Claim: recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election (p.2).
p.2Recognizing and Addressing Threats to Statewide Voter Registration Databases
Key Insights
AI-generated from the sourced claims — verify against the documents.
Recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election.
Hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states.
Russian actors hacked into a state board of elections website and stole information on approximately 500,000 voters, including names, addresses, partial SSNs, dates of birth, and driver's license numbers.
The report states that breached voter registration data 'does not get stale' and could be used to request absentee ballots for elections years later.
A background check firm data breach in April 2024 exposed 2.9 billion records containing PII of 170 million individuals, including SSNs and addresses, which can be used to exploit voter verification systems.
31 sourced claims
Claim: hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states (p.2).
p.2The report states experts have "routinely minimized" the significance of successful voter registration breaches and exposure of sensitive verification data (p.2).
p.2Stated purpose: an unclassified overview of threats to statewide voter registration databases (VRDB) from both foreign and domestic actors, relying on intelligence community, law enforcement, and state election official reporting, to inform state/local officials (p.2).
p.2Russian government cyber actors attempted to identify and exploit SQL database vulnerabilities in webservers/databases; FBI reported lacking insight into extent of success, but in at least two separate instances Russian actors accessed voter registration files from a US county website (June 2016) (p.3).
p.3The District Attorney in Riverside County, California revealed a bad actor used the state's voter registration website to change party affiliation of a large number of registered voters, leveraging access to personal information (name, date of birth, driver's license, or Social Security number) without voters' knowledge or consent (July 2016) (p.3).
p.3Russian actors hacked the website of a state board of elections and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver's license numbers (July 2016) (p.3).
p.3Russian actors hacked into computers of a U.S. vendor that supplied software used to verify voter registration information (August 2016) (p.3).
p.3DHS and FBI confirmed Russian actors conducted election system reconnaissance and probed voter registration databases in all 50 states; they could not confirm how many probes resulted in successful breaches. In January 2017, White House officials reported the federal assessment was that networks in at least seven states were compromised (2016) (p.3).
p.3Arizona experienced a breach, and the Illinois State Board of Elections announced attackers gained access to voter registration data including names, addresses, birth dates, and partial Social Security numbers (2016) (p.3).
p.3Kennesaw State University, responsible for supporting Georgia's voter registration database, was found to expose nearly 7 million voter records including driver's license and Social Security numbers; data may have been exposed for as long as seven months (March 2017) (p.3).
p.3Chinese state-sponsored cyber actors aggressively targeted U.S. critical infrastructure to steal sensitive data and PII (August 2021) (p.4).
p.4CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]
p.4Pro-Russian hacktivists claimed to have conducted a Distributed Denial of Service (DDoS) attack that temporarily restricted access to a public-facing US state election office website (2022) (p.4).
p.4Suspected Chinese cyber actors scanned both election-related and non-election state government websites; other suspected PRC cyber actors also collected publicly available U.S. voter information (2022) (p.4).
p.4New Hampshire election officials discovered that a vendor selected to replace the state's aging voter registration database had offshored part of the project; the software had been configured to connect to servers in Russia, and a programmer had hard-coded the Ukrainian national anthem into the database. The issues were corrected prior to deployment (2023) (p.4).
p.4Obtaining absentee ballots: information required to apply for/receive an absentee ballot is stored in the VRDB; a breach can expose public info (name, date of birth, address) and sensitive info (driver's license numbers, full/partial social security numbers, voter signatures on file), enabling bad actors to request absentee ballots at scale for low-propensity voters (p.5).
p.5The report states breached data "does not get stale" — data from a 2021 breach could be used to request a ballot for a 2028 election (p.5).
p.5Altering registration or deleting registrants: a malicious actor could change addresses (and thus polling place) or party affiliation to impede voting; at scale this could disenfranchise voters and might go unnoticed if carefully distributed, using stolen personal data (date of birth, portions of SSN, driver's license number) to pass identity checks in official online state systems. Deletion of registration files at scale could disrupt election administration (p.5).
p.5Develop a plan built on a realistic threat assessment; back up VRDB files frequently and store them securely offline; test the ability to revert to backup during an incident; for electronic pollbooks, produce paper pollbooks as backups; engage a security incident response plan on detecting unauthorized access (p.6).
p.6Phishing defenses: enable Multifactor Authentication on all accounts; unique credentials, no credential sharing; principle of least privilege / separate admin and user accounts; change default passwords, require strong passwords; enable DMARC (Domain-based Message Authentication Reporting and Conformance); flag external emails; train staff on official-account use and phishing recognition at regular intervals (p.7).
p.7DDoS defenses: review contracts and coordinate with website and internet service providers before an incident; identify DDoS mitigation/redundancy measures; know who to contact; ensure network traffic monitoring via firewall/intrusion detection with reviewed logs; maintain an alternate information-dissemination plan and test it (p.7-8).
p.7Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).
p.8The report states millions of Americans have had PII leaked in non-voter-registration breaches that nonetheless compromise election security, because the same data (SSNs, addresses, names, dates of birth, driver's license numbers) is used to verify voter eligibility and identity for absentee ballot requests (p.9).
p.9July 2017: a credit reporting firm discovered a data breach affecting a potential 143 million United States citizens (almost half the population); breach reportedly began May 2017, announced nearly four months later, via an unpatched web application vulnerability, exposing SSNs, dates of birth, home addresses, driver's license numbers, and full names (p.9). [firm not named in OCR text]
p.9February 10, 2020: DOJ indicted four members of China's People's Liberation Army on economic espionage, wire fraud, and computer fraud counts; Attorney General William Barr described a "disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China" targeting PII, trade secrets, and confidential information (p.9).
p.9April 2024: a background check firm suffered a data breach of 2.9 billion records containing PII of 170 million individuals (full names, current/past addresses, Social Security numbers, dates of birth, telephone numbers), reportedly offered on the Dark Web for $3.5 million (p.9). [firm not named in OCR text]
p.9June 2025: one of the largest U.S. supplemental insurance providers suffered a breach affecting 22.65 million individuals (SSNs, dates of birth, driver's license numbers, full names); access gained via social engineering (phishing, whaling, impersonation) (p.9). [provider not named in OCR text]
p.9A University of Oxford report found Russia and China ranked first and third, respectively, as nations posing the highest threat level of cybercrime; PII available to these adversaries can also be purchased or accessed on the dark web (p.9).
p.9The report states VRDBs are "the foundation of our voting system" and urges state/local officials to prioritize security and adopt enhancements such as smart network monitoring and multi-factor authentication; DHS is charged with protecting election infrastructure and encourages collaboration (p.10).
p.10Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).
p.10Page evidence
Recognizing and Addressing Threats to Statewide Voter Registration Databases · p.2

Page OCR text
EXECUTIVE SUMMARY Recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election. Unfortunately, this is not anew phenomenon. Unclassified reports from the last decade reveal that Statewide Voter Registration Databases (VRDB) are attractive targets for foreign adversaries.! Hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states. However, experts have routinely minimized the significance of successful voter registration breaches and the exposure of sensitive personal data used for voter verification. This failure to identify and accurately describe the potential threats makes U.S. elections less secure. State and local election officials must prioritize enhanced defenses to protect voter registration databases, and to limit the ways that compromised data can be exploited. Steps should be taken to prevent bad actors from using stolen data to successfully obtain absentee ballots, alter voter registration information, or add and delete registrants. Implementing and maintaining safeguards is essential to protecting the electoral process and sustaining public confidence in elections. It is imperative to be realistic about the threats posed by foreign adversaries to our critical systems, including election infrastructure. Accurately assessing and communicating the potential for serious consequences is fundamental to effective preparedness and risk management. While candid acknowledgment of these threats may cause concern, it enables critical infrastructure owners to make informed decisions about security measures and mitigation strategies, thereby reducing vulnerability to worst case scenarios. Ignoring or minimizing risks undermines the ability to implement robust controls and leaves critical systems exposed. Transparent recognition of the threat landscape is essential for developing resilient defenses and ensuring the integrity and security of our election systems. This product provides an unclassified overview of the threats to statewide voter registration databases from both foreign and domestic actors. It relies on reporting from the intelligence community, law enforcement, and state election officials. This report is intended to inform state and local election officials of the associated threats and the need to implement recommended mitigating controls.