Friday, August 7, 2026
Arizona News
Arizona Watcher
Menu
Phoenix·August 7, 2026·5 min read
Mariam DelgadoBy Mariam Delgado

Investigators Say Maricopa County Voter Files Were Scraped in 2020; Prosecutors Declined to Charge

Declassified investigative records show a 2020 cyberintrusion into Maricopa County’s public voter systems resulted in the exfiltration of more than 633,000 voter registration records and exposed over 900 records with sensitive information. The FBI traced the activity to a Fountain Hills residence and obtained a confession, but several prosecutorial offices declined to bring charges and the criminal file was closed in 2023.

100%

In the final days before the 2020 presidential election, more than 633,000 voter registration records were removed from a Maricopa County online system after an intruder exploited a vulnerability in the county’s public-facing website, declassified investigative files show. The breach included more than 900 voter records that contained sensitive personal details, and federal agents say they identified and interviewed a suspect who admitted writing an automated script to collect the files. Despite the admission, multiple state and federal prosecutorial offices declined to pursue charges, and the FBI closed the investigation in 2023 after investigators asked to retire the file.

Loading post…

Voters walk past a 'VOTE HERE / AQUI' sign outside a Maricopa County polling location — the county whose 2020 voter files were later copied in the reported hack.Voters walk past a 'VOTE HERE / AQUI' sign outside a Maricopa County polling location — the county whose 2020 voter files were later copied in the reported hack.

The activity was first logged in late October and continued through Nov. 2, 2020. A federal summary notes that the intrusion was detected by Maricopa County and reported through state intelligence channels the day before the election as an “attempt to scrape voter registration information.” The FBI’s cyber notes describe the tool used as a PowerShell script that exploited a weakness in the recorder’s website to iterate through URL parameters and harvest pages of registration data. The material in the government’s declassified memos places the start of the scraping on Oct. 21, 2020, and the endpoint at about Nov. 2, 2020, when county staff tightened controls.

Federal agents say they traced the automated traffic to an address in Fountain Hills, Arizona, and executed a search warrant after interviewing a resident there in the days following the election. The interview was memorialized on the FBI’s standard FD-302 summary form, which records the subject’s account of how he discovered an apparent vulnerability while entering his own voter data and then tested the site by changing seven-digit identifiers in the page URL. The man described himself as a “hacker or tinkerer” and told agents he later wrote a PowerShell script to automate the process, running it from early October until county defenses were changed.

In the interview summary, the subject estimated he had obtained between 1 million and 2 million voter files, though the FBI’s analysis of the county intrusion logged and reported a total of more than 633,000 records taken during the identified period. The agent’s notes say the subject eventually grew afraid of the consequences and tried to remove traces of his activity: he deleted files from cloud storage, scrubbed local hard drives and declined to notify media outlets he briefly considered telling. Later that same day, agents executed a warrant at the Fountain Hills residence and seized multiple pieces of hardware identified in search affidavits and reports — including eight hard drives, three computers and a collection of USB storage devices.

Election workers carry sealed ballot boxes at a counting center; federal memos say more than 600,000 Maricopa County voter records were taken in the 2020 incident.Election workers carry sealed ballot boxes at a counting center; federal memos say more than 600,000 Maricopa County voter records were taken in the 2020 incident.

The investigation generated sustained attention inside the Intelligence Community’s cyber logs in the days around the election, and by the morning of Election Day those logs indicated that non-public voter information had been collected. At the time county election officials said the intruder’s access was limited to the public registration interface and that the underlying voter file database had not been penetrated; the FBI’s subsequent work identified more than 900 records in the harvested data that contained private details, including entries marked with special statuses such as domestic violence protections and sensitive occupational flags.

Despite the investigative work and the subject’s admissions, prosecutors elected not to bring criminal charges. The U.S. Attorney’s Office in Phoenix formally declined prosecution on July 12, 2021, and other state and local prosecutorial agencies reviewed the matter and likewise chose not to pursue criminal filings at dates not otherwise specified in the investigative memos. FBI leadership informed outside reviewers that agents devoted significant resources to the inquiry but were unable to convince those prosecutorial bodies to charge the case. In May 2023, the investigative team asked the bureau to close the file and the case was administratively closed.

Government records make clear that voter registration files are distinct from ballots and that there is no evidence in the investigative materials that any ballots were altered as a result of this intrusion. Nevertheless, intelligence analysts have long warned that control of registration data could enable campaigns of voter suppression or other interference that would hamper the ability of affected citizens to cast ballots in later contests. Separate government documents released in other reviews note international actors have acquired very large collections of voter and consumer records, underscoring why access to such data is viewed as a potential national security and election integrity concern.

The Fountain Hills subject’s prior background drew attention during the probe. Publicly available records show he had been investigated in 2011 when he lived in Wisconsin; local officials there questioned him in connection with spoofed email activity surrounding a municipal election when he served in an information-technology role. The FBI’s forensic work sought to identify a full chain of custody for the seized devices and to determine whether the subject’s deletions had removed evidence of the scale of collection he described. After their review, agents documented the investigative steps, the interview, the seizure of hardware and the prosecutorial declinations in the closing memorandum that formally retired the investigation in 2023.

The documents assembled by investigators provide a detailed accounting of the technique used to gather the records, the timeline of activity, the location law enforcement tied to the traffic and the administrative decisions that followed. They also record competing public positions at the time: county election officials maintained that only registration numbers were exposed through the public-facing pages, while the FBI’s analysis identified hundreds of records containing non-public, sensitive flags. The criminal inquiry concluded without indictments, and the agency files list the reasons investigators closed the file after more than two years of work.

The declassified records were released August 6, 2026 by the White House Government Transparency Task Force during its review of 2020 election security. FBI Director Kash Patel wrote to the task force that the bureau devoted significant resources to the investigation but could not persuade federal or Arizona prosecutors to file charges despite the suspect's confession.

The Fountain Hills resident identified in FBI search affidavits has been reported in news accounts as 56-year-old IT professional Elliot Kerwin, who ran businesses including Desert Oasis Technology and Desert Oasis Tactical; Forbes reported agents served a warrant at his home and seized multiple hard drives, computers and USB devices during the 2020 probe.

Maricopa County’s own fee schedule allowed bulk purchase of voter-registration data — news reporting noted the county listed prices as low as $328 for one million or more records — meaning large collections of largely public registration fields could be legally obtained for a small fee.

Arizona law (A.R.S. §16-168) prohibits distribution of certain sensitive voter information and provides for protections (such as confidential-address or other exclusions) for groups including victims of domestic violence, law enforcement and certain public officials, which explains the presence of protective "special status" flags on some registration records.

Share
← Back to all stories
Add as preferred source on Google

Phoenix Weather

☀️
109°F
Clear · H 111° / L 87°
Arizona Watcher

Arizona news coverage updated throughout the day with local reporting from across the state.

Top Cities

  • Mesa
  • Phoenix
  • Tucson
All cities →

About

Arizona Watcher covers news from cities and communities across Arizona. Our team reports on local events, public safety, politics, and more.

RSS Feed

© 2026 Arizona Watcher. All rights reserved.

Facts sourced from public reporting.

Mesa NewsPhoenix NewsTucson NewsWeb StoriesAbout UsEditorial Guidelines
Legal Information
Privacy PolicyTerms of Use