Claim: recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election (p.2).
p.2Recognizing and Addressing Threats to Statewide Voter Registration Databases
Key Insights
AI-generated from the sourced claims — verify against the documents.
Recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election.
Hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states.
Russian actors hacked into a state board of elections website and stole information on approximately 500,000 voters, including names, addresses, partial SSNs, dates of birth, and driver's license numbers.
The report states that breached voter registration data 'does not get stale' and could be used to request absentee ballots for elections years later.
A background check firm data breach in April 2024 exposed 2.9 billion records containing PII of 170 million individuals, including SSNs and addresses, which can be used to exploit voter verification systems.
31 sourced claims
Claim: hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states (p.2).
p.2The report states experts have "routinely minimized" the significance of successful voter registration breaches and exposure of sensitive verification data (p.2).
p.2Stated purpose: an unclassified overview of threats to statewide voter registration databases (VRDB) from both foreign and domestic actors, relying on intelligence community, law enforcement, and state election official reporting, to inform state/local officials (p.2).
p.2Russian government cyber actors attempted to identify and exploit SQL database vulnerabilities in webservers/databases; FBI reported lacking insight into extent of success, but in at least two separate instances Russian actors accessed voter registration files from a US county website (June 2016) (p.3).
p.3The District Attorney in Riverside County, California revealed a bad actor used the state's voter registration website to change party affiliation of a large number of registered voters, leveraging access to personal information (name, date of birth, driver's license, or Social Security number) without voters' knowledge or consent (July 2016) (p.3).
p.3Russian actors hacked the website of a state board of elections and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver's license numbers (July 2016) (p.3).
p.3Russian actors hacked into computers of a U.S. vendor that supplied software used to verify voter registration information (August 2016) (p.3).
p.3DHS and FBI confirmed Russian actors conducted election system reconnaissance and probed voter registration databases in all 50 states; they could not confirm how many probes resulted in successful breaches. In January 2017, White House officials reported the federal assessment was that networks in at least seven states were compromised (2016) (p.3).
p.3Arizona experienced a breach, and the Illinois State Board of Elections announced attackers gained access to voter registration data including names, addresses, birth dates, and partial Social Security numbers (2016) (p.3).
p.3Kennesaw State University, responsible for supporting Georgia's voter registration database, was found to expose nearly 7 million voter records including driver's license and Social Security numbers; data may have been exposed for as long as seven months (March 2017) (p.3).
p.3Chinese state-sponsored cyber actors aggressively targeted U.S. critical infrastructure to steal sensitive data and PII (August 2021) (p.4).
p.4CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]
p.4Pro-Russian hacktivists claimed to have conducted a Distributed Denial of Service (DDoS) attack that temporarily restricted access to a public-facing US state election office website (2022) (p.4).
p.4Suspected Chinese cyber actors scanned both election-related and non-election state government websites; other suspected PRC cyber actors also collected publicly available U.S. voter information (2022) (p.4).
p.4New Hampshire election officials discovered that a vendor selected to replace the state's aging voter registration database had offshored part of the project; the software had been configured to connect to servers in Russia, and a programmer had hard-coded the Ukrainian national anthem into the database. The issues were corrected prior to deployment (2023) (p.4).
p.4Obtaining absentee ballots: information required to apply for/receive an absentee ballot is stored in the VRDB; a breach can expose public info (name, date of birth, address) and sensitive info (driver's license numbers, full/partial social security numbers, voter signatures on file), enabling bad actors to request absentee ballots at scale for low-propensity voters (p.5).
p.5The report states breached data "does not get stale" — data from a 2021 breach could be used to request a ballot for a 2028 election (p.5).
p.5Altering registration or deleting registrants: a malicious actor could change addresses (and thus polling place) or party affiliation to impede voting; at scale this could disenfranchise voters and might go unnoticed if carefully distributed, using stolen personal data (date of birth, portions of SSN, driver's license number) to pass identity checks in official online state systems. Deletion of registration files at scale could disrupt election administration (p.5).
p.5Develop a plan built on a realistic threat assessment; back up VRDB files frequently and store them securely offline; test the ability to revert to backup during an incident; for electronic pollbooks, produce paper pollbooks as backups; engage a security incident response plan on detecting unauthorized access (p.6).
p.6Phishing defenses: enable Multifactor Authentication on all accounts; unique credentials, no credential sharing; principle of least privilege / separate admin and user accounts; change default passwords, require strong passwords; enable DMARC (Domain-based Message Authentication Reporting and Conformance); flag external emails; train staff on official-account use and phishing recognition at regular intervals (p.7).
p.7DDoS defenses: review contracts and coordinate with website and internet service providers before an incident; identify DDoS mitigation/redundancy measures; know who to contact; ensure network traffic monitoring via firewall/intrusion detection with reviewed logs; maintain an alternate information-dissemination plan and test it (p.7-8).
p.7Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).
p.8The report states millions of Americans have had PII leaked in non-voter-registration breaches that nonetheless compromise election security, because the same data (SSNs, addresses, names, dates of birth, driver's license numbers) is used to verify voter eligibility and identity for absentee ballot requests (p.9).
p.9July 2017: a credit reporting firm discovered a data breach affecting a potential 143 million United States citizens (almost half the population); breach reportedly began May 2017, announced nearly four months later, via an unpatched web application vulnerability, exposing SSNs, dates of birth, home addresses, driver's license numbers, and full names (p.9). [firm not named in OCR text]
p.9February 10, 2020: DOJ indicted four members of China's People's Liberation Army on economic espionage, wire fraud, and computer fraud counts; Attorney General William Barr described a "disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China" targeting PII, trade secrets, and confidential information (p.9).
p.9April 2024: a background check firm suffered a data breach of 2.9 billion records containing PII of 170 million individuals (full names, current/past addresses, Social Security numbers, dates of birth, telephone numbers), reportedly offered on the Dark Web for $3.5 million (p.9). [firm not named in OCR text]
p.9June 2025: one of the largest U.S. supplemental insurance providers suffered a breach affecting 22.65 million individuals (SSNs, dates of birth, driver's license numbers, full names); access gained via social engineering (phishing, whaling, impersonation) (p.9). [provider not named in OCR text]
p.9A University of Oxford report found Russia and China ranked first and third, respectively, as nations posing the highest threat level of cybercrime; PII available to these adversaries can also be purchased or accessed on the dark web (p.9).
p.9The report states VRDBs are "the foundation of our voting system" and urges state/local officials to prioritize security and adopt enhancements such as smart network monitoring and multi-factor authentication; DHS is charged with protecting election infrastructure and encourages collaboration (p.10).
p.10Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).
p.10Page evidence
Recognizing and Addressing Threats to Statewide Voter Registration Databases · p.8

Page OCR text
Share information about important election dates and locations, requesting that ample troubleshooting is available during key periods, and ensuring mutual awareness of any planned maintenance that could impact election operations. Ensure network traffic monitoring and analysis is enabled via a firewall or intrusion detection system and that the logs are being reviewed. Have an alternate plan for information dissemination in case your website does go down. Make sure to test that plan. Protect and Respond: Ransomware Targeting Your Network While not binding on non-Federal entities, CISA's Binding Operational Directives are indicative of best practices and network owners should consider following them. Develop a patch management plan that makes reducing the significant risk of known exploited vulnerabilities a top priority for remediation and requires critical vulnerabilities to be re-mediated within 15 calendar days of initial detection. Implement and enforce network segmentation. Proper network segmentation is an effective security mechanism to prevent an intruder from propagating exploits or moving laterally within an internal network. This includes not transferring election results on the business network. Implement endpoint detection and response software on endpoint devices to monitor for malicious traffic. Verify alerts are being created and response processes are followed. If not already being used, government entities should use .gov domains. Implement Malicious Domain Blocking and Reporting (MDBR) across your network devices to prevent IT systems from connecting to harmful web domains. MDBR can block the vast majority of ransomware infections just by preventing the initial outreach to a ransomware delivery domain. Develop and maintain incident response plans that specifically detail how to operate mission- critical processes in the event of a cybersecurity incident. Test your incident response plans with all key players who would be involved in implementing the response. Maintain backups that allow you to recover data at a minimum of up to 30 days prior. - Encrypt backup files and ensure credentials for accessing the backups are not stored in the targeted environment. Ransomware actors often hunt for and collect credentials stored in the targeted environment and use those credentials to attempt to access backup solutions; they also use publicly available exploits to target unpatched backup solutions. - Ensure backups are maintained offline, as most ransomware actors attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid. - Test the availability and integrity of backups in a disaster recovery scenario.