Title/lead: "China: Cyber Activities Probably Prelude to Election Espionage"; China is probing the presidential campaign for opportunities to tailor collection and gather insight on U.S.-China policy positions (p.1).
p.1CIA WIRe Memo — China: Cyber Activities Probably Prelude to Election Espionage (1 July 2020)
Declassified by Counsel to the President Warrington 10 July 2026
Key Insights
AI-generated from the sourced claims — verify against the documents.
Chinese cyber actors targeted personal email accounts of senior U.S. leadership, including officials in the Executive Office of the President, high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary since 2018.
As the 2020 election approached, the IC detected Chinese state-sponsored cyber actors targeting the former Vice President's presidential campaign — the first instance this cycle of direct targeting of a U.S. presidential campaign.
Chinese cyber actors collected U.S. election-related information from U.S. voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns during the past year.
Assesses China does not currently intend to covertly interfere to sway the election outcome, although this activity could enable such operations if Beijing decided to do so.
11 sourced claims
States U.S. policy on China is a longstanding high collection priority for Beijing, and Chinese cyber actors have conducted such activity in every U.S. presidential election campaign since at least 2008 (p.1).
p.1Since [OCR unclear] 2018, Chinese cyber actors known in the private sector as APT31 [OCR renders "AP 3"; identified as APT31 later on p.1] targeted personal email accounts of senior U.S. leadership, including officials in the Executive Office of the President, high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1Since 2017, a separate [REDACTED] worked to enable more stealthy operations by identifying email addresses of high-level U.S. officials, then requesting [others] obtain or crack passwords for targeted accounts (p.1).
p.1As the 2020 election approached, the IC detected Chinese state-sponsored cyber actors targeting the former Vice President's presidential campaign — described as the first instance this cycle of direct targeting of a U.S. presidential campaign (p.1).
p.1Assesses China does not currently intend to covertly interfere to sway the election outcome, although this activity could enable such operations if Beijing decided to do so (p.1).
p.1As of 20 May, APT31 actors had sent spear-phishing emails containing tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1Google and the FBI both briefed campaign officials; Google publicly stated the spear-phishing attempts were unsuccessful (p.1).
p.1During the past year, Chinese cyber actors collected U.S. election-related information from U.S. voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns (p.1).
p.1APT31's tracking-link method suggests mapping the target network for follow-on approaches, possibly including tasking campaign staffers' email accounts in the Chinese military's signals intelligence system for collection (p.1-2).
p.1Document details: Produced By CIA; Product Type World Intelligence Review; Publication Date 01 Jul 2020; produced jointly under the Chief of Analysis, the FBI, and the NSA (p.2).
p.2Page evidence
CIA WIRe Memo — China: Cyber Activities Probably Prelude to Election Espionage (1 July 2020) · p.1

Page OCR text
DECLASSIFIED BY COUNSEL TO THE PRESIDENT WARRINGTON ON 10 July 2026, , a " it... V VI R 2 Mg China: Cyber Activities Probably Prelude to Election Espionage Ee China is probing the presidential campaign for opportunities to tailor collection and gather insight on policy positions on US-Chinese issues. US policy on China is a longstanding high collection priority for Beijing, and Chinese cyber actors have conducted such activity in every US presidential election campaign since at least 2008, according to EERE) «Open-source reporting. — Ms Since M2018, Chinese cyber actors known in the private sector as AP 3 | —jIaaaRaaaapapeeeeneee ER ave targeted the personal e-mail accounts of senior US leadership, including officials in the Executive Office of the President and high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary, eRe aa | — Bi Since 2017, a Separate a has worked with the a (0 enable more stealthy operations by MR Chinese cyber actors are targeting US presidential campaign information, probably to gather intelligence that enables future operations. identifying the e-mail addresses of high-level US officials, then requesting Se ee ee ere obtain or crack the passwords for targeted DOO" all i ie aaa ai SRE ART | Mes As the 2020 election approaches, the IC has detected Chinese state-sponsored cyber actors targeting the former Vice President’s presidential campaign, probably to gather intelligence that could enable future operations, the first instance this election cycle that we have seen them directly targeting a US presidential campaign China has also conducted cyber espionage against other US election- related entities, The IC assesses that China does not currently intend to covertly interfere to try to sway the outcome of the election, although this activity could enable such operations, if Beijing made a decision to do so. — Mim As of 20 May, APT31 actors had sent spear-phishing e-mails containing tracking links to the G-mail accounts of staffers associated with a presidential Campaign, i On 4 June, Google announced that APT31 was targeting the campaign. — (gg Google and the FBI both briefed campaign officials on the Chinese cyber operations shortly after discovering the activity. Google officials have publicly stated that the spear-phishing attempts were unsuccessful: — ME During the past year, Chinese cyber actors have collected US election-related information from US voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns, ioe ea SE Oe | Ml APT31's method of sending tracking links Suggests that the Chinese operators are mapping out the target network for follow-on approaches, Possibly including tasking campaign staffers’ e-mail accounts in the Chinese military's signals intelligence system for collection. Tracking links collect metadata such as Classified Sy Ea Derived From: Declassify On FEC WIRe2020-05063 Se TS aR