China is probing the presidential campaign for opportunities to tailor collection and gather insight on US-China policy positions; Chinese cyber actors have conducted such activity in every US presidential election campaign since at least 2008 (p.1).
p.1China: Cyber Activities Probably Prelude to Election Espionage (WIRe)
declassified by Counsel to the President Warrington 10 July 2026
Key Insights
AI-generated from the sourced claims — verify against the documents.
Chinese cyber actors have probed every US presidential election campaign since at least 2008, and as the 2020 election approached, they directly targeted a presidential campaign for the first time that cycle.
Since approximately 2018, Chinese cyber actors known as APT31 have targeted personal email accounts of senior US leadership, including officials in the Executive Office of the President, Congress, and the federal judiciary.
The IC assessed that China did not intend to covertly interfere to sway the 2020 election outcome, but the cyber espionage activity could enable such operations if Beijing decided to do so.
Chinese cyber actors collected US election-related information from voter databases, a polling-data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns.
11 sourced claims
Since [~2018], Chinese cyber actors known in the private sector as APT31 [OCR shows "AP 3"] have targeted personal e-mail accounts of senior US leadership, including officials in the Executive Office of the President and high-ranking officials across Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1Since 2017, a separate [REDACTED] group worked with [REDACTED] to enable more stealthy operations by identifying e-mail addresses of high-level US officials and then [REDACTED] to obtain or crack passwords for targeted [REDACTED] (p.1).
p.1As the 2020 election approached, the IC detected Chinese state-sponsored actors targeting the former Vice President's presidential campaign, the first instance that cycle of directly targeting a US presidential campaign; China also conducted cyber espionage against other US election-related entities (p.1).
p.1The IC assessed China did not then intend to covertly interfere to sway the election outcome, though the activity could enable such operations if Beijing decided to do so (p.1).
p.1As of 20 May, APT31 actors sent spear-phishing e-mails with tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1Google and the FBI both briefed campaign officials shortly after discovering the activity; Google publicly stated the spear-phishing attempts were unsuccessful (p.1).
p.1Over the prior year, Chinese cyber actors collected US election-related information from US voter databases, a polling-data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns (p.1).
p.1APT31's use of tracking links suggests operators are mapping the target network for follow-on approaches, possibly tasking staffers' e-mail accounts in the Chinese military's signals-intelligence system; tracking links collect metadata (Internet activity, system information) usable to exploit accounts and identify other targets (p.1-2).
p.1Knowledge of a target's OS and software would let actors determine whether to exploit known vulnerabilities or develop new malware; opening a tracking-link e-mail (even without clicking) confirms an active account (p.2).
p.2Produced jointly under the auspices of the Chief of Analysis, [REDACTED], the FBI, and the NSA; Product Type: World Intelligence Review (p.2).
p.2Page evidence
China: Cyber Activities Probably Prelude to Election Espionage (WIRe) · p.1

Page OCR text
DECLASSIFIED BY COUNSEL TO THE PRESIDENT WARRINGTON ON 10 July 2026, , a " it... V VI R 2 Mg China: Cyber Activities Probably Prelude to Election Espionage Ee China is probing the presidential campaign for opportunities to tailor collection and gather insight on policy positions on US-Chinese issues. US policy on China is a longstanding high collection priority for Beijing, and Chinese cyber actors have conducted such activity in every US presidential election campaign since at least 2008, according to EERE) «Open-source reporting. — Ms Since M2018, Chinese cyber actors known in the private sector as AP 3 | —jIaaaRaaaapapeeeeneee ER ave targeted the personal e-mail accounts of senior US leadership, including officials in the Executive Office of the President and high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary, eRe aa | — Bi Since 2017, a Separate a has worked with the a (0 enable more stealthy operations by MR Chinese cyber actors are targeting US presidential campaign information, probably to gather intelligence that enables future operations. identifying the e-mail addresses of high-level US officials, then requesting Se ee ee ere obtain or crack the passwords for targeted DOO" all i ie aaa ai SRE ART | Mes As the 2020 election approaches, the IC has detected Chinese state-sponsored cyber actors targeting the former Vice President’s presidential campaign, probably to gather intelligence that could enable future operations, the first instance this election cycle that we have seen them directly targeting a US presidential campaign China has also conducted cyber espionage against other US election- related entities, The IC assesses that China does not currently intend to covertly interfere to try to sway the outcome of the election, although this activity could enable such operations, if Beijing made a decision to do so. — Mim As of 20 May, APT31 actors had sent spear-phishing e-mails containing tracking links to the G-mail accounts of staffers associated with a presidential Campaign, i On 4 June, Google announced that APT31 was targeting the campaign. — (gg Google and the FBI both briefed campaign officials on the Chinese cyber operations shortly after discovering the activity. Google officials have publicly stated that the spear-phishing attempts were unsuccessful: — ME During the past year, Chinese cyber actors have collected US election-related information from US voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns, ioe ea SE Oe | Ml APT31's method of sending tracking links Suggests that the Chinese operators are mapping out the target network for follow-on approaches, Possibly including tasking campaign staffers’ e-mail accounts in the Chinese military's signals intelligence system for collection. Tracking links collect metadata such as Classified Sy Ea Derived From: Declassify On FEC WIRe2020-05063 Se TS aR