrutiny over their financial and data-handling practices; scale alone doesn’t earn trust.
Every one of these has historically been a fear: fear of the headline, fear of the subpoena, fear of the donor who quietly stops giving because they no longer trust you with their information. But fear is just an unmet need wearing a scary mask. Each one of these is solvable, and the organizations that solve it first get to compete on trust instead of just hoping it holds.
What Political Data Seeding Actually Changes
This is where the seed-name instinct, automated and made rigorous, really earns its keep. The core idea is simple: plant realistic, monitored decoy contacts inside a list before it moves anywhere before a merge/purge job, before it’s rented to a broker, before it’s shared with a coalition partner, before it crosses a 501(c)(3)/(c)(4) firewall. Each decoy is unique to that specific hand-off. If it’s ever contacted somewhere it shouldn’t be, you know instantly, with a timestamp, exactly which transaction and which party is responsible.
That single capability turns every pain point above from an open-ended fear into an answerable question:
- A political data vendor can prove, not just promise, that a client’s exclusive segment hasn’t leaked to a competing campaign.
- A nonprofit can seed its donor file before any authorized (c)(4) data-sharing arrangement and produce an actual audit trail if the IRS or a board member ever asks.
- A campaign renting a list can verify it’s real, correctly sized and not quietly resold after the rental period ends.
- A CRM platform whose ownership just changed hands can let clients independently confirm the new owner isn’t repurposing their political data.
- Any organization accused of a leak can produce evidence before the accusation even lands, instead of scrambling to explain itself after a reporter calls.
None of this requires a cultural shift. The political data world already believes in seeding lists with decoys; it’s been doing it by hand since at least the 1990s. What’s been missing is the infrastructure to do it continuously, automatically, and at the scale modern list-sharing actually happens at. That infrastructure exists now, and it’s live at Assumed.
What We Found When We Tested It Ourselves
Between July 22 and July 29, 2026, we planted 425 unique seed identities into the newsletter and volunteer sign-up forms of 362 different campaign websites, covering 377 named candidates and races, U.S. Senate contests down to state legislative primaries. Each seed is a real, deliverable identity (name, inbox, phone number) submitted to exactly one sign-up form and never reused anywhere else. Then we watched what showed up in each inbox, pulling and re-classifying inbound mail six times between July 24 and July 31.
The Number That Stood Out
In our most recent pull (July 31), those 425 seeds had logged 434 total inbound emails. 395 came from the campaign each seed actually signed up with, first-party, exactly as expected. The other 39 came from somewhere else. Of those 39, 31 traced back to an explainable cause: a shared email vendor sending on the candidate’s behalf (Substack, Wix, NGP VAN, and Action Network all showed up in the data), a volunteer replying from a personal Gmail address, or one of 13 seeds we deliberately double-planted across two candidates as an internal control. That leaves 8 emails, landing in two different inboxes, with no explanation at all, and both of those inboxes trace back to the same sign-up form.
Seed #2505 — Maxine Dexter, OR-03
On July 23, we submitted a seed identity to the “Get Involved” sign-up form at maxinefororegon.com, the campaign site for Maxine Dexter, the Democratic candidate for Oregon’s 3rd Congressional District. That form is the only place this identity’s email address has ever been entered.
20 hours and 34 minutes later, that inbox got its first message. It came from info@colinallred.com, the campaign of Colin Allred, a Democrat running for U.S. Senate in Texas. Subject line: “Welcome to the team!”
Over the next six days, six more arrived from the same address, roughly one every 24 hours: “Not asking for money,” “Asking for $5,” “I’m a fifth-generation logger,” “I hate sending this email — but here’s the reality,” “We’re still missing your first gift, friend,” and, on July 30, “this could really hurt.” Seven emails in seven days, all from a Texas Senate campaign. Zero from Maxine Dexter’s own campaign; this seed has never once heard from the candidate whose form it actually signed up on.
Ruling Out a Fluke
One data point could be an accident: a mistyped address, a one-off list swap, plain coincidence. So on July 29, six days after the first seed, with no connection to it beyond the form, we planted a second, independent seed on that same maxinefororegon.com sign-up. Then we left it alone.
23 hours and 23 minutes later, it received its first-ever email. Sender: info@colinallred.com. Subject line: “Welcome to the team!”, the identical opening line the first seed got.
Two seeds. Six days apart. No shared history except one sign-up form. Both ended up on the same unrelated Senate campaign’s fundraising list within a day of signing up. That’s not a coincidence with a sample size of one; it’s a repeatable pipeline.
What This Isn’t
To be precise about what we’re claiming: we have no evidence this is illegal, and we’re not alleging that it is. Maxine Dexter’s campaign privacy policy does state that submitted information may be shared with other organizations. What we found is consistent with that disclosure being exercised, not violated.
The gap isn’t legal; it’s a gap in what anyone signing up actually knows. In the most-cited academic study on the subject, 74% of people click straight past a privacy policy in favor of a “quick join” option. Among the minority who do open one, average reading time is 73 seconds for a document that takes roughly 30 minutes to read properly. Almost nobody who types their email into a Congressional candidate’s website expects it to land in a Texas Senate campaign’s fundraising sequence within a day. Whether that’s disclosed somewhere in a privacy policy doesn’t change what actually happens in the inbox.
The Takeaway
This is the exact scenario the rest of this document describes in the abstract: a planted contact catching a hand-off nobody could otherwise prove. The difference is that this one isn’t hypothetical. Seed #2505 and its replicate, #2324, are sitting in real inboxes right now, still receiving fundraising emails from a campaign neither of them ever signed up for.
