Cited, verified accountability journalism.

Crosscheck

Fact-check

The Arizona Voter Data Breach and the 2020 Election Security Claim

A real confession and real non-prosecution, but framing voter-roll scraping as proof the election was insecure inverts what CISA's security claim actually covered.

By · 2026-08-07

Misleading

New evidence further undermines claim that 2020 election was 'most secure' in history (Trump Truth Social, Aug 7, 2026)

Mostly True

A hacker admitted to stealing Arizona voter data in the 2020 election

True

The hacker destroyed evidence related to the 2020 Arizona voter data theft

Mostly True

Prosecutors took no action against the hacker who admitted to the 2020 Arizona voter data theft

The Claims Under Review

On August 7, 2026, President Trump posted to Truth Social:

"New evidence further undermines claim that 2020 election was 'most secure' in history: https://justthenews.com/politics-policy/elections/new-evidence-further-undermines-claim-2020-election-was-most-secure"

That post linked to a Just The News article reporting on FBI documents released one day earlier by the White House Government Transparency Task Force. The Reddit community r/Conservative circulated the story the same day with three specific claims: that a hacker admitted to stealing Arizona voter data in the 2020 election, that the hacker destroyed evidence, and that prosecutors took no action.

All four assertions, Trump's framing and the three factual sub-claims, are assessed below.

What CISA's "Most Secure" Claim Actually Said

The phrase being disputed originated in a November 12, 2020 statement from the Election Infrastructure Government Coordinating Council and the Cybersecurity and Infrastructure Security Agency (CISA), then led by Christopher Krebs, a Trump appointee. The operative sentence was:

"There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised."

The statement addressed voting systems: the hardware, software, and networks that record, tabulate, and transmit ballots. It did not claim zero cyber incidents occurred in 2020. It did not claim voter registration databases were impenetrable. It did not cover the management of voter rolls. Trump fired Krebs five days after the statement, on November 17, 2020.[4]

That scope matters for every claim that follows. Voter registration files and voting systems are separate infrastructure. A breach of one says nothing about the integrity of the other.

What the Declassified Documents Show

On August 6, 2026, the White House Government Transparency Task Force released declassified FBI case files documenting the following sequence of events:[2][3]

Between October 21 and November 2, 2020 (12 days, ending one day before Election Day), an individual at a Fountain Hills, Arizona residence exploited a vulnerability in Maricopa County's voter registration portal. He wrote a PowerShell script that iterated through voter ID numbers in the URL, extracting registration records at scale. The FBI determined he obtained between 633,000 and approximately 2 million voter files. About 930 of those records contained protected information: domestic violence victims, judges, and law enforcement officers whose addresses are shielded by statute.[3]

When FBI agents executed a search warrant at the residence, they found the individual had already wiped his hard drives and deleted copies from Google Cloud. He was interviewed, acknowledged what he had done, said he was "100 percent accountable," and expressed remorse. He described himself as a hobbyist hacker who had noticed the vulnerability by seeing his own voter ID exposed in a URL.[2]

The FBI presented the case to four prosecutorial offices. All four declined to bring charges:

  • U.S. Attorney's Office for the District of Arizona (declined 2021)
  • Arizona Attorney General's Office
  • Maricopa County Attorney's Office
  • Pinal County Attorney's Office

The Arizona Attorney General's Office told reporters the case was declined under the prior administration, and noted that "the information in question was also publicly available." The Maricopa County Attorney's Office cited a conflict of interest: as county counsel, it legally represents the Maricopa County Recorder, which was the potential victim, making prosecution untenable. The FBI closed the investigation in May 2023.[5]

Note on the data: Most voter registration information in Arizona is a public record. The bulk of the 633,000 files could lawfully be obtained through a formal records request; the breach's primary harm was the extraction of the 930 protected records, plus the automated exploitation of the county's website. This partly explains why prosecuting under the Computer Fraud and Abuse Act (CFAA) was complicated: several circuits have found that accessing publicly available data through unconventional means does not clearly constitute "unauthorized access" under the statute.

There is no indication in any document released to date that voter registrations were altered, that ballots were accessed, or that vote tallies were affected. All reporting outlets covering the story, including those with conservative editorial positions, state this explicitly.

Claim-by-Claim Verdicts

Misleading
Trump Truth Social post (Aug 7, 2026): "New evidence further undermines claim that 2020 election was 'most secure' in history."

The underlying fact, that a cyber breach of voter registration files occurred in Arizona before the 2020 election, is confirmed by declassified FBI documents. The post is accurate in that narrowly factual sense.

The misleading element is the word "undermines." The 2020 "most secure election" claim made by CISA covered voting system integrity (no votes deleted, changed, or lost). The Arizona incident involved voter registration files, not voting systems or ballots. No votes were changed. The Just The News article Trump linked to acknowledges this directly: "None of the evidence released so far by the White House suggests that votes were manipulated or provides proof of widespread fraud."

A post that says new evidence "undermines" a claim, while the linked article concedes the claim's core remains intact, misrepresents the weight of the evidence. The real question the evidence raises is not whether votes were secure, but whether voter registration infrastructure was adequately protected and whether non-prosecution was appropriate. Those are legitimate concerns; they are a different claim.

There is also a notable conflict in the information chain: the documents were released by the White House Government Transparency Task Force, which is chaired by John Solomon, who simultaneously founded and leads Just The News, the outlet Trump's post linked to. Solomon identified and amplified documents his own task force released, a loop with no independent editorial step between release and amplification. (See "The Information Chain" below.)

Mostly True
A hacker admitted to stealing Arizona voter data in the 2020 election.

The confession is confirmed: the individual told FBI agents he wrote a script to exploit Maricopa County's site and extract voter files, said he was fully accountable, and described the process in detail. The FBI case files corroborate the admission with seized hardware and server logs.

Two qualifications keep this from a full "True." First, "stealing" is colloquially accurate but technically imprecise for data exfiltration: the original records remained on the county's server; copies were extracted. Second, "in the 2020 election" carries an implicit suggestion that the election itself was compromised. No votes were affected. The breach occurred around the 2020 election, not within its systems.

True
The hacker destroyed evidence related to the 2020 Arizona voter data theft.

Confirmed by the FBI case files. Before agents arrived to execute the search warrant, the individual wiped his hard drives and deleted the Google Cloud copies of the extracted data. The FBI documented this in its case record. The suspect himself acknowledged the destruction. The claim is accurate.

Mostly True
Prosecutors took no action against the hacker who admitted to the 2020 Arizona voter data theft.

It is accurate that all four prosecutorial offices declined to bring charges despite a confession and an FBI investigation. No criminal charges were filed. In that literal sense, "no action" is correct.

The phrasing implies the non-prosecution was unexplained or improper. The available record gives two stated reasons: the Arizona AG's office noted the data was largely publicly available (complicating the CFAA theory of the case), and the Maricopa County DA's office cited a direct conflict of interest because it represents the recorder's office that was the victim. Evidence destruction further weakened a case that would have needed to reconstruct the scope of harm. These are substantive legal reasons, not omissions from the record. The claim rates "Mostly True" because the prosecutors did decline, but "no action" overstates the inference of impropriety.

Who Is Involved and What Each Gains

Actor Position / Outcome What This Story Means for Them
Trump / White House Amplified The disclosure supports a years-long narrative that 2020 election security was overstated. The story arrived as the White House prepared a broader election-integrity document release campaign.
John Solomon / Just The News Primary beneficiary Solomon's task force released the documents; his outlet reported them first; Trump linked to that outlet. A closed loop with no independent verification step.
CISA / Election security officials (2020) Partially contested The "most secure election" claim's core (no votes changed) remains unrefuted. But the broader claim that election infrastructure was well-protected is harder to sustain when a voter roll containing protected identities was accessible via URL enumeration.
The hacker (unnamed) No legal consequence Confessed, destroyed evidence, escaped prosecution. The case is closed (2023). Current DOJ could theoretically revisit, but no active investigation has been announced.
Maricopa County / AZ prosecutors Under scrutiny The county's website had an elementary vulnerability (sequential voter IDs in a URL) that a hobbyist exploited for 12 days. Prior prosecutorial offices gave legal reasons for declining; how the current administration characterizes those decisions is an open question.
Voters whose data was taken Harmed, no remedy 633,000 people had registration data exfiltrated; 930 had protected identity information exposed. No charges, no civil remedy, case closed. They received no direct notification or compensation.

The Information Chain

The provenance of this story matters for weighing it. John Solomon is the founder and editor-in-chief of Just The News. He is simultaneously serving as a Special Government Employee chairing the White House Government Transparency Task Force. His task force identified and declassified the FBI case files on August 6, 2026. His outlet then published the primary report on those files. Trump's Truth Social post on August 7 linked to Solomon's outlet.[10][11]

Peter Loge, director of George Washington University's Project on Ethics in Political Communication, noted that Solomon's dual role "gives the perception of a conflict," adding: "He's a political commentator with his own platform, promoting the findings of an investigation that already has ideas about."[10]

None of this means the FBI documents are fabricated. The underlying case files appear to be authentic government records. But the path from "classified FBI file" to "Trump social media post" ran entirely through one person who had a professional and ideological stake in the story's framing. An independent news organization with no role in the document release has not yet published a detailed assessment of the complete files.

The Strongest Real Case for the Conservative Framing

Steelman: Why the Conservative Framing Has a Point Worth Taking Seriously

The fact-check above rates Trump's post "Misleading" because it conflates voter registration security with voting system security. But the narrower version of the concern is defensible and not addressed by that distinction.

The Maricopa County voter portal exposed 633,000 records through a method a hobbyist discovered by noticing his own voter ID in a URL. That is a poor security posture for a government database that includes protected identities of domestic violence victims and law enforcement officers. The 12-day window during which the exfiltration occurred, ending the day before the 2020 election, means this happened at the most sensitive moment in the electoral calendar.

A man confessed to a federal crime, destroyed evidence, and faced zero legal consequences. The reasons given (data was public, conflicts of interest) are legitimate, but they also mean the structural accountability gap is real: someone can exploit a government database, damage hundreds of protected individuals, destroy evidence, confess, and walk free because the data's public status creates a legal gray zone. That is a genuine flaw in the legal framework, and calling it out is not equivalent to claiming votes were changed.

Where the framing breaks down is the leap from "voter registration was inadequately secured" to "the election was not the most secure in history." Those are separate propositions. Accepting the first does not require accepting the second.

What to Watch

Forward Look

  • Continued document releases: The White House Government Transparency Task Force has released multiple tranches of election-related documents since July 2026. Additional releases are expected. Each batch arrives through the same Solomon-linked channel, so independent verification of the full files remains outstanding.
  • DOJ posture: The case against the Fountain Hills hacker was closed in May 2023. The current Department of Justice has not announced any intent to reopen it. Whether the political visibility of this story changes that calculus is the clearest near-term signal to watch.
  • Maricopa County infrastructure: The exploited vulnerability (sequential voter IDs in URL parameters) was a basic flaw. Whether the county has since remediated it and what other states run similarly structured voter portals has not been reported. A follow-up audit of state voter registration portal security would be the most directly useful next step for voter protection.
  • Broader election integrity campaign: Trump delivered a primetime address on election integrity in July 2026. This story was released within weeks of that speech. The document release program appears coordinated with the political calendar rather than driven by organic FOIA timelines. The question of whether additional disclosures will be timed to specific political moments is worth tracking.

Sources

  1. Truth Social post by Donald J. Trump, August 7, 2026
  2. New evidence further undermines claim that 2020 election was 'most secure' in history
  3. More than 600,000 voter files ripped off Arizona site in 2020 by hacker, but DOJ didn't prosecute
  4. No Prosecution For Hacker Behind 2020 Breach Of 633K AZ Voters
  5. FBI says hacker scraped MASSIVE voter data from Maricopa County in 2020 — Arizona officials DECLINED to prosecute
  6. Bombshell: Hacker Admitted to 2020 AZ Voter Data Theft, Destroyed Evidence — Prosecutors Did Nothing
  7. CISA says there's no evidence of election fraud; 2020 election was the most secure in American history
  8. It's Official: The Election Was Secure
  9. Hacker Admitted to 2020 AZ Voter Data Theft
  10. John Solomon's Trump administration role draws ethics scrutiny
  11. Misinformer John Solomon, who reportedly pushed for Trump's prime-time speech, has spent months claiming China interfered in the 2020 election
  12. Election Integrity — The White House
fact-check2020-electionelection-securityArizonaMaricopa-Countyvoter-dataCISAJohn-SolomonTrumpcybersecurityprosecutionJust-The-News

Get the biweekly digest

New Crosscheck fact-checks, every other Monday. Sourced, never spun.