Maricopa County Hacker Stole 633,000 Voter Files, DOJ Declined Charges

This piece lays out recent voter-roll revelations, a large Arizona data breach with an admitted hacker, and why those facts matter for election security and public trust.

President Trump’s primetime warning about election vulnerabilities was mocked by much of the media, but subsequent reporting has forced skeptics to confront inconvenient facts. New Jersey recently disclosed that 6,600 noncitizens appear on its voter rolls, with roughly 400 of them having voted in prior elections. Automatic registration in that state since 2018 means the true scope is likely larger than the initial count suggests.

Federal reporting also points to a broader pattern: Department of Homeland Security analyses identified about 278,000 noncitizens on voter rolls across New Jersey, Nevada, California, and Pennsylvania. Those numbers make the single-state figure in New Jersey look like the tip of the iceberg rather than a complete accounting. Local officials have been resistant to outside scrutiny, which raises obvious questions about transparency and accountability.

Trump has long warned about foreign interference, and investigators have documented troubling access to voter data that would be useful to hostile actors. The disclosure that China has obtained vast troves of voter information heightens the concern that bad actors could target registration systems or intimidate voters. Weak points in registration databases can be exploited in ways that do not require altering ballots to have real impact.

One of the most striking episodes involves an Arizona case tied to the 2020 election cycle, where a hacker reportedly scraped hundreds of thousands of voter registration files. The FBI obtained a confession, but prosecutors declined to pursue charges, a choice critics say reflects a politically influenced reluctance to treat election-system intrusions with the seriousness they deserve. That decision left a major security incident effectively unresolved and sent a worrying message.

https://x.com/RealSKeshel/status/2085341714290495912

Arizona’s largest county suffered a significant breach of its election data in the days before the 2020 presidential election when a self-described hacker foiled security and obtained 633,000 voter registration files but the Biden Justice Department and local prosecutors declined to bring charges even after the FBI got the suspect to confess, according to declassified documents made public Thursday by the White House.

The scraping of Maricopa County’s voter registration files was the most flagged security incident in a cyberintrusion log kept by U.S. spy agencies in the days around the Nov. 3, 2020 election, and it caused an extensive FBI investigation that led agents to a home in Fountain Hills, Ariz., the memos show.

The man the FBI confronted admitted he wrote a computer script to exploit the county voter systems security and scraped the files, which included 930 with “sensitive voter information like domestic violence victims, judges and law enforcement officers,” according to the FBI case files declassified and made public by President Donald Trump’s White House Government Transparency Task Force.

FBI Director Kash Patel sent a letter to that task force this week stating the bureau spent “significant resources” but could not get the U.S. Attorney’s Office in Phoenix, the Arizona Attorney General’s Office, the Maricopa County Arizona Attorney’s Office or the Pinal County, Arizona Attorney’s Office to bring charges despite an admission from the alleged hacker.

[…]

Voter registration files do not include ballots, and there’s no evidence votes were changed in the incident, But the U.S. intelligence community has been warning since 2020 that if bad actors gained access to such files they could hamper the ability of voters to cast ballots in the future. China has obtained about 220 million such files, documents released last month by President Donald Trump show.

[…]

The man was forthcoming, telling federal agents exactly how he discovered the vulnerability in the Maricopa County Recorder’s website and how he wrote a computer script to exploit it, according to an FD-302 memorializing the interview. An FD-302 is the official FBI form used by special agents to write down a summary of an interview with a witness, suspect, or informant.

The suspect, who described himself as a “hacker or tinkerer,” told the agents that he first discovered the vulnerabilities in Maricopa’s website about two months earlier, in September 2020. “He noticed his voter ID appeared in the URL” after entering his own voter information and “tested the vulnerability by entering several seven-digit numbers into the URL path resulting in access to different voter registration information,” the agents wrote.

According to reporting, the suspect expected law enforcement would show up and took steps to scrub his hard drives before agents got there. He considered going to the media to explain what he had done but ultimately kept quiet, leaving a dangerous hole in the public record. That silence and the absence of prosecution have left unanswered how easily bad actors can exploit registration systems.

When prosecutors decline to act after an admission and a clear technical exploit, the message is simple: the system can be probed with few consequences. That invites further probing and increases the odds that hostile actors will exploit the same vulnerabilities for worse outcomes. Election infrastructure is only as secure as the willingness of authorities to investigate and deter intrusions.

Democratic policy choices such as broad automatic registration and resistance to rigorous audits have critics arguing those approaches expand the attack surface and reduce certainty about who is eligible to vote. From a security perspective, more openness in handling election data must be paired with stricter safeguards and independent verification. Otherwise, the risk to confidence in our elections will keep growing.

At stake is more than partisan advantage; it is the integrity of the process that decides who governs the country. When the institutions charged with protecting voter data hesitate to act, citizens are left wondering whether politics trumps security. That doubt corrodes trust in ways that last far beyond any single incident.

Picture of The Real Side

The Real Side

Posts categorized under "The Real Side" are posted by the Editor because they are deemed worthy of further discussion and consideration, but are not, by default, an implied or explicit endorsement or agreement. The views of guest contributors do not necessarily reflect the viewpoints of The Real Side Radio Show or Joe Messina. By publishing them we hope to further an honest and civilized discussion about the content. The original author and source (if applicable) is attributed in the body of the text. Since variety is the spice of life, we hope by publishing a variety of viewpoints we can add a little spice to your life. Enjoy!

Leave a Replay

Recent Posts

Sign up for Joe's Newsletter, The Daily Informant