Title/lead: "China: Cyber Activities Probably Prelude to Election Espionage"; China is probing the presidential campaign for opportunities to tailor collection and gather insight on U.S.-China policy positions (p.1).
p.1CIA WIRe Memo — China: Cyber Activities Probably Prelude to Election Espionage (1 July 2020)
Declassified by Counsel to the President Warrington 10 July 2026
Key Insights
AI-generated from the sourced claims — verify against the documents.
Chinese cyber actors targeted personal email accounts of senior U.S. leadership, including officials in the Executive Office of the President, high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary since 2018.
As the 2020 election approached, the IC detected Chinese state-sponsored cyber actors targeting the former Vice President's presidential campaign — the first instance this cycle of direct targeting of a U.S. presidential campaign.
Chinese cyber actors collected U.S. election-related information from U.S. voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns during the past year.
Assesses China does not currently intend to covertly interfere to sway the election outcome, although this activity could enable such operations if Beijing decided to do so.
11 sourced claims
States U.S. policy on China is a longstanding high collection priority for Beijing, and Chinese cyber actors have conducted such activity in every U.S. presidential election campaign since at least 2008 (p.1).
p.1Since [OCR unclear] 2018, Chinese cyber actors known in the private sector as APT31 [OCR renders "AP 3"; identified as APT31 later on p.1] targeted personal email accounts of senior U.S. leadership, including officials in the Executive Office of the President, high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1Since 2017, a separate [REDACTED] worked to enable more stealthy operations by identifying email addresses of high-level U.S. officials, then requesting [others] obtain or crack passwords for targeted accounts (p.1).
p.1As the 2020 election approached, the IC detected Chinese state-sponsored cyber actors targeting the former Vice President's presidential campaign — described as the first instance this cycle of direct targeting of a U.S. presidential campaign (p.1).
p.1Assesses China does not currently intend to covertly interfere to sway the election outcome, although this activity could enable such operations if Beijing decided to do so (p.1).
p.1As of 20 May, APT31 actors had sent spear-phishing emails containing tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1Google and the FBI both briefed campaign officials; Google publicly stated the spear-phishing attempts were unsuccessful (p.1).
p.1During the past year, Chinese cyber actors collected U.S. election-related information from U.S. voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns (p.1).
p.1APT31's tracking-link method suggests mapping the target network for follow-on approaches, possibly including tasking campaign staffers' email accounts in the Chinese military's signals intelligence system for collection (p.1-2).
p.1Document details: Produced By CIA; Product Type World Intelligence Review; Publication Date 01 Jul 2020; produced jointly under the Chief of Analysis, the FBI, and the NSA (p.2).
p.2Page evidence
CIA WIRe Memo — China: Cyber Activities Probably Prelude to Election Espionage (1 July 2020) · p.2

Page OCR text
V\Re J China: Cyber Activities Probably Prelude... Internet activity and system information that the operators can use to exploit the accounts and identify other targets of interest. — ig Knowledge of a campaign official's operating system and software would allow cyber actors to determine whether they could quickly exploit known vulnerabilities or if they needed to develop malware to gain undetected access to the victim’s machine. — ggg |f a target opened a spear-phishing e-mail with a tracking link—even without clicking on any links—it would confirm an active account for the cyber actors, potentially narrowing the target set for future ay operations. For additional information: Produced jointly under the auspices of the Chief of Analysis, mmm the Federal Bureau of Investigation, and the National Security Agency. OCUMENT DETAILS CONTENTS Produced By: CIA Product Type: World Intelligence Review Document Number: WiRe2020-05063 Publication Date: 01 Jul 2020 Contact TS (Secure). IT (open) Material used in the WIRe may be subject to copyright laws. Further reproduction and dissemination by any means, for any purpose other than official business, may be subject to copyright restrictions and is generally prohibited without the permission of the copyright holder