What Do the Election Security Documents Say About Chinese Interference in U.S. Elections?
Photo: SimpleImages/Getty Images
Introduction
The Trump administration on Thursday, July 16, released intelligence products and other documents about possible foreign interference in the 2020 elections. The documents themselves show an intelligence community working diligently and professionally on one of the hardest issues they have to tackle, if you understand the culture and the context. But some will try to use this release as fodder for political fights; some on the fringes of these political fights may even use it to justify extreme, illegal measures. It is important to understand what is and is not in those documents and to distinguish between propaganda efforts by our adversaries and actual interference in election infrastructure to change votes. The real message must not get lost: Adversaries still seek to weaken the United States from within by making us doubt the democracy that defines us.
Democracy works because people across the political spectrum agree that elections are the best way to select leaders. That is why allegations of election interference are so insidious. If the system itself is in doubt, then so are the outcomes.
Foreign attempts to interfere in elections are far from new. The Soviet Union worked to undermine democracy in sometimes fantastical ways. Russia continues those efforts. Iran in 2020 ham-handedly tried a disinformation campaign posing as the Proud Boys. Democracy survived all of these, but the modern era of social media and aggressive foreign interference in elections, plus AI’s ability to tailor influence campaigns rapidly and at scale, amp up the potential risk.
The documents that the current administration just published portray election influence efforts by a formidable adversary: China. The allegations are in alignment with Beijing’s standard operating procedure, where information operations play a central role in strategic competition.
Q1: What do the documents say about the security of voting machines?
A1: First and most importantly, the documents state clearly that there is no evidence any votes were changed in the 2020 election. However, there is evidence that hackers could, in some circumstances, alter the outputs of electronic voting (for example, with direct physical access to a machine). This is why election officials take great care to secure access to voting machines and implement tampering protection methods. One document reviewing a study by the Cybersecurity and Infrastructure Security Agency (CISA) says, “Election-related software, like all complex software, contains vulnerabilities that require timely remediation,” and that “CISA assessors gained full network control within hours or days, demonstrating that many [state, local, tribal, and territorial] partners remain soft targets incapable of stopping even moderately skilled adversaries.” These concerns are real, but theoretical—researchers have accomplished manipulation of machines in controlled environments, but there is no evidence that these techniques have been used in live elections.
Several documents in the declassified set are good explanations of the voting machine issue. The intelligence community-wide memorandum written by the National Intelligence Council (NIC) from January 2020 titled “Vulnerabilities in U.S. 2020 Election infrastructure” is a good, clear, and comprehensive exploration. Separately, the NIC’s assessment from August 2020 titled “Foreign Threats to 2020 U.S. Federal Elections” lays out why manipulating elections on a large scale is so difficult: “Post-election audits and paper trails also most likely would uncover such efforts in nearly all U.S. states. Similarly, foreign actors would have difficulty coordinating a large-scale campaign to manipulate mail-in voting, and robust postal tracking probably would detect any large-scale effort.”
Q2: What do the documents say about election interference from China?
A2: The release includes two categories of allegations about Chinese efforts to influence the election with propaganda and other efforts. First, there is an allegation that China stole (or bought) millions of voter records in the 2020 elections, which fits with Chinese patterns of data theft for the last 20 years. Its motivation was likely to better understand the electoral landscape in the United States, perhaps with an intent to manipulate voter mindsets in the future. Second, China in 2020 was attempting to shape public perceptions of the candidates and the election, as well as compromise political figures.
One document reports that China “was in possession of” data sets that included voter registration information, including 204,822,241 records. The document is silent on how China got the data; it just says that the collection indicated China had it. A second document refers to PRC analysis of voter registration data from 18 states. That report is heavily redacted, but it does not appear to say how China got the data. Neither report has a date attached, and it is impossible to know if the two documents refer to two separate data sets.
Voter records are full of personal data, but they are also in many cases publicly available, or available for purchase. While their possession is disconcerting, China likely gained little advantage from the records. More likely, the new information was additive to the millions and millions of other records China has stolen in recent decades. Another set of intel (Summary Clean PART 1, 2, and 3) said that China “had extensive plans to utilize potential [REDACTED] and cyber operations to sway public opinion against the Trump administration and international opinion against the U.S. government.” The campaign would have centered around painful, yet obvious, key themes: gun proliferation, immigration policies, racial tension, police-community tensions, military-community tensions, and women’s rights. It is unclear from the available data whether China actually executed on the plans. Critically, neither the documents nor the president’s speech allege that China actually manipulated votes in any way. They are not alleging that China breached live voter rolls or the e-pollbooks at polling places.
There are also allegations in the documents that China was attempting to influence senior officials’ perceptions. For example, a President’s Daily Brief (PDB)—memos the president and his cabinet receive as a high priority nearly every day—from June 25, 2020, points to “China’s attempt to use blackmail against a U.S. administration official” by threatening to release derogatory information via social media. The intelligence community assessed that the threat was “credible.” The same PDB points to this as part of a pattern: “Lower level Chinese officials have recommended collecting and using ‘black materials’ against perceived anti-China U.S. officials since at least January 2019.” Separately, a CIA analytical piece from July 1, 2020, indicates that China since 2018 had been engaging in cyber espionage to gain access to the “personal email accounts of senior U.S. leadership, including individuals in the Executive Office of the President and high-ranking individuals in multiple Executive Branch organizations, Congress, and the federal judiciary.” It goes on to say that Chinese state-sponsored cyber actors targeted then-Vice President Biden’s campaign.
These tactics are offensive—every American should be offended—but the public should also have the right perspective on how much impact they really have: China has stolen millions of records multiple times; trying to gain insight into U.S. voting preferences is not difficult and is largely open-source intelligence; blackmail is one of the oldest spy tricks in the book. Americans should be outraged at China, but also at Russia, Iran, and anyone who tries to divide the United States from within. Doubting the security of elections based on thin accusations furthers the adversary’s cause. The better reaction is not to take the bait, to read critically, to evaluate the credibility of sources, and to elevate political debate.
Q3: Do the documents show an intelligence community cover-up of election-related information?
A3: No, not at all. The documents themselves show the intelligence community repeatedly warning of Chinese election interference attempts. One example, from a World Intelligence Review (WIRe) in 2020: “During the past year, Chinese cyber actors have collected U.S. election-related information from U.S. voter databases, a polling data company, political and nonprofit organizations, fundraisers, and advisory organizations for political campaigns.” Another, from an assessment in August 2020: “We assess that China prefers that President Trump be defeated; in the past few months it has stepped up public rhetoric criticizing his Administration, which it recognizes may affect the election.” These are two examples just from the declassified intel drop; there are most likely many others that remain classified.
Pulling together scattered data points to show a coherent, accurate picture of an adversary’s activities is difficult in the best of times. But when that adversary is an exceedingly secretive target, like China, and when the topic is among the most sensitive the intelligence community has to tackle, like election security, the challenge is extreme. Election security as a topic is a nightmare for the intelligence community, which has long taught its professionals to be unbiased and apolitical and to protect the American people and their right to live free in a democratic society. Anything that even remotely seems to look inward or touches politics is handled with extreme levels of caution. These are high stakes, which means senior leaders need to be involved, for they are the ones who will answer to Congress, the president, and the American people. The internal debate over this intel is where professionals see normal analytical disagreements handled carefully, while laypeople may cry conspiracy.
What the documents show is an honest, and valuable, analytical debate about the scope of China’s activity and its intent. On one side, you have CIA and FBI analysts arguing that China is collecting information but doing little by way of large-scale influence efforts. They are likely comparing China’s work to Russia’s and Iran’s and seeing a significant gap in scale and aggression. On the other side is the national intelligence officer for cyber and the director for election threat analysis (D/ETA), both very senior analysts with long and distinguished service records. They are less convinced that China’s efforts have been limited or ineffective. In a 30-page exchange of views over email, there is a back and forth debating the right way to parse the language so that everyone can agree it is complete and accurate. But they can’t get there. The national intelligence officer for cyber and the D/ETA then make a prudent suggestion: “Rather than continue to argue about this and drive you all nuts, we are opting to publish an alternative analysis NIC memo. We think this is the best way for us to put our perspective on the record while not getting in the way of what the rest of the community wants to say.” This is a normal approach in the post-Iraq weapons of mass destruction world, where analysts have been taught to embrace disagreements and lay out all the arguments for the policymakers to see. Smart people can come to different conclusions when the data is scant and the adversary is working hard to hide its intent. Even so, the difference of opinion is relatively limited, debating the scope and impact of China’s activity, rather than the fact of the activity.
Some are also pointing to the issuance and then withdrawal of an intelligence report out of the Albany FBI field office as evidence of a cover-up. This is equally a misunderstanding of the nuances of intelligence work. The intelligence information report (IIR) in question was based on an unreliable source providing thin information. The source was a defector in the United States who had heard a rumor from a friend in China, who had supposedly heard the same rumor from a Communist Party official. That’s third-hand knowledge at best, which should correctly be viewed with skepticism. Further, the content of the information was highly inflammatory—an allegation that China had produced fraudulent driver’s licenses and exported them to the United States so that “tens of thousands” of Chinese students and “immigrants sympathetic to the Chinese Communist Party” could vote for then-Vice President Biden. This is the kind of information that causes an uproar when it hits. If true, it would mean a massive escalation in China’s election interference efforts and perhaps a devastating blow to relations. In other words, it is a big allegation by a source with distant knowledge. It needed review, caveats, and follow-up questions before it was published.
The internal FBI debate that ensued was fairly normal, albeit messily handled. The IIR hit the wires, and senior FBI leadership started asking questions about whether the information was good and whether the source could answer some additional questions. Basically, they were saying that this would cause a storm, so FBI had better be confident in the information. In the end, leadership in the counterintelligence division at FBI HQ decided to recall the IIR until the source could be recontacted for more details on where they got the information. This is prudent, and by itself is not at all evidence of a cover-up. Plenty of other information existed about other Chinese influence efforts, and no one on that email chain was suggesting that the information be permanently squashed. Frankly, if the intelligence community published every outlandish piece of intelligence volunteered by an unverified source, the databases would be full of nonsense. Judgment is required in discerning what is and is not potentially accurate and useful information. Further, a recall is hardly rare. Sometimes new information comes out that shows the source was likely lying, or at least was incorrect. Sometimes there are substantive revisions to reports as new information comes to light. The documents released state that FBI recalled more than 1,000 intelligence reports from 2019–2025, when the document was issued.
In another email chain, the National Security Agency says it “deliberately massaged our one pending PDB to avoid any direct links to the election.” It goes on to say that reports will be available for “the 45-day piece,” which is a required after-action report about any evidence of interference put together by the entire intelligence community on a fixed 45-day timetable. There is an uncharitable way to read this email that implies hiding information. But that’s hearing hoofbeats and assuming zebras rather than horses. A key piece of information gives much better insight into that exchange—anything election-related has to go through an additional set of scrutiny by a specialized group that deals with this extraordinarily sensitive topic. The authors of that PDB decided to write their piece without referencing elections, still communicating the message but avoiding the extra editing and instead leaving the specialized team to give the definitive word. It was not a cover-up, but an effort to defer a hot topic to a group of people better suited to deal with it comprehensively.
Conclusion
What should be clear is that China, Russia, and Iran all want the United States to collapse from the inside, under the weight of its own disagreements. Clearly, they know they can’t beat the United States on the battlefield, so they want to weaken it from within. They see its open society and ability to debate as a weakness, when it is really a strength. Americans need to read critically—and carefully—to ask what the source is and what their agenda might be before absorbing the information in a mindless doom scroll. Critical to that thinking process is finding trusted sources to better understand the context surrounding the allegations.
Emily Harding is director of the Intelligence, National Security, and Technology Program and vice president of the Defense and Security Department at the Center for Strategic and International Studies in Washington, D.C.