FBI Records Show Hacker Took 633k Maricopa County Voter Files Before 2020 Election, Prosecutors Declined Charges

maricopa

Newly released FBI records show that a hacker exploited a vulnerability in a Maricopa County website and extracted approximately 633,000 voter-registration records in the weeks before the 2020 presidential election, and that federal, state, and county prosecutors declined to bring charges.

Rep. Abe Hamadeh (R-AZ-08) questioned those decisions during a Friday appearance on John Solomon Reports.

“I’m still curious to know, you know, which attorneys at the U.S. Attorney’s Office, at the Arizona Attorney General’s Office, in Maricopa County, Pinal County, declined charges, especially when the FBI referred it and had this case pretty much handed on a platter to these prosecuting agencies, and they all refused,” Hamadeh said.

Hamadeh also pointed to Maricopa County’s size and technological resources while raising concerns about the cybersecurity of election systems elsewhere in Arizona.
“If you have these people, these hackers able to exfiltrate into the data systems of a big county like Maricopa, imagine what they can do to some of these smaller counties that don’t have the cyber tech and the counter cyber measures that Maricopa County may have,” Hamadeh said.

The records, released as part of the White House’s election-integrity disclosures, include the FBI’s opening and closing documents, an interview report and an Aug. 4 letter from FBI Director Kash Patel.

“The FBI confirmed that voter records were illegally extracted from the site and identified a suspect who admitted the crime,” Patel wrote.

According to an FBI opening document, the Maricopa County Recorder’s Office notified the bureau on Nov. 2, 2020, through the Arizona Counter Terrorism Information Center that there had been an attempt to scrape voter-registration information.

Investigators determined that an intruder had been obtaining registration data from a county website since Oct. 21 through a PowerShell script that resulted in the exfiltration of approximately 633,000 voter-registration records.

About 930 of those records contained sensitive voter information involving domestic violence victims, judges and law enforcement officers, according to the FBI. The information included full names, voter identification numbers and party affiliations. The records did not include Social Security numbers.

Investigators said the website permitted the intruder to place identification numbers directly into its URL, bypassing normal authentication requirements. The suspect automated the process through a PowerShell script that sequentially entered voter identification numbers.

Maricopa County detected a spike in website traffic on Nov. 2 and configured its firewall through Cloudflare to impose traffic-rate limits, according to the FBI document.

The bureau traced the activity to a Fountain Hills residence. According to an FBI interview report, the suspect told investigators that he discovered the vulnerability around September 2020 after noticing his own voter identification number displayed in the website URL.

He entered several other seven-digit numbers and discovered that other voters’ registration information could be accessed, then developed a script to automate the process.

The suspect estimated that he ultimately obtained between 1 million and 2 million records, although investigators documented approximately 633,000 exfiltrated records. He stored the information on personal hard drives and through Google Cloud before deleting the material, according to the FBI.

Agents executed a federal search warrant at the residence Nov. 5, 2020. A subsequent investigation included analysis of seized devices and records from the suspect’s bank, social-media and email accounts.

The bureau ultimately found that the suspect had developed and operated the PowerShell script and deleted the information he had scraped. Investigators “did not find indications of a domestic or foreign influence” over his actions, according to the FBI’s May 2023 closure memorandum.

Despite the investigation and the suspect’s admission, four prosecuting offices declined the case.

The U.S. Attorney’s Office for the District of Arizona declined prosecution. The Maricopa County Attorney’s Office also declined and informed investigators that the Arizona Attorney General’s Office had declined the matter. The FBI then presented the case to the Pinal County Attorney’s Office, which also declined prosecution, according to the closure memorandum.

The U.S. Attorney’s Office declined prosecution on July 12, 2021, according to reporting from Just the News, citing the FBI records. The released FBI records do not state when the remaining offices declined the case.

Investigators requested that the FBI close the case on May 23, 2023, citing the federal, state, and local prosecutorial declinations.

The FBI disclosures differ from Maricopa County’s public description of the intrusion the following year.

The newly released records provide answers to questions raised by the Arizona Daily Independent more than five years ago.

In January 2021, ADI reported that the FBI had seized computers and hard drives from the Fountain Hills residence of an information technology professional while the public remained unaware of what voter information had been obtained during the intrusion.

A May 2021 ADI follow-up reported that Maricopa County officials said no confidential voter files had been accessed, although publicly accessible voter information may have been viewed or copied. At the time, officials had not disclosed what specific information was accessed, and the FBI and U.S. Attorney’s Office had provided no further details.

The records also reveal what was unknown when ADI first reported on the investigation: the FBI identified the suspect, obtained an admission, investigated the intrusion through 2023 and presented the case to four prosecuting offices, each of which declined prosecution.

The records concern voter-registration data and do not establish that ballots were accessed or votes were altered. Just the News reported that voter-registration files do not contain ballots and that there is no evidence votes were changed as a result of the intrusion.

Hamadeh described the breach during the interview as “a direct attack on democracy” and said Arizonans continue to seek accountability.

“The win that the American people had here in Arizona, especially what we’re still trying to get, is justice,” Hamadeh said.

Hamadeh has pushed election-related legislation since entering Congress, including the SAVE America Act. In July, he called on the Senate to advance the measure, which requires proof of U.S. citizenship to register to vote in federal elections and identification when casting a federal ballot.

About ADI Staff Reporter 14550 Articles
Under the leadership of Editor-in -Chief Huey Freeman, our team of staff reporters bring accurate,timely, and complete news coverage.

Be the first to comment

Leave a Reply

Your email address will not be published.


*