China is probing the presidential campaign for opportunities to tailor collection and gather insight on US-China policy positions; Chinese cyber actors have conducted such activity in every US presidential election campaign since at least 2008 (p.1).
p.1China: Cyber Activities Probably Prelude to Election Espionage (WIRe)
declassified by Counsel to the President Warrington 10 July 2026
Key Insights
AI-generated from the sourced claims — verify against the documents.
Chinese cyber actors have probed every US presidential election campaign since at least 2008, and as the 2020 election approached, they directly targeted a presidential campaign for the first time that cycle.
Since approximately 2018, Chinese cyber actors known as APT31 have targeted personal email accounts of senior US leadership, including officials in the Executive Office of the President, Congress, and the federal judiciary.
The IC assessed that China did not intend to covertly interfere to sway the 2020 election outcome, but the cyber espionage activity could enable such operations if Beijing decided to do so.
Chinese cyber actors collected US election-related information from voter databases, a polling-data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns.
11 sourced claims
Since [~2018], Chinese cyber actors known in the private sector as APT31 [OCR shows "AP 3"] have targeted personal e-mail accounts of senior US leadership, including officials in the Executive Office of the President and high-ranking officials across Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1Since 2017, a separate [REDACTED] group worked with [REDACTED] to enable more stealthy operations by identifying e-mail addresses of high-level US officials and then [REDACTED] to obtain or crack passwords for targeted [REDACTED] (p.1).
p.1As the 2020 election approached, the IC detected Chinese state-sponsored actors targeting the former Vice President's presidential campaign, the first instance that cycle of directly targeting a US presidential campaign; China also conducted cyber espionage against other US election-related entities (p.1).
p.1The IC assessed China did not then intend to covertly interfere to sway the election outcome, though the activity could enable such operations if Beijing decided to do so (p.1).
p.1As of 20 May, APT31 actors sent spear-phishing e-mails with tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1Google and the FBI both briefed campaign officials shortly after discovering the activity; Google publicly stated the spear-phishing attempts were unsuccessful (p.1).
p.1Over the prior year, Chinese cyber actors collected US election-related information from US voter databases, a polling-data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns (p.1).
p.1APT31's use of tracking links suggests operators are mapping the target network for follow-on approaches, possibly tasking staffers' e-mail accounts in the Chinese military's signals-intelligence system; tracking links collect metadata (Internet activity, system information) usable to exploit accounts and identify other targets (p.1-2).
p.1Knowledge of a target's OS and software would let actors determine whether to exploit known vulnerabilities or develop new malware; opening a tracking-link e-mail (even without clicking) confirms an active account (p.2).
p.2Produced jointly under the auspices of the Chief of Analysis, [REDACTED], the FBI, and the NSA; Product Type: World Intelligence Review (p.2).
p.2Page evidence
China: Cyber Activities Probably Prelude to Election Espionage (WIRe) · p.2

Page OCR text
V\Re J China: Cyber Activities Probably Prelude... Internet activity and system information that the operators can use to exploit the accounts and identify other targets of interest. — ig Knowledge of a campaign official's operating system and software would allow cyber actors to determine whether they could quickly exploit known vulnerabilities or if they needed to develop malware to gain undetected access to the victim’s machine. — ggg |f a target opened a spear-phishing e-mail with a tracking link—even without clicking on any links—it would confirm an active account for the cyber actors, potentially narrowing the target set for future ay operations. For additional information: Produced jointly under the auspices of the Chief of Analysis, mmm the Federal Bureau of Investigation, and the National Security Agency. OCUMENT DETAILS CONTENTS Produced By: CIA Product Type: World Intelligence Review Document Number: WiRe2020-05063 Publication Date: 01 Jul 2020 Contact TS (Secure). IT (open) Material used in the WIRe may be subject to copyright laws. Further reproduction and dissemination by any means, for any purpose other than official business, may be subject to copyright restrictions and is generally prohibited without the permission of the copyright holder