A hacker exploited a vulnerability in a Maricopa County, Arizona, website and obtained more than 600,000 voter registration files shortly before the 2020 election, according to newly declassified FBI and intelligence community records released Thursday.
The FBI eventually identified the alleged hacker, searched his Arizona home, and obtained an admission that he had written a computer script to exploit the vulnerability, the records show. But federal, state, and local prosecutors declined to bring charges, and the FBI ultimately closed the investigation in 2023.
The documents were released by the White House Government Transparency Task Force as part of the Trump administration’s examination of election security surrounding the 2020 contest. John Solomon, founder and editor-in-chief of Just the News, who also serves as a special government employee, previewed the records Thursday morning and has played a prominent role in recent administration releases of declassified material related to the election and investigations of President Donald Trump.
The latest disclosure brings that scrutiny back to Maricopa County, which became a focal point of disputes over the 2020 election after Joe Biden narrowly carried Arizona, and even became the site of a full-scale audit of the county’s vote, commissioned by the then-Republican state Senate president Karen Fann.
Some of the 2.1 million ballots cast during the 2020 election are brought in for recounting at an election ballot audit ordered by the Republican-led Arizona Senate at the Arizona Veterans Memorial Coliseum during a news conference on April 22, 2021, in Phoenix. (Ross D. Franklin/AP Photo, file)The incident highlighted in the declassified materials, however, concerns the security of voter registration information rather than ballots or vote tabulation. The documents provide no evidence that votes were changed or that the breach affected the outcome of the election.
According to an FBI summary, the Maricopa County Recorder’s Office submitted a tip through the Arizona Counterterrorism Intelligence Center on Nov. 2, 2020, reporting an “attempt to scrape voter registration information.”
An FBI document dated Nov. 3, 2020, details the opening of a cyber intrusion investigation after roughly 633,000 voter registration records were extracted from a Maricopa County, Arizona, website in the weeks leading up to the presidential election. (FBI)Investigators determined that an intruder used a PowerShell script to exploit a weakness in the county’s website, extracting more than 633,000 voter records between Oct. 21 and Nov. 2, 2020.
The FBI determined that 930 of the files contained sensitive information involving domestic violence victims, judges, and law enforcement officers.
The incident appeared repeatedly in intelligence community cyber logs tracking threats surrounding the election. By 7:15 a.m. on Election Day, intelligence officials knew the intrusion had resulted in the extraction of some nonpublic information, according to the records.
That finding provides additional detail beyond what Maricopa County has said publicly about the incident. The county has maintained that the intruder accessed its public-facing website and obtained “publicly available information,” emphasizing that the website was separate from the air-gapped system used to tabulate ballots. The newly released FBI records, however, state that the intrusion resulted in the extraction of some nonpublic voter information.
The Washington Examiner contacted a spokeswoman for the Maricopa County Elections Department.
FBI investigators traced the activity to a home in Fountain Hills, Arizona, and interviewed the suspect days after the election.
The man described himself as a “hacker or tinkerer” and said he discovered the vulnerability in September 2020 after noticing his voter identification number appeared in a website URL, according to an FBI interview report. The report also notes the alleged hacker was a college student, but redacted the school’s name, and mentioned that his “hacking activity” at one point led to a “meeting with the dean” of the college.
An FBI interview report dated Nov. 5, 2020, shows the suspect in the Maricopa County cyber intrusion describing himself to agents as a “hacker or tinkerer” who searched for computer vulnerabilities as a hobby. (FBI)He experimented with other seven-digit numbers and discovered he could access other people’s voter registration information. He then wrote a PowerShell script to automate the process, running it until Nov. 2, when Maricopa County detected the activity and fixed its firewall.
The suspect estimated he obtained between 1 million and 2 million voter files, although investigators documented roughly 633,000.
He told agents he eventually “realized the gravity of the situation and became scared” because he expected a visit from law enforcement. According to the FBI, he deleted files from Google Cloud and scrubbed his hard drives.

Agents executed a search warrant at his home the same day they interviewed him, seizing eight hard drives, three computers, and a bag containing USB drives, according to reports at the time.
Despite the investigative work, no prosecution followed.
FBI Director Kash Patel told the White House task force in a letter released Thursday that the bureau devoted “significant resources” to the case but could not secure charges from any of four prosecutorial offices that reviewed the matter.
The U.S. Attorney’s Office in Arizona declined prosecution on July 12, 2021, during the Biden administration, according to the FBI. The Arizona Attorney General’s Office, Maricopa County Attorney’s Office, and Pinal County Attorney’s Office also declined to prosecute, although the records do not specify when those decisions were made or detail each office’s reasoning.
With prosecutors declining to pursue the case, investigators requested that the FBI close it in May 2023, nearly three years after the intrusion was first detected.
‘OXFERD COMMA’ INVESTIGATION BEING CLASSIFIED BY WHITE HOUSE, WITH JOHN SOLOMON BRIEFING
Maricopa County became a national flashpoint in the days after the 2020 election, when several hundred Trump supporters — some of them armed — gathered outside its vote-counting center as ballots were still being tabulated, chanting “Count those votes!” and protesting amid the razor-thin contest.
However, the latest tranche of declassified materials serves as another example of election irregularities to the Trump administration’s broader examination of vulnerabilities surrounding the 2020 election. The administration last month released intelligence showing that foreign governments, including China, obtained large quantities of U.S. voter registration information in addition to identifying nearly 278,000 noncitizens registered to vote in federal elections.









