AZ SOS Adrian Fontes cheers AZ Governor Katie Hobbs in the Capitol (Screenshot: @AZSecretary)
White House Declassifies 2020 Maricopa County Voter Data Breach
A self-described hacker bypassed security and stole 633,000 voter registration files, Biden-DOJ declined to prosecute
By Megan Barth, August 6, 2026 1:14 pm
The White House Government Transparency Task Force released newly declassified FBI and intelligence community records Thursday detailing a significant cybersecurity incident in Arizona’s largest county just days before the 2020 presidential election.
A new release on election integrity shows Arizona’s largest county had a major election data breach just DAYS before the 2020 presidential election. A self-described hacker bypassed security and stole 633,000 voter registration files – but the Biden DOJ declined to charge him. pic.twitter.com/Z5PdT6yxqa
— The White House (@WhiteHouse) August 6, 2026
A self-described “hacker or tinkerer” exploited a vulnerability on the Maricopa County Recorder’s Office website, extracting approximately 633,000 voter registration files—including 930 containing sensitive, nonpublic information on domestic violence victims, judges, and law enforcement officers—between October 21 and November 2, 2020. The suspect later confessed to FBI agents after a search warrant was executed at his Fountain Hills home on November 5, 2020. Despite the admission and evidence, the U.S. Attorney’s Office for the District of Arizona, the Arizona Attorney General’s Office, the Maricopa County Attorney’s Office, and the Pinal County Attorney’s Office all declined to prosecute. The FBI closed the case in 2023.
According to the declassified documents, the Maricopa County Recorder’s Office first flagged the activity on November 2, 2020, reporting an “attempt to scrape voter registration information” through the Arizona Counterterrorism Intelligence Center. Investigators determined an intruder used a PowerShell script to bypass security weaknesses on the public-facing website. The intelligence community’s cyber intrusion logs around the November 3 election identified this as the most flagged security incident of the period. By early morning on Election Day, agencies were aware that nonpublic data had been accessed.
In an FBI interview memorialized in an FD-302, the man admitted discovering the vulnerability in September 2020 after noticing his own voter identification number appeared in a website URL. He tested it with other numbers, then automated the process with a script that ran until the county patched its firewall on November 2. He estimated extracting between 1 million and 2 million records (investigators documented roughly 633,000), storing them on personal hard drives and a Google Cloud account—totaling about four gigabytes. After realizing the seriousness, he said he became concerned, considered contacting the media, then scrubbed the files and drives before agents arrived. He described himself as a “hacker or tinkerer,” expressed remorse, and claimed he believed the data was largely public.
Agents seized eight hard drives, three computers, and USB devices during the search. No evidence indicated foreign involvement, alteration of ballots or registrations, or access to the actual voter registration database itself—only the website data. The files did not include Social Security numbers or driver’s license numbers in most cases, though the sensitive subset raised particular concerns.FBI Director Kash Patel noted in a letter accompanying the release that the Bureau devoted substantial resources to the probe but could not secure charges from any of the declining offices.
This declassification comes amid the Trump administration’s broader review of 2020 election security through the Government Transparency Task Force. White House communications highlighted the breach occurring “just DAYS before” the election and the Biden-era DOJ’s decision not to charge the suspect despite his confession. The revelations underscore long-standing vulnerabilities in Arizona’s election infrastructure that California Globe has previously documented.
In September 2025, the Globe reported on a July 2025 cyberattack in which pro-Iranian hackers—attributed with “moderate confidence” by state officials to Iran’s Islamic Revolutionary Guard Corps or affiliates—breached the Arizona Secretary of State’s Candidate Portal. The attackers swapped candidate photos with images of Iranian leaders, posted Persian-language anti-American propaganda, and attempted deeper SQL server intrusions while probing for access to voter systems. The site went offline for about 24 hours.
As the Globe detailed at the time, Arizona Rep. John Gillette (R-LD30) launched “Project Sentinel” to expose the incident, citing legacy systems running outdated code incompatible with post-2018 NIST standards, weak encryption, and potential “sleeper code” insertions. While no voter data was confirmed stolen, the hackers returned after initial mitigation. Gillette alleged that Democratic Secretary of State Adrian Fontes blocked full federal engagement with DHS and CISA despite legal mandates, and referred the matter for criminal probes into potential neglect and misuse of Help America Vote Act funds. Fontes described the breach as “contained” and sought additional cybersecurity funding.
California Globe has also covered numerous Arizona election integrity issues, including undeliverable mail ballots in Navajo County ahead of the 2026 primary and the deployment of DOJ election monitors to the state. Those accounts, alongside the 2025 Iranian incident and now the declassified 2020 Maricopa records, highlight persistent questions about voter roll security, website vulnerabilities, and administrative responses in a key battleground state.
Maricopa County officials at the time of the 2020 incident characterized it as unauthorized access to publicly available information on the website, distinct from any breach of the secure voter registration system or tabulation equipment. Independent audits of the county’s 2020 election processes and machines found no evidence of vote alteration or hacking of tabulators. The newly released records, however, confirm that sensitive nonpublic data was among the files taken and that the scale—hundreds of thousands of records—exceeded earlier public characterizations in some accounts. No charges were ever filed in the 2020 case. It quietly ended in 2023.
The declassified materials now make public what investigators knew in real time: a vulnerability was exploited on the eve of a presidential election in one of the nation’s most pivotal counties, a confession was obtained, and prosecutorial discretion at every level resulted in no accountability—against a backdrop of continued foreign interference of Arizona’s election systems years later.
- White House Declassifies 2020 Maricopa County Voter Data Breach - August 6, 2026
- Trump Touts Working Families Tax Cuts in Las Vegas, Warns of Democratic Open Borders and Communist Threat - August 5, 2026
- Three New Polls Show Lombardo Expanding Lead Over Ford in Nevada Governor’s Race - August 5, 2026




