Scope note: assesses potential impact of cyber operations against US election infrastructure for the 2020 presidential election (voting process and integrity of results); does not assess adversary intentions or views of US vulnerabilities (p.1).
p.1Vulnerabilities in US 2020 Election Infrastructure (NICM)
declassified by DNI Gabbard 16 March 2026, approved for public release by President Trump 3 July 2026
Key Insights
AI-generated from the sourced claims — verify against the documents.
At least Russia, China, Iran, and North Korea have the capability to access and potentially manipulate data in US election-related computer systems, though the IC does not know whether they have specific plans to interfere.
Russia almost certainly reconnoitered all US state election networks during the 2016 cycle, accessed election-related infrastructure in at least two states, and exfiltrated voter data from at least one state; Russia, China, Iran, and North Korea are all capable of similar operations in 2020.
Adversary claims of manipulation would be difficult to disprove and could undermine public confidence.
At the 2019 DefCon conference, hackers demonstrated the ability to compromise more than 100 voting machines, all certified for use in at least one US voting jurisdiction.
Centralized election-related data repositories (voter-registration databases, pollbooks, official election websites) are most vulnerable to exploitation; adversaries could use access to disrupt election processes.
24 sourced claims
Assesses at least Russia, China, Iran, and North Korea have the capability to access and potentially manipulate data in US election-related computer systems, but the IC does not know whether they have specific plans to interfere (p.1).
p.1Centralized election-related data repositories (voter-registration databases, pollbooks, official election websites) are most vulnerable to exploitation; adversaries could use access to disrupt election processes (p.1).
p.1Systems that tabulate, transmit, or display results are vulnerable to localized exploitation but would be difficult to manipulate at wide enough scale to alter the outcome (p.1).
p.1Adversary claims of manipulation would be difficult to disprove and could undermine public confidence (p.1).
p.1Russia almost certainly reconnoitered all US state election networks during the 2016 cycle, accessed election-related infrastructure in at least two states, and exfiltrated voter data from at least one state; Russia, China, Iran, and North Korea are all capable of similar operations in 2020 (p.1).
p.1Availability of sophisticated intrusion/attack tools on the dark web gives additional countries and nonstate actors (cyber criminals, hacktivists) potential capability to interfere (p.1).
p.1Defines cyber terms: Attack, Compromise, Exploit, and Scan (p.2).
p.2Voter-registration databases are predominantly on Internet-connected systems designed for easy access; adversaries could alter data to prevent voters from voting, cause delays, or force provisional ballots, and use registration data (sometimes public/for purchase) to tailor other efforts (p.2).
p.2Pollbooks: some e-pollbooks tie to Internet-connected databases adversaries could likely exploit, with effects similar to registration-database manipulation (p.2).
p.2State/local election officials' websites: attacks could deter voting or cast doubt on results (p.2).
p.2Direct recording electronic (DRE) machines that store tabulation data in removable memory are particularly vulnerable, especially with no paper backup, but are used far less than more secure types (p.2-3).
p.2Adversaries with physical access to voting machines could alter function, manipulate data, or install malware, per US state and academic investigations (p.2-3).
p.2At the 2019 DefCon conference, hackers demonstrated the ability to compromise more than 100 voting machines, all certified for use in at least one US voting jurisdiction (p.3).
p.3Pollbook hacking example: a pollbook was modified at the 2019 DefCon Voting Machine Hacking Village to run the videogame Doom, per press reporting (marked UNCLASSIFIED) (p.3).
p.3Thirty-one states and DC allow eligible voters to submit absentee ballots via Internet or fax; four states allow return via a web-based portal, seven allow fax-only return for some voters, and one allows mobile voting secured with blockchain; absentee votes are small in number and monitored for anomalies (p.3).
p.3Vote-tabulation systems would be difficult to manipulate at wide scale; systems in each location are not Internet-connected or connected to each other, and exploitation methods often rely on physical proximity; post-election audits and paper trails very likely would uncover such efforts (p.3).
p.3Ballot preparation (often outsourced to third-party vendors) can use Internet-connected systems lacking password/encryption policies, allowing corruption of ballot files, but logic-and-accuracy tests probably would detect it; voting-machine preparation at central locations is vulnerable to insider threats/malware but detectable during preelection testing (p.3).
p.3A growing number of jurisdictions use voter-verified paper backups and post-election audits (required in 38 states) that can alert officials to manipulation or errors (p.3-4).
p.3Cyber operations targeting electronic tabulation could delay results reporting and create public uncertainty but probably would not affect integrity of certified results; tabulated results are stored independently of copies on results websites; DoS attacks or manipulation of results in transit would delay/degrade public access (p.4).
p.4The Blue Ribbon Commission on the vulnerabilities of Pennsylvania's election infrastructure found transmission of preliminary results to public-facing websites is vulnerable to "man-in-the-middle" attacks, though such attacks would not alter separately stored, offline certified copies (p.4).
p.4In May 2019, unidentified cyber actors rendered a US county election website unavailable on the night of a mayoral primary; the incident did not affect tabulation results, stored on a separate non-Internet system (p.4).
p.4False manipulation narratives: adversaries could make false or exaggerated claims (e.g., compromising all US voting machines, or linking exaggerated claims to real DoS/intrusion operations) to undermine confidence; disproving them could take weeks or months (p.4).
p.4Mitigations: physical security and cyber hygiene (replacing obsolete equipment, stronger passwords/audits, network segmentation) — may deter less-sophisticated actors but probably insufficient against advanced nation-states; third-party vendor verification/screening; public messaging and education; and privately messaging adversaries that manipulation attempts are unacceptable with serious consequences (p.4-5).
p.4