In the final weeks before the 2020 presidential election, a Fountain Hills, Arizona man quietly scraped more than 633,000 voter registration records from Maricopa County's public website โ and despite confessing to the FBI, was never charged.
Newly declassified FBI documents, made public Thursday by the White House Government Transparency Task Force, show the man discovered that voter ID numbers were visible directly in the county recorder website's URL. He wrote a PowerShell script exploiting the flaw and ran it from Oct. 21 through Nov. 2, 2020 โ the day before the election โ collecting hundreds of thousands of files, including roughly 930 containing sensitive personal details about domestic violence victims, judges, and law enforcement officers.
How the Breach Was Discovered
One day before the election, the Maricopa County Recorder's Office flagged an "attempt to scrape voter registration information" through the Arizona Counterterrorism Intelligence Center. The intrusion became the most frequently flagged incident in U.S. intelligence agencies' cyber logs around Election Day 2020; by 7:15 a.m. that day, the intelligence community already knew non-public information had been taken.
FBI agents traced the activity to the man's Fountain Hills home and interviewed him days after the election, seizing eight hard drives, three computers, and a bag of USB sticks. According to an FBI interview memo, the man, who described himself as a "hacker or tinkerer," said he first discovered the vulnerability in September 2020 after noticing his own voter ID number appeared in the website's URL. He tested it by entering different seven-digit numbers into the URL and finding he could pull up other voters' registration information.
The man told agents he estimated he had obtained between 1 million and 2 million voter files, though the FBI's own count places the confirmed number at more than 633,000. He said he grew scared once he understood the seriousness of what he'd done, considered going to the media, but ultimately kept it secret and deleted his files and cloud storage before agents arrived.
No Charges Filed
Despite the confession, the U.S. Attorney's Office in Phoenix declined to prosecute on July 12, 2021, under the Biden administration. According to FBI Director Kash Patel, who detailed the matter in a letter to the White House task force this week, the bureau also could not persuade the Arizona Attorney General's Office, the Maricopa County Attorney's Office, or the Pinal County Attorney's Office to bring charges. The FBI formally closed the case in May 2023, nearly three years after the intrusion, citing the declinations from all four agencies.
A Contradicted Public Statement
At the time of the breach, Maricopa County election officials said the intruder had accessed only the public registration page and could not reach the server storing actual voter registration files, adding that the only information obtained was voters' registration numbers. The newly released FBI records contradict that account, identifying more than 900 voter files that contained sensitive personal information, including domestic violence victim status.

Voter registration files do not include ballots, and there is no evidence any votes were altered as a result of the breach. Federal officials have separately warned since 2020 that large-scale access to voter registration data could be used to disrupt future elections; documents released by the Trump administration last month indicate China has obtained roughly 220 million such files.
Sources:
