Vulnerabilities in Electronic Voting and Ballot-Counting Systems

Vulnerabilities in US 2020 Election Infrastructure (NICM)

National Intelligence Council MemorandumJan 15, 20205 pagesNICM_VulnerabilitiesInUS2020ElectionInfrastructure_15JAN2020_DECLASS_REDACTEDed.pdf

declassified by DNI Gabbard 16 March 2026, approved for public release by President Trump 3 July 2026

Redaction map

Text (5)Redacted / blank (0)

Key Insights

AI-generated from the sourced claims — verify against the documents.

  • At least Russia, China, Iran, and North Korea have the capability to access and potentially manipulate data in US election-related computer systems, though the IC does not know whether they have specific plans to interfere.

  • Russia almost certainly reconnoitered all US state election networks during the 2016 cycle, accessed election-related infrastructure in at least two states, and exfiltrated voter data from at least one state; Russia, China, Iran, and North Korea are all capable of similar operations in 2020.

  • Adversary claims of manipulation would be difficult to disprove and could undermine public confidence.

  • At the 2019 DefCon conference, hackers demonstrated the ability to compromise more than 100 voting machines, all certified for use in at least one US voting jurisdiction.

  • Centralized election-related data repositories (voter-registration databases, pollbooks, official election websites) are most vulnerable to exploitation; adversaries could use access to disrupt election processes.

24 sourced claims

Scope note: assesses potential impact of cyber operations against US election infrastructure for the 2020 presidential election (voting process and integrity of results); does not assess adversary intentions or views of US vulnerabilities (p.1).

p.1

Assesses at least Russia, China, Iran, and North Korea have the capability to access and potentially manipulate data in US election-related computer systems, but the IC does not know whether they have specific plans to interfere (p.1).

p.1

Centralized election-related data repositories (voter-registration databases, pollbooks, official election websites) are most vulnerable to exploitation; adversaries could use access to disrupt election processes (p.1).

p.1

Systems that tabulate, transmit, or display results are vulnerable to localized exploitation but would be difficult to manipulate at wide enough scale to alter the outcome (p.1).

p.1

Adversary claims of manipulation would be difficult to disprove and could undermine public confidence (p.1).

p.1

Russia almost certainly reconnoitered all US state election networks during the 2016 cycle, accessed election-related infrastructure in at least two states, and exfiltrated voter data from at least one state; Russia, China, Iran, and North Korea are all capable of similar operations in 2020 (p.1).

p.1

Availability of sophisticated intrusion/attack tools on the dark web gives additional countries and nonstate actors (cyber criminals, hacktivists) potential capability to interfere (p.1).

p.1

Defines cyber terms: Attack, Compromise, Exploit, and Scan (p.2).

p.2

Voter-registration databases are predominantly on Internet-connected systems designed for easy access; adversaries could alter data to prevent voters from voting, cause delays, or force provisional ballots, and use registration data (sometimes public/for purchase) to tailor other efforts (p.2).

p.2

Pollbooks: some e-pollbooks tie to Internet-connected databases adversaries could likely exploit, with effects similar to registration-database manipulation (p.2).

p.2

State/local election officials' websites: attacks could deter voting or cast doubt on results (p.2).

p.2

Direct recording electronic (DRE) machines that store tabulation data in removable memory are particularly vulnerable, especially with no paper backup, but are used far less than more secure types (p.2-3).

p.2

Adversaries with physical access to voting machines could alter function, manipulate data, or install malware, per US state and academic investigations (p.2-3).

p.2

At the 2019 DefCon conference, hackers demonstrated the ability to compromise more than 100 voting machines, all certified for use in at least one US voting jurisdiction (p.3).

p.3

Pollbook hacking example: a pollbook was modified at the 2019 DefCon Voting Machine Hacking Village to run the videogame Doom, per press reporting (marked UNCLASSIFIED) (p.3).

p.3

Thirty-one states and DC allow eligible voters to submit absentee ballots via Internet or fax; four states allow return via a web-based portal, seven allow fax-only return for some voters, and one allows mobile voting secured with blockchain; absentee votes are small in number and monitored for anomalies (p.3).

p.3

Vote-tabulation systems would be difficult to manipulate at wide scale; systems in each location are not Internet-connected or connected to each other, and exploitation methods often rely on physical proximity; post-election audits and paper trails very likely would uncover such efforts (p.3).

p.3

Ballot preparation (often outsourced to third-party vendors) can use Internet-connected systems lacking password/encryption policies, allowing corruption of ballot files, but logic-and-accuracy tests probably would detect it; voting-machine preparation at central locations is vulnerable to insider threats/malware but detectable during preelection testing (p.3).

p.3

A growing number of jurisdictions use voter-verified paper backups and post-election audits (required in 38 states) that can alert officials to manipulation or errors (p.3-4).

p.3

Cyber operations targeting electronic tabulation could delay results reporting and create public uncertainty but probably would not affect integrity of certified results; tabulated results are stored independently of copies on results websites; DoS attacks or manipulation of results in transit would delay/degrade public access (p.4).

p.4

The Blue Ribbon Commission on the vulnerabilities of Pennsylvania's election infrastructure found transmission of preliminary results to public-facing websites is vulnerable to "man-in-the-middle" attacks, though such attacks would not alter separately stored, offline certified copies (p.4).

p.4

In May 2019, unidentified cyber actors rendered a US county election website unavailable on the night of a mayoral primary; the incident did not affect tabulation results, stored on a separate non-Internet system (p.4).

p.4

False manipulation narratives: adversaries could make false or exaggerated claims (e.g., compromising all US voting machines, or linking exaggerated claims to real DoS/intrusion operations) to undermine confidence; disproving them could take weeks or months (p.4).

p.4

Mitigations: physical security and cyber hygiene (replacing obsolete equipment, stronger passwords/audits, network segmentation) — may deter less-sophisticated actors but probably insufficient against advanced nation-states; third-party vendor verification/screening; public messaging and education; and privately messaging adversaries that manipulation attempts are unacceptable with serious consequences (p.4-5).

p.4