Newly declassified FBI documents show a self-described "tinkerer" exploited a Maricopa County voter registration website for nearly two weeks before the 2020 election, confessed to agents, and walked free after every prosecutor who reviewed the case declined to act.
The White House made the files public Thursday after FBI Director Kash Patel sent a letter to the Government Transparency Task Force disclosing that the bureau had spent "significant resources" investigating the breach but could not persuade a single prosecutorial office to file charges. The U.S. Attorney's Office in Phoenix, the Arizona Attorney General's Office, the Maricopa County Attorney's Office, and the Pinal County Attorney's Office all passed. The suspect, a man living in Fountain Hills, Arizona, was never arrested.
The case file, reported by Just the News, lays out a breach that began in October 2020 and ran through the eve of Election Day, a window during which a single individual, armed with a simple script and a basic website flaw, pulled more than 633,000 voter registration records out of the nation's fourth-largest county.
The FBI's own case-opening memo describes the intrusion plainly. The suspect entered his personal information on the Maricopa County Recorder's voter registration website and noticed that his voter ID number appeared in the page's web address. He plugged in other seven-digit numbers and found that each one returned a different voter's registration data.
From there, he wrote a PowerShell script, a common automation tool, to cycle through numbers at scale. FBI documents place the confirmed exfiltration window between October 21 and November 2, 2020. The suspect himself told agents he began running the script at the start of October and estimated he collected between one million and two million voter files, a figure larger than the 633,000-plus the FBI confirmed.
Among the stolen records, 930 contained what the FBI called "sensitive voter information like domestic violence victims, judges and law enforcement officers." Those are the people whose addresses are shielded precisely because exposure could endanger their lives.
Maricopa County's Recorder's Office told the public at the time that the suspect had accessed only the voter registration website, not the server where files are stored, and that the only data obtained were voter registration numbers. The FBI's findings directly contradict that claim.
The county filed a tip through the Arizona Counterterrorism Intelligence Center on November 2, 2020, one day before the election. By 7:15 a.m. on Election Day itself, Intelligence Community cyber-intrusion logs flagged the Maricopa breach as the most prominent security incident in the days surrounding the vote. Federal officials knew, in real time, that non-public voter information had been compromised.
Several days after the election, FBI agents showed up at the suspect's home in Fountain Hills. They executed a search warrant and seized eight hard drives, three computers, and a bag of USB sticks. The suspect sat for an interview, described himself as a "hacker or tinkerer," and walked agents through exactly what he had done.
He told them he had discovered the vulnerability roughly two months earlier, in September 2020. He admitted he "realized the gravity of the situation and became scared." He considered going to the media but decided instead to keep the breach secret, scrub his hard drives, and delete files he had stored on Google Cloud. Forbes reported on the search warrant execution in December 2020.
None of it mattered. On July 12, 2021, under the Biden administration, the U.S. Attorney's Office in Phoenix formally declined to prosecute. The Arizona Attorney General's Office, the Maricopa County Attorney's Office, and the Pinal County Attorney's Office each followed suit at dates the released documents do not specify. By May 2023, the FBI's investigative team requested the case be closed. It was.
The declassified files do not reveal what specific federal or state charges the FBI recommended, nor do they record the reasons any of the four offices gave for walking away from a case that included a confession, seized hardware, and more than half a million compromised voter records.
Patel's letter to the transparency task force puts the blame squarely on prosecutors. The FBI director wrote that the bureau invested "significant resources" but could not get any of the four offices to act "despite an admission from the alleged hacker." The letter does not name the suspect.
The disclosure arrives as the Trump administration has pressed a broader election-integrity agenda. The Justice Department recently warned all 50 states that allowing noncitizens on voter rolls could trigger prosecution, a signal that federal enforcement priorities have shifted sharply from the previous administration's posture.
The suspect was not a first-time figure in election-related incidents. Forbes reported that in 2011, while working as an IT administrator for the City of Ashland, Wisconsin, he was investigated by local police over a series of spoof emails sent ahead of a local election. The outcome of that investigation is not disclosed in the released documents.
The Maricopa breach also fits into a wider picture of voter-file vulnerability. Documents released by President Trump last month showed that China has obtained roughly 220 million American voter registration files, a staggering figure that dwarfs the Arizona incident in scale but underscores the same basic problem: voter data is far more accessible than officials have acknowledged. The administration's disclosures about Beijing's acquisition of those records drew limited coverage from major networks.
One of the sharpest contradictions in the declassified file is the gap between what Maricopa County told the public and what the FBI found. The Recorder's Office said the suspect accessed only the voter registration website, not the underlying server, and obtained nothing beyond registration numbers.
The FBI's case documents tell a different story. Agents confirmed that 930 records contained sensitive personal details, including information identifying domestic violence victims, judges, and law enforcement officers. That is not a registration number. That is the kind of data that exists behind a firewall for a reason.
Meanwhile, states across the country continue to fight over who belongs on voter rolls and how those rolls are verified. A Florida federal judge recently ordered DHS to restore a citizenship verification database that had been taken offline, part of an escalating legal clash over whether states can confirm voters' eligibility at all.
The Intelligence Community's own cyber-intrusion logs, released with redactions, confirm that the Maricopa breach was the most flagged incident in the days surrounding the November 3, 2020 election. Officials knew before polls opened that non-public information had been scooped up. The public did not learn the full scope until now.
And the vulnerability itself was not sophisticated. A voter ID visible in a URL. A script any competent hobbyist could write. A county website that left the front door propped open for nearly two weeks before someone noticed and patched the firewall.
The suspect told agents he scrubbed his hard drives and deleted his cloud files after he "became scared." Whether every copy of those records was actually destroyed remains an open question the declassified documents do not answer. The FBI seized his hardware, but the files do not disclose what agents found on those eight drives, three computers, and USB sticks.
In New Jersey, the governor publicly accused the Trump administration of lying about noncitizens on voter rolls, only for DOJ evidence to suggest her own office already knew the problem was real. The Arizona case fits a similar mold: officials downplayed a breach while federal investigators documented something far more serious.
Networks that declined to carry the president's primetime address on election security may find it harder to ignore a case file that includes a confession, a contradicted county statement, and 633,000 reasons to ask why no one was charged.
When a man confesses to breaching a county election system, hands over his hardware, and still walks free because four separate prosecutors cannot be bothered to act, the question is no longer whether voter data is secure. It is whether anyone in authority cares enough to hold the line.