China's Acquisition and Exploitation of American Voter Data

PRC Possesses List of Likely Leaked/Compromised Data Including 200M+ Voter Records

Intelligence productJul 10, 202624 pages200M Voter Records Compromised - declass marked_Redacted.pdf

Declassified by Counsel to the President Warrington 10 July 2026

Redaction map

Text (23)Redacted / blank (1)

Key Insights

AI-generated from the sourced claims — verify against the documents.

  • PRC possesses a list of likely leaked/compromised data including over 200 million U.S. voter records, as of 2019.

  • The list includes 97 entries explicitly identified as originating from U.S. entities, including private companies, government organizations, and NGOs.

  • A U.S. citizen medical/social database with 28 million records, including Social Security numbers, is on the list.

  • The list contains F-15 fighter jet maintenance and technical manuals, and data from U.S. cleared defense contractors.

  • The list includes publicly leaked emails from a named former U.S. official and information about alleged NSA intelligence collection activities.

9 sourced claims

Subject: PRC possesses a list (as of 2019) of likely leaked/compromised data that included U.S. entities; data sets apparently include those related to [REDACTED] and voter data/PII (p.1).

p.1

States a [REDACTED] possessed a document as of 2019 containing a list of entities and the data yielded; a comparatively small portion of the list's entries featured U.S. entities, with most targets in other countries; data primarily dated between 2009 and 2018 (p.1).

p.1

Assessed the majority of entities consisted of data sets of PII, potentially indicating bulk collection of such PII was the goal; several PII data sets were characterized as voter registration records (p.1).

p.1

The list contained 97 entries explicitly identified as originating from U.S. [REDACTED] entities, though the majority of the list consisted of data from other countries; entries included private companies, government organizations, and NGOs (p.2).

p.2

U.S. Voter/Election-Related Data table (p.3-4):

p.3

U.S.-Origin PII table includes an "Unspecified U.S. citizen medical/social [database]": 28 million records including [OCR unclear: medical] Social Security numbers; plus a named U.S. medical group, biogenetics group, school, and business services company (p.5).

p.5

Additional tables (partly redacted) catalog compromised websites (business services companies, web services companies with email addresses, passwords, domain names, login IDs, account numbers; "America" Exploit.in list released 2017 marked 2018; www.mac-torrents.com; biige.com 2014), social networking companies 1-6, U.S. NGOs/religious/professional organizations (labor organizations, religious media, an international law organization "2014 Business Cards," lawyer association, law enforcement association, trade association, think tank, travel company), and other private U.S. entities (think tanks, software) (p.6-11).

p.6

Pages 12, 15-24 are largely redacted or blank/declassification stamps only (p.12, p.15-24).

p.12

U.S. Government Data table (p.13-14): a named U.S. publisher — military maps and records in PDF (2017); publicly released information about alleged NSA intelligence collection activities (2013-2016); publicly leaked emails from a named former U.S. official; F-15-related data (1998-2012), described as downloaded data including F-15 fighter jet maintenance and technical manuals; and named U.S. cleared defense contractors 1-4 (documents/database records dated 2012-2017) (p.13-14).

p.13