Investigators Say Maricopa County Voter Files Were Scraped in 2020;…

Arizona Watcher

In late Oct.–Nov. 2, 2020, an intruder scraped Maricopa County’s public voter-registration system, exfiltrating more than 633,000 records and exposing over 900 records that contained sensitive personal flags.

Investigators say the attacker used a PowerShell script to exploit a vulnerability in the recorder’s public website by iterating URL parameters; the scraping began Oct. 21 and continued until county staff tightened controls on Nov. 2.

The FBI traced the automated traffic to a Fountain Hills address, interviewed a resident who admitted testing the site and writing the script, and executed a warrant seizing multiple hard drives, computers and USB devices.

The subject told agents he may have collected 1–2 million files; FBI analysis of the county intrusion logged about 633,000 records for the identified period and noted the subject deleted cloud copies and scrubbed local drives.

Maricopa officials said access was limited to public registration pages, but FBI work identified more than 900 records containing non-public flags such as confidential-address or other protective statuses.

Despite the interview and seized evidence, prosecutors declined to file charges; the U.S. Attorney’s Office in Phoenix formally declined prosecution on July 12, 2021, and the FBI administratively closed the file in 2023.

Declassified investigative records were released Aug. 6, 2026 by the White House task force; news reports identified the Fountain Hills resident as Elliot Kerwin and the FBI said it devoted substantial resources to the inquiry.

Declassified investigative records show a 2020 cyberintrusion into Maricopa County’s public voter systems resulted in the exfiltration of more than 633,000 voter registration records and exposed over 900 records with sensitive information. The FBI traced the activity to a…

Read the full story