Claim: recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election (p.2).
p.2Recognizing and Addressing Threats to Statewide Voter Registration Databases
Key Insights
AI-generated from the sourced claims — verify against the documents.
Recently declassified records revealed that China breached multiple state voter registration systems prior to the 2020 election.
Hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states.
Russian actors hacked into a state board of elections website and stole information on approximately 500,000 voters, including names, addresses, partial SSNs, dates of birth, and driver's license numbers.
The report states that breached voter registration data 'does not get stale' and could be used to request absentee ballots for elections years later.
A background check firm data breach in April 2024 exposed 2.9 billion records containing PII of 170 million individuals, including SSNs and addresses, which can be used to exploit voter verification systems.
31 sourced claims
Claim: hackers have attempted to breach voter registration systems in all 50 states, with confirmed successes in at least 20 states (p.2).
p.2The report states experts have "routinely minimized" the significance of successful voter registration breaches and exposure of sensitive verification data (p.2).
p.2Stated purpose: an unclassified overview of threats to statewide voter registration databases (VRDB) from both foreign and domestic actors, relying on intelligence community, law enforcement, and state election official reporting, to inform state/local officials (p.2).
p.2Russian government cyber actors attempted to identify and exploit SQL database vulnerabilities in webservers/databases; FBI reported lacking insight into extent of success, but in at least two separate instances Russian actors accessed voter registration files from a US county website (June 2016) (p.3).
p.3The District Attorney in Riverside County, California revealed a bad actor used the state's voter registration website to change party affiliation of a large number of registered voters, leveraging access to personal information (name, date of birth, driver's license, or Social Security number) without voters' knowledge or consent (July 2016) (p.3).
p.3Russian actors hacked the website of a state board of elections and stole information related to approximately 500,000 voters, including names, addresses, partial social security numbers, dates of birth, and driver's license numbers (July 2016) (p.3).
p.3Russian actors hacked into computers of a U.S. vendor that supplied software used to verify voter registration information (August 2016) (p.3).
p.3DHS and FBI confirmed Russian actors conducted election system reconnaissance and probed voter registration databases in all 50 states; they could not confirm how many probes resulted in successful breaches. In January 2017, White House officials reported the federal assessment was that networks in at least seven states were compromised (2016) (p.3).
p.3Arizona experienced a breach, and the Illinois State Board of Elections announced attackers gained access to voter registration data including names, addresses, birth dates, and partial Social Security numbers (2016) (p.3).
p.3Kennesaw State University, responsible for supporting Georgia's voter registration database, was found to expose nearly 7 million voter records including driver's license and Social Security numbers; data may have been exposed for as long as seven months (March 2017) (p.3).
p.3Chinese state-sponsored cyber actors aggressively targeted U.S. critical infrastructure to steal sensitive data and PII (August 2021) (p.4).
p.4CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]
p.4Pro-Russian hacktivists claimed to have conducted a Distributed Denial of Service (DDoS) attack that temporarily restricted access to a public-facing US state election office website (2022) (p.4).
p.4Suspected Chinese cyber actors scanned both election-related and non-election state government websites; other suspected PRC cyber actors also collected publicly available U.S. voter information (2022) (p.4).
p.4New Hampshire election officials discovered that a vendor selected to replace the state's aging voter registration database had offshored part of the project; the software had been configured to connect to servers in Russia, and a programmer had hard-coded the Ukrainian national anthem into the database. The issues were corrected prior to deployment (2023) (p.4).
p.4Obtaining absentee ballots: information required to apply for/receive an absentee ballot is stored in the VRDB; a breach can expose public info (name, date of birth, address) and sensitive info (driver's license numbers, full/partial social security numbers, voter signatures on file), enabling bad actors to request absentee ballots at scale for low-propensity voters (p.5).
p.5The report states breached data "does not get stale" — data from a 2021 breach could be used to request a ballot for a 2028 election (p.5).
p.5Altering registration or deleting registrants: a malicious actor could change addresses (and thus polling place) or party affiliation to impede voting; at scale this could disenfranchise voters and might go unnoticed if carefully distributed, using stolen personal data (date of birth, portions of SSN, driver's license number) to pass identity checks in official online state systems. Deletion of registration files at scale could disrupt election administration (p.5).
p.5Develop a plan built on a realistic threat assessment; back up VRDB files frequently and store them securely offline; test the ability to revert to backup during an incident; for electronic pollbooks, produce paper pollbooks as backups; engage a security incident response plan on detecting unauthorized access (p.6).
p.6Phishing defenses: enable Multifactor Authentication on all accounts; unique credentials, no credential sharing; principle of least privilege / separate admin and user accounts; change default passwords, require strong passwords; enable DMARC (Domain-based Message Authentication Reporting and Conformance); flag external emails; train staff on official-account use and phishing recognition at regular intervals (p.7).
p.7DDoS defenses: review contracts and coordinate with website and internet service providers before an incident; identify DDoS mitigation/redundancy measures; know who to contact; ensure network traffic monitoring via firewall/intrusion detection with reviewed logs; maintain an alternate information-dissemination plan and test it (p.7-8).
p.7Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).
p.8The report states millions of Americans have had PII leaked in non-voter-registration breaches that nonetheless compromise election security, because the same data (SSNs, addresses, names, dates of birth, driver's license numbers) is used to verify voter eligibility and identity for absentee ballot requests (p.9).
p.9July 2017: a credit reporting firm discovered a data breach affecting a potential 143 million United States citizens (almost half the population); breach reportedly began May 2017, announced nearly four months later, via an unpatched web application vulnerability, exposing SSNs, dates of birth, home addresses, driver's license numbers, and full names (p.9). [firm not named in OCR text]
p.9February 10, 2020: DOJ indicted four members of China's People's Liberation Army on economic espionage, wire fraud, and computer fraud counts; Attorney General William Barr described a "disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China" targeting PII, trade secrets, and confidential information (p.9).
p.9April 2024: a background check firm suffered a data breach of 2.9 billion records containing PII of 170 million individuals (full names, current/past addresses, Social Security numbers, dates of birth, telephone numbers), reportedly offered on the Dark Web for $3.5 million (p.9). [firm not named in OCR text]
p.9June 2025: one of the largest U.S. supplemental insurance providers suffered a breach affecting 22.65 million individuals (SSNs, dates of birth, driver's license numbers, full names); access gained via social engineering (phishing, whaling, impersonation) (p.9). [provider not named in OCR text]
p.9A University of Oxford report found Russia and China ranked first and third, respectively, as nations posing the highest threat level of cybercrime; PII available to these adversaries can also be purchased or accessed on the dark web (p.9).
p.9The report states VRDBs are "the foundation of our voting system" and urges state/local officials to prioritize security and adopt enhancements such as smart network monitoring and multi-factor authentication; DHS is charged with protecting election infrastructure and encourages collaboration (p.10).
p.10Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).
p.10Page evidence
Recognizing and Addressing Threats to Statewide Voter Registration Databases · p.9

Page OCR text
DATA BREACHES GENERALLY Over the last decade, millions of Americans have had their personally identifiable information (PI) leaked in data breaches that are not related to voter registration but compromise election security, nonetheless. Cybercriminals have gained access to databases belonging to financial institutions, healthcare providers, and other government agencies, obtaining PII including Social Security numbers, addresses, full names, dates of birth, and driver’s license numbers. In many cases, this information is sold on the dark web, where it is easily accessible to malicious actors. Because much of this same data is used to verify voter eligibility, maintain voter rolls, and verify identity for absentee ballot requests, large-scale PII exposure of data held by private companies has implications not only for privacy and financial fraud, but also for the integrity of U.S. elections. e In July 2017, a credit reporting firm discovered a data breach that affected a potential 143 million United States citizens, almost half of the population. The breach reportedly began in May 2017 and was announced nearly four months later. By exploiting an unpatched vulnerability in web application software, cyber attackers were able to steal an unprecedented amount of PII including Social Security numbers, dates of birth, home addresses, driver’s license numbers, and full names. e On February 10, 2020, the Department of Justice (DOJ) indicted four members of China's People’s Liberation Army on counts of economic espionage, wire fraud and computer fraud. In a statement following the indictment, Attorney General William Barr said the hack fits "a disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China and its citizens that have targeted personally identifiable information, trade secrets, and other confidential information.” e In April 2024, a background check firm that stored troves of records including full names, current and past addresses, Social Security numbers, dates of birth, and telephone numbers suffered a colossal data breach of 2.9 billion records containing PII of 170 million individuals. The information was reportedly found on the Dark Web being offered for $3.5 million. e One of the largest supplemental insurance providers in the United States suffered a data breach in June 2025 that affected 22.65 million individuals. Information accessed by hackers included PII such as Social Security numbers, dates of birth, driver’s license numbers and full names. Hackers gained access to the provider's systems via social engineering tactics e.g. phishing, whaling, and impersonation. e A report from the University of Oxford found that Russia and China ranked first and third, respectively, as nations that pose the highest threat level of cybercrime. Moreover, the PII available to these adversaries is not limited to that accessed through their own cyber operations but can be readily purchased or accessed on the dark web. The cases mentioned above involve breaches that contained the information typically needed for voter registration and absentee ballot applications. The threat this exposed data poses to the integrity of U.S. elections is significant and ongoing, underscoring the need to recognize and mitigate the direct risk it poses to critical election infrastructure.