Four separate prosecutors at the federal, state, and county levels declined to bring charges against a hacker who admitted to stealing data from 633,000 Maricopa County voter records in 2020, according to documents released by the White House Government Transparency Task Force. The case underscores a significant gap in accountability for election-related cybercrimes, as the FBI ultimately closed its investigation after years of unsuccessful attempts to secure a prosecution.

The breach occurred when a self-described 'hobbyist hacker' exploited a vulnerability in the Maricopa County voter registration website. According to an administration official, the hacker extracted between 1 million and 2 million records over several months. Of the 633,000 records confirmed as exfiltrated, about 930 contained sensitive, non-public information, including data related to domestic violence victims. Officials emphasized that no ballots or registrations were altered as a result of the breach.

FBI Investigation and Suspect’s Admission

The FBI led the investigation into the breach, ultimately identifying a suspect who admitted to the conduct. The hacker told investigators he had noticed the website's vulnerability for some time and used a script to extract data through the same webpage voters use to enter their information. The FBI determined the hacker acted alone, finding no evidence of collaboration with domestic or foreign actors after reviewing his bank records and communications.

An administration official, speaking on a call with reporters, said, "The suspect, perhaps to the chagrin of his attorney, admitted to all of the conduct involved, including that he noticed the vulnerability for quite some time."

The suspect reportedly expressed regret, telling authorities he was "100% accountable for his actions and was deeply regretful," and apologized for the breach. The FBI's investigation found no indication that the hacker had any broader agenda or was working with others, and there was no evidence of financial gain or outside influence.

Prosecutors Decline to Pursue Charges

Despite the FBI's findings and repeated requests, four prosecutors declined to pursue the case. The first rejection came from the U.S. Attorney for the District of Arizona on June 12, 2021. The Arizona attorney general, Maricopa County district attorney, and Pinal County district attorney also declined to prosecute. By 2023, after multiple attempts to interest prosecutors at various levels, the FBI closed the case due to lack of prosecutorial interest.

An administration official said the White House has since requested information about the prosecutors who declined to act. The official also noted that former Cybersecurity and Infrastructure Security Agency (CISA) Director Chris Krebs was briefed on the breach, which was labeled as a matter of "highest concern," but Krebs did not publicly address the issue.

Officials who declined to prosecute have not publicly commented on their decisions. The reasons for declining to bring charges have not been made public, and the released documents do not specify whether legal, evidentiary, or policy considerations played a role in the decisions.

Broader Context and Security Concerns

The breach has drawn renewed attention to election system vulnerabilities, particularly as some officials and media outlets have described the 2020 election as highly secure. While no votes or registrations were changed, the exposure of sensitive voter data has raised questions about the adequacy of cybersecurity protections for election infrastructure. The fact that data related to domestic violence victims was among the information accessed has heightened concerns about the potential risks to individuals whose information was exposed.

Supporters of the current system argue that the lack of impact on ballots or registration integrity demonstrates the resilience of election processes. They point to the fact that, despite the breach, the core mechanisms of the election remained intact. However, critics point to the incident as evidence of ongoing risks and the need for stronger cybersecurity measures to protect voter information and maintain public trust in election systems.

The White House Government Transparency Task Force released the documents detailing the breach and investigation on Thursday morning. The release of these documents is part of a broader effort to increase transparency around election security incidents and to inform the public about the steps taken in response to cyber threats targeting critical infrastructure.

As the 2024 election cycle approaches, the incident serves as a reminder of the persistent challenges facing election officials and law enforcement agencies in safeguarding voter data. The lack of prosecution in this case has prompted calls for a review of legal frameworks governing cybercrimes against election systems, with some advocates urging policymakers to clarify and strengthen laws to ensure accountability for similar breaches in the future.

The Bottom Line

  • Four prosecutors declined to charge the hacker behind the 2020 Maricopa County voter data breach.
  • The FBI closed its investigation after failing to secure a prosecution at any level.
  • The White House has requested information on the prosecutors who declined to pursue the case.