A declassified FBI case file, released by President Donald Trump's White House Government Transparency Task Force, describes a 2020 cyberattack on Arizona's voter registration system. The hacker exploited a vulnerability in the Arizona Secretary of State's website and downloaded hundreds of thousands of voter records, including files from Maricopa County.
The Desert Review reports the stolen files included publicly available voter registration information. But about 930 to 933 records contained "sensitive voter information" involving domestic violence victims, judges and law enforcement officers. The exact count is inconsistent in the public summary, with 933 mentioned at one point and 930 later.
FBI Director Kash Patel told the task force that the bureau spent "significant resources" investigating the case. The alleged hacker admitted to writing a script that exploited county voter system security and scraped the files, according to the FBI.
Despite that admission, the U.S. Attorney's Office in Phoenix, the Arizona Attorney General's Office, the Maricopa County Attorney's Office and the Pinal County Attorney's Office all declined to bring charges. The Biden-era Department of Justice did not file a case, and no public explanation was given.
Arizona and other states use safeguards such as paper ballots, post-election audits, testing protocols and physical security measures. Voter registration files do not include ballots, and there is no evidence that any vote was changed in this incident.
The U.S. intelligence community has warned since 2020 that bad actors could use voter file access to hamper the ability of voters to cast ballots, even if they cannot alter votes.
The disclosure comes as the Trump administration continues to seek state voter rolls. Reuters reported this week that the administration suffered its 21st court defeat of the year in that effort, with courts rejecting an unprecedented push to assert federal control over elections before the November midterms.
Earlier this year, a federal judge dismissed a Department of Justice lawsuit seeking Arizona's complete voter registration database, ruling that federal law did not authorize the government to compel the state to turn over the information. Arizona officials said the database contains sensitive personal information protected by law.
No California jurisdiction was named in the Arizona FBI case, but the pattern is relevant statewide. California also depends on voter registration databases that contain personal information, and its election system relies on paper ballots and post-election audits. The Arizona case is a reminder that registration data can be targeted even when votes remain safe.
Newly released documents show that China has obtained about 220 million voter files, highlighting the scale of the threat. Election security experts distinguish between attacks on voter registration systems and attacks on vote-counting equipment, and they say registration breaches do not automatically compromise election results.
The Arizona case shows that even with an admission from the attacker, prosecution is not guaranteed. It also shows how voter file theft can create political and legal battles long after an election is over. Voters should know that registration data is a target, but there is no evidence in this case that ballots were touched.