Newly declassified FBI documents are raising questions about a previously reported cybersecurity incident in Arizona after revealing that a hacker extracted a massive quantity of voter-registration data from Maricopa County around the time of the 2020 presidential election.
According to documents reported by Just the News, investigators determined that the individual used an automated computer script to obtain hundreds of thousands of voter-registration records from the Maricopa County Recorder’s Office website.
One count cited in the reporting puts the number of affected voter files at approximately 633,000. The FBI interview with the suspected hacker describes an even larger volume of extracted records during repeated attempts.
The distinction between voter-registration data and actual ballots is critical.
Nothing in the newly released material establishes that the hacker changed votes, created fraudulent ballots, altered election results, or gained access to voting machines. Merely obtaining voter-registration information does not provide the ability to cast or modify votes.
What the documents do describe is a significant data-security problem involving one of the most closely watched counties in the country.
Maricopa County includes Phoenix, contains the majority of Arizona’s population, and was central to the extraordinarily close 2020 presidential contest in the state.
According to the newly released material, the stolen information included records belonging to 930 people whose files contained sensitive information, including domestic-violence victims, judges, and law-enforcement officers.
The FBI investigated and eventually interviewed the individual responsible.
“The FBI spent significant resources solving this cybercrime,” FBI Director Kash Patel wrote in a letter released this week.
Yet the investigation did not produce a prosecution.
“The United States Attorney’s Office for the District of Arizona, the Arizona Attorney General’s Office, the Maricopa County, Arizona Attorney’s Office, and the Pinal County, Arizona Attorney’s Office were presented with the findings of this investigation,” Patel wrote. “All declined to prosecute the matter.”
The newly declassified FBI interview provides a detailed account of how the breach allegedly occurred.
The individual, whose name is redacted in the released document, described himself to investigators as a “hacker or tinkerer.” He allegedly discovered that his voter identification number appeared in the URL associated with his registration information on the Maricopa County Recorder’s website.
He then began experimenting.
According to the Nov. 5, 2020 FBI interview, the individual “developed and tested a PowerShell script, which accessed and extracted the voter registration data from the Maricopa County Recorder’s website.”
The first attempt was relatively limited.
The hacker estimated that he obtained between 100 and 1,000 records during what he called a “trial run.” He stopped because the script was not functioning properly and began thinking about how to improve it.
By early October, according to the FBI account, he had done exactly that.
“Around the beginning of October 2020, [redacted] improved his PowerShell script,” the document states. “He ran the script again up until around November 2, 2020, when Maricopa County fixed their firewall.”
The hacker told investigators that he likely would have continued extracting information had the vulnerability remained available.
The FBI document says the individual estimated that between 1 million and 2 million voter-registration records were extracted into text files on his personal hard drives, amounting to approximately four gigabytes of data.
He eventually realized county officials had blocked what he was doing when his script began returning an error message and could no longer make successful requests.
The details are considerably more extensive than what the public was initially told about the incident.
Contemporary reporting portrayed the breach as relatively limited. Election officials said at the time that the affected system was associated with voter registration rather than vote tabulation and indicated that sensitive information had not been compromised, according to reporting from Tucson.com.
The newly released FBI material provides a fuller picture of what investigators subsequently learned about the scale of the data extraction.
The hacker reportedly told investigators he had no intention of selling the information. He considered it publicly available and acknowledged that he could have purchased voter data through legitimate channels but wanted to obtain it without paying.
Eventually, according to the FBI interview, the seriousness of what he had done began to sink in.
He told agents that he “realized the gravity of the situation and became scared.”
Perhaps most strikingly given the timing, he considered telling the media but decided against it.
The hacker reportedly believed revealing what he had done would create a “s***storm” during the election.
That does not establish that the breach affected the election outcome. The material cited by Just the News explicitly stops short of that conclusion.
“None of the evidence released so far by the White House suggests that votes were manipulated or provides proof of widespread fraud,” reporter Steven Richards wrote.
That qualification matters. A cybersecurity vulnerability in voter-registration infrastructure and proof that fraudulent votes determined an election are two very different things.
But absence of evidence that votes were altered does not make the underlying security failure insignificant.
Large voter databases can contain information useful for identity theft, targeted disinformation, harassment, or attempts to interfere with voters. Such concerns become more serious when foreign governments and sophisticated intelligence services are involved rather than an individual experimenting with a PowerShell script.
The revelations have consequently entered the current political debate over election legislation.
President Donald Trump has pointed to election-security concerns while urging Congress to pass the SAVE America Act. Among its provisions, the legislation would establish documentary proof-of-citizenship requirements for federal voter registration.
Opponents of such requirements have argued they could make registration more difficult for eligible citizens who lack readily available documentation. Supporters argue citizenship verification is a basic election-security measure.
The Arizona hack does not resolve that policy dispute, nor does it demonstrate that noncitizens voted because of the Maricopa County vulnerability.
What it does provide is a documented example of an individual discovering a weakness in election-related infrastructure, automating its exploitation, extracting an enormous quantity of voter data and admitting what he had done to federal investigators — only for multiple prosecutorial offices ultimately to decline the case.
That is remarkable enough without claiming the documents prove something they do not.
The 2020 election has generated years of arguments about fraud, voting machines, ballots and election security. These documents do not establish widespread fraudulent voting or demonstrate that Arizona’s presidential result was changed.
They expose a different problem: a hacker found a vulnerability in a major county’s voter-registration system during an intensely contested presidential election and exploited it on a massive scale.
The FBI figured out who did it.
The hacker admitted what he had done.
And prosecutors still declined to bring charges.