Noncitizens on State Voter Rolls

Recognizing and Addressing Threats to Statewide Voter Registration Databases

DHS unclassified report11 pagesVoter Registration Database Threats - FINAL.pdf

Redaction map

Text (11)Redacted / blank (0)

Key Insights

AI-generated from the sourced claims — verify against the documents.

  • Recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election.

  • Hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states.

  • Russian actors hacked into a state board of elections website and stole information on approximately 500,000 voters, including names, addresses, partial SSNs, dates of birth, and driver's license numbers.

  • The report states that breached voter registration data 'does not get stale' and could be used to request absentee ballots for elections years later.

  • A background check firm data breach in April 2024 exposed 2.9 billion records containing PII of 170 million individuals, including SSNs and addresses, which can be used to exploit voter verification systems.

31 sourced claims

Claim: recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election (p.2).

p.2

Claim: hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states (p.2).

p.2

The report states experts have "routinely minimized" the significance of successful voter registration breaches and exposure of sensitive verification data (p.2).

p.2

Stated purpose: an unclassified overview of threats to statewide voter registration databases (VRDB) from both foreign and domestic actors, relying on intelligence community, law enforcement, and state election official reporting, to inform state/local officials (p.2).

p.2

Russian government cyber actors attempted to identify and exploit SQL database vulnerabilities in webservers/databases; FBI reported lacking insight into extent of success, but in at least two separate instances Russian actors accessed voter registration files from a US county website (June 2016) (p.3).

p.3
History of breaches (p.3-4):Russia·FBI

The District Attorney in Riverside County, California revealed a bad actor used the state's voter registration website to change party affiliation of a large number of registered voters, leveraging access to personal information (name, date of birth, driver's license, or Social Security number) without voters' knowledge or consent (July 2016) (p.3).

p.3
History of breaches (p.3-4):

Russian actors hacked the website of a state board of elections and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver's license numbers (July 2016) (p.3).

p.3
History of breaches (p.3-4):Russia

Russian actors hacked into computers of a U.S. vendor that supplied software used to verify voter registration information (August 2016) (p.3).

p.3
History of breaches (p.3-4):Russia

DHS and FBI confirmed Russian actors conducted election system reconnaissance and probed voter registration databases in all 50 states; they could not confirm how many probes resulted in successful breaches. In January 2017, White House officials reported the federal assessment was that networks in at least seven states were compromised (2016) (p.3).

p.3
History of breaches (p.3-4):Russia·FBI·DHS

Arizona experienced a breach, and the Illinois State Board of Elections announced attackers gained access to voter registration data including names, addresses, birth dates, and partial Social Security numbers (2016) (p.3).

p.3
History of breaches (p.3-4):

Kennesaw State University, responsible for supporting Georgia's voter registration database, was found to expose nearly 7 million voter records including driver's license and Social Security numbers; data may have been exposed for as long as seven months (March 2017) (p.3).

p.3
History of breaches (p.3-4):

Chinese state-sponsored cyber actors aggressively targeted U.S. critical infrastructure to steal sensitive data and PII (August 2021) (p.4).

p.4
History of breaches (p.3-4):China

CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]

p.4
History of breaches (p.3-4):Iran·FBI·CISA

Pro-Russian hacktivists claimed to have conducted a Distributed Denial of Service (DDoS) attack that temporarily restricted access to a public-facing US state election office website (2022) (p.4).

p.4
History of breaches (p.3-4):Russia

Suspected Chinese cyber actors scanned both election-related and non-election state government websites; other suspected PRC cyber actors also collected publicly available U.S. voter information (2022) (p.4).

p.4
History of breaches (p.3-4):China

New Hampshire election officials discovered that a vendor selected to replace the state's aging voter registration database had offshored part of the project; the software had been configured to connect to servers in Russia, and a programmer had hard-coded the Ukrainian national anthem into the database. The issues were corrected prior to deployment (2023) (p.4).

p.4
History of breaches (p.3-4):Russia

Obtaining absentee ballots: information required to apply for/receive an absentee ballot is stored in the VRDB; a breach can expose public info (name, date of birth, address) and sensitive info (driver's license numbers, full/partial social security numbers, voter signatures on file), enabling bad actors to request absentee ballots at scale for low-propensity voters (p.5).

p.5
Potential avenues for exploitation (p.5):

The report states breached data "does not get stale" — data from a 2021 breach could be used to request a ballot for a 2028 election (p.5).

p.5
Potential avenues for exploitation (p.5):

Altering registration or deleting registrants: a malicious actor could change addresses (and thus polling place) or party affiliation to impede voting; at scale this could disenfranchise voters and might go unnoticed if carefully distributed, using stolen personal data (date of birth, portions of SSN, driver's license number) to pass identity checks in official online state systems. Deletion of registration files at scale could disrupt election administration (p.5).

p.5
Potential avenues for exploitation (p.5):

Develop a plan built on a realistic threat assessment; back up VRDB files frequently and store them securely offline; test the ability to revert to backup during an incident; for electronic pollbooks, produce paper pollbooks as backups; engage a security incident response plan on detecting unauthorized access (p.6).

p.6
Recommended mitigations (p.6-8):

Phishing defenses: enable Multifactor Authentication on all accounts; unique credentials, no credential sharing; principle of least privilege / separate admin and user accounts; change default passwords, require strong passwords; enable DMARC (Domain-based Message Authentication Reporting and Conformance); flag external emails; train staff on official-account use and phishing recognition at regular intervals (p.7).

p.7
Recommended mitigations (p.6-8):

DDoS defenses: review contracts and coordinate with website and internet service providers before an incident; identify DDoS mitigation/redundancy measures; know who to contact; ensure network traffic monitoring via firewall/intrusion detection with reviewed logs; maintain an alternate information-dissemination plan and test it (p.7-8).

p.7
Recommended mitigations (p.6-8):

Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).

p.8
Recommended mitigations (p.6-8):CISA

The report states millions of Americans have had PII leaked in non-voter-registration breaches that nonetheless compromise election security, because the same data (SSNs, addresses, names, dates of birth, driver's license numbers) is used to verify voter eligibility and identity for absentee ballot requests (p.9).

p.9
Data breaches generally (p.9):

July 2017: a credit reporting firm discovered a data breach affecting a potential 143 million United States citizens (almost half the population); breach reportedly began May 2017, announced nearly four months later, via an unpatched web application vulnerability, exposing SSNs, dates of birth, home addresses, driver's license numbers, and full names (p.9). [firm not named in OCR text]

p.9
Data breaches generally (p.9):

February 10, 2020: DOJ indicted four members of China's People's Liberation Army on economic espionage, wire fraud, and computer fraud counts; Attorney General William Barr described a "disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China" targeting PII, trade secrets, and confidential information (p.9).

p.9
Data breaches generally (p.9):China

April 2024: a background check firm suffered a data breach of 2.9 billion records containing PII of 170 million individuals (full names, current/past addresses, Social Security numbers, dates of birth, telephone numbers), reportedly offered on the Dark Web for $3.5 million (p.9). [firm not named in OCR text]

p.9
Data breaches generally (p.9):

June 2025: one of the largest U.S. supplemental insurance providers suffered a breach affecting 22.65 million individuals (SSNs, dates of birth, driver's license numbers, full names); access gained via social engineering (phishing, whaling, impersonation) (p.9). [provider not named in OCR text]

p.9
Data breaches generally (p.9):

A University of Oxford report found Russia and China ranked first and third, respectively, as nations posing the highest threat level of cybercrime; PII available to these adversaries can also be purchased or accessed on the dark web (p.9).

p.9
Data breaches generally (p.9):China·Russia

The report states VRDBs are "the foundation of our voting system" and urges state/local officials to prioritize security and adopt enhancements such as smart network monitoring and multi-factor authentication; DHS is charged with protecting election infrastructure and encourages collaboration (p.10).

p.10
Conclusion (p.10):DHS

Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).

p.10
Conclusion (p.10):CISA

Recognizing and Addressing Threats to Statewide Voter Registration Databases — Election Integrity Archive