Batch 1 summary
These documents are heavily redacted and mix finished intelligence assessments, internal analytic debates, inventories of allegedly compromised data, and raw unevaluated reporting. The summaries below describe what the visible text asserts; they do not independently validate those assertions.
- “18 States Memo”
A redacted actor reportedly obtained voter-registration information from 18 states and intended to use it for U.S.-person matching, election-related analysis, and public-opinion analysis. The data included names, birth dates, addresses, party affiliation, historical voting records, partial telephone information, military affiliation, polling locations, donation or election-expense information, and demographics. The memo warns that this information could be mined to evaluate U.S. identities and identify important targets.
- “200M Voter Records Compromised”
This memo says a PRC-related entity possessed a 2019 list of likely leaked or compromised datasets, mostly involving personally identifiable information. Although most listed targets were outside the United States, 97 entries were identified as U.S.-origin data involving companies, government bodies, and NGOs.
The election-related entries included a dataset of 204,822,241 voter records, several state voter databases ranging from roughly 1.7 million to 7.9 million records, additional databases of unknown size, and election-related emails from a named U.S. person. The records reportedly contained voter IDs, names, addresses, dates of birth, gender, telephone numbers, and citizenship information. The broader inventory also covered medical, business, website-login, social-networking, NGO, government, and defense-related information. The document catalogs apparent possession of compromised data; it does not, in the visible text, establish that the listed holder personally conducted every original breach.
- CIA WIRe: “China: Cyber Activities Probably Prelude to Election Espionage”
This July 2020 assessment describes Chinese cyber operations, particularly APT31 spear-phishing and tracking-link activity, targeting a presidential campaign and senior U.S. officials. It judges that the immediate purpose was probably intelligence collection—mapping personnel, identifying vulnerabilities, and preparing possible follow-on access—rather than an active decision to covertly sway the election. However, it notes that the collected access and information could support influence operations later if Beijing chose to undertake them.
It also says Chinese actors had collected information from voter databases, a polling company, political and nonprofit organizations, fundraisers, and campaign advisers.
- December 2021 email, “Everyone’s favorite topic”
An ODNI/NIC official argues that a later intelligence report characterized Chinese units as conducting election influence even though similar personnel, intelligence, and methods had been described in 2020 as merely “issue-focused.” The author views this as an inconsistent analytic standard and recommends highlighting the discrepancy for oversight, especially where later reporting attributes activity to the Chinese military or government more confidently than the 2020 assessment did.
- November 20, 2020 email chain: “Massaged PDB”
This chain centers on an NSA analyst’s statement that a pending President’s Daily Brief had been “deliberately massaged” to avoid direct links to the election. Some ODNI/NIC participants interpreted this as a possible analytic-objectivity problem and argued that new intelligence reportedly showing Chinese election influence should be explicitly connected to the post-election 45-day Intelligence Community Assessment.
The chain also says a large underlying report had been divided into 13 reports and would be cross-posted or downgraded so it could be incorporated into the election assessment. The emails record participants’ concerns and interpretations; they are not themselves a completed adjudication of why the PDB was worded that way.
- November 23, 2020 follow-up email chain
This follow-up separates two issues: the apparent wording of the PDB away from election terminology, and the broader administrative effort to make NSA reporting available for the 45-day assessment. The writer expresses concern about “massaging” the analysis but acknowledges not having seen the PDB draft and notes that publication may have been delayed. The repeated underlying NSA email again states that the PDB avoided direct election links and that 13 reports were being prepared for possible use in the assessment.
- October 7, 2020 email chain on an “alternative analysis”
NIO Cyber and the Director of Election Threat Analysis planned a formally labeled minority or alternative NIC assessment. Its central judgment was that Beijing had taken low-level, exploratory steps to denigrate President Trump and shape voter perceptions, a stronger election nexus than the mainline assessment recognized. The authors intended to include a box accurately presenting the majority view while keeping their dissent on the record.
Several NSA analysts expressed support and said others had been reluctant to voice similar views because CIA and FBI were strongly committed to the mainline position.
- September 2020 coordination chain on the four-country election-security graphic
This long exchange documents the main analytic dispute over China. CIA, FBI, and State/INR generally argued that China had policy preferences and conducted broad influence activity, but that available evidence indicated Beijing probably was not attempting to influence the presidential outcome, partly because the risks of exposure outweighed potential gains. They warned against confusing issue-focused influence with election interference.
NIC officials wanted the product to retain the judgment that China preferred Trump’s defeat, add uncertainty caveats, and mention pro-China social-media videos criticizing and denigrating him. They argued that small-scale activities might be exploratory or precursors to election targeting and objected to overly definitive language.
The chain therefore shows a genuine tradecraft disagreement over definitions, confidence levels, attribution, and whether caution amounted to appropriate analytic discipline or improper “self-censorship.”
- FBI Albany IIR provided to Chairman Grassley
This is a raw information report, explicitly labeled “not finally evaluated intelligence.” It relays an indirect source’s allegation that the Chinese government produced fraudulent U.S. driver’s licenses so ineligible Chinese students and immigrants could cast tens of thousands of mail-in votes for Joe Biden. The source was uncorroborated and claimed to have received the information through a sub-source who cited unidentified PRC officials.
The allegation further claimed that TikTok user data would supply real identities and addresses. The FBI itself noted a major inconsistency: residential address was not a valid TikTok account field, and the report did not explain how China would obtain that information. This document should therefore be treated as a recorded allegation of low and unresolved reliability, not as an established finding.
- August 19, 2020 National Intelligence Council Assessment: “Foreign Threats to 2020 US Federal Elections”
The mainline assessment concludes that Russia, China, Iran, and some nonstate actors possessed capabilities to influence or attack election-related systems, while large-scale, undetected manipulation of voting would be difficult. It distinguishes broad election influence from the narrower technical category of election interference.
Its principal country judgments were:
- Russia: actively using proxies, media, cyber collection, and narratives—including allegations involving Biden, Ukraine, Burisma, mail voting, and voter fraud—to denigrate Biden, favor Trump, and intensify U.S. divisions.
- China: preferred Trump’s defeat and conducted broad influence, coercion, online messaging, and cyber collection, but was judged at that time not to have decided on a concerted effort to determine the presidential outcome because of uncertain benefits and the risk of backlash.
- Iran: sought to undermine Trump, weaken confidence in U.S. institutions, and amplify social divisions through covert online influence; the assessment lacked evidence that Iran then intended to manipulate U.S. election infrastructure directly.
The assessment also judged that local election systems could be disrupted or exploited, but that wide-scale vote manipulation would probably be difficult and exposed by paper trails, audits, postal tracking, or other safeguards. The comparative chart on page 8 visually portrays Russia, China, and Iran as using several overt and covert influence tools, while distinguishing observed activity from merely preparatory steps.
Batch 1 themes to carry forward
The central tension is not whether China collected U.S. political and voter information—it plainly appears throughout the documents—but
how that activity should be classified: traditional espionage and issue influence, exploratory election influence, or technical election interference.
The documents also have sharply different evidentiary weights. The NICA and CIA WIRe are coordinated analytic products; the email chains expose disagreements behind those products; the voter-data memos inventory apparent holdings; and the FBI IIR is expressly uncorroborated raw reporting. None of the visible material in this batch demonstrates that foreign activity changed certified vote totals, and the mainline assessment judged large-scale manipulation difficult and likely detectable.
Batch 2 summary
As with Batch 1, these files are heavily redacted. The summaries describe the documents’ visible claims and judgments, not independent verification of them.
- CIA Note: “Sensitive PRC Reporting from 2018–2020”
This note compiles selected—not comprehensive—reporting portraying the PRC as attempting to weaken President Trump politically. It says that in 2018 China sought to leverage domestic and foreign opposition to reduce his support, prevent reelection, and influence both the midterms and the 2020 presidential election. One proposed method was to identify pro-Trump states and industries and impose targeted tariffs so affected sectors would pressure the administration.
The note also describes influence through paid travel and speaking engagements for think-tank officials, academics, former officials, and other influential Americans; added attention to swing states and Trump campaign donors; economic leverage over major U.S. businesses; and alleged plans to pay journalists already critical of Trump to produce further negative coverage.
- President’s Daily Brief, 25 June 2020
Almost the entire PDB is redacted. The visible section says Beijing was escalating efforts to shape U.S. China policy and that Chinese officials had recommended collecting and using derogatory or compromising “black materials” against officials viewed as anti-China since at least January 2019. The item calls the underlying recommendation unusually detailed and authoritative.
Because the operational details and most analytic context are concealed, the visible material does not show how broadly such recommendations were approved or implemented.
- “PRC Analysis on U.S. Voter Registration Information”
This document says a PRC-linked analysis used voter-registration records from multiple states, apparently originating in midterm-election data. The records contained PII and were intended for mining, identifying or matching U.S. persons, conducting public-opinion analysis associated with a U.S. general election, and continuing collection of state voter-registration data.
Most subsequent pages are fully or nearly fully redacted, so the particular states, organization, methods, targets, and outputs cannot be reconstructed from the released version.
- “PRC Collection of U.S. Consumer, Military, Voter Registration Data”
The title and limited visible text state that PRC actors were aware by mid-2020 of U.S.-origin databases containing PII on millions of Americans and possessed capabilities to conduct identity-verification checks.
The table rendered on page 2 visibly lists a U.S. consumer database, a general voter-registration database, state-government voter databases associated with Georgia and Iowa, and a registered U.S. military-personnel database. The surrounding text refers to assembling a comprehensive PII baseline on U.S. persons, but most explanatory details are redacted.
- “PRC Target 2024 Election—2023 Information”
This report describes a 2023 exchange in which PRC-linked parties shared data—including voter-registration information from a named but redacted U.S. state entity—and discussed the following year’s U.S. election.
The document interprets references to an election system, observing voting in an unidentified swing state, and requesting a swing-state list as being “almost certainly” connected to the 2024 congressional or presidential elections. It also acknowledges uncertainty over whether the individuals involved had been instructed to target the election. This is therefore an analytic inference from a heavily redacted conversation, rather than visible proof of a completed operation.
- “PRC U.S. Presidential Election-Related Intelligence in 2020”
This document says a PRC-linked entity collected publicly available election information from a U.S. government website. The collected products included infographics and maps explaining differing state and local procedures for mail voting, post-election processing, result reporting, rumor countermeasures, and election safeguards.
Specific products included maps of state mail-ballot procedures and pandemic-related policy changes, a safeguards infographic, a post-election timetable extending toward Inauguration Day, and material on result-reporting risks and mitigation. The visible text establishes collection and analysis of open-source procedural information; it does not by itself establish malicious use.
- “PRC Shares 2020 U.S. Voter Registration Data for Cities within Seven States in 2023”
This report describes PRC-linked individuals exchanging requested 2020 voter data in 2023. One person also asked about Connecticut and Massachusetts.
The sample reportedly came from cities in Arkansas, Colorado, Connecticut, Florida, Ohio, Michigan, and North Carolina, and the provider stated that the 2020 data had previously been purchased. The visible portion does not establish whether the data was publicly purchasable voter-file information, unlawfully obtained data, or subsequently used operationally.
- Summary, Part 1
This one-page summary says China had extensive potential influence and cyber plans before the 2020 election to turn U.S. and international opinion against the Trump administration. Proposed themes included an economic recession, violent demonstrations and looting, social instability, doubts about Trump’s fitness to govern, and criticism of the federal COVID-19 response.
It says these narratives could be projected through TikTok, Facebook, Twitter, YouTube, mainstream media, overt or concealed influencers, and media contributors. It also mentions collecting information on senior officials to shape opinion about them.
- Summary, Part 2
Part 2 expands the proposed themes to racial tensions, police–activist conflict, civil-military tensions, party disputes, conflicts between Congress and the Trump administration, women’s rights, South China Sea policy, alleged U.S. war aims, and broader international propaganda.
It repeats the claimed ability to distribute such narratives through social and mainstream media and to use information on senior officials in personalized influence efforts.
- Summary, Part 3
Part 3 adds gun proliferation and immigration to the proposed influence themes. Suggested narratives included provoking dissatisfaction among migrant communities, organizing demonstrations over alleged U.S. human-rights violations, heightening conflict between pro- and anti-immigration constituencies, and encouraging anti-immigration demonstrations.
It again describes social media, mainstream outlets, overt and hidden influencers, and information about senior officials as possible delivery mechanisms.
Batch 2 themes to carry forward
This batch depicts a potential
collection-to-influence pipeline:
Acquire or purchase large U.S. datasets → match identities and analyze voters → study state procedures and swing states → identify officials, businesses, journalists, donors, and social divisions → apply economic, media, cyber, or interpersonal influence.
It also broadens the picture beyond classic cyber intrusion. The described tools include tariffs, corporate contracts, paid access to influential Americans, compromising information, public government data, purchased voter files, overt messaging, covert influencers, and tailored narratives exploiting existing U.S. disputes.
The evidentiary limitations are substantial. Many documents omit source descriptions, confidence levels, actor identities, operational details, and evidence of implementation. Several describe
plans, capabilities, discussions, recommendations, or analytical interpretations, rather than completed effects. Nothing visible in this batch demonstrates alteration of counted votes or certified election results.
Batch 3 summary
These documents combine an FBI retrospective review, a cyber-defense notice, and a White House public statement. Their evidentiary status differs substantially.
1. FBI Albany briefing handout and strategic review
This 35-page handout reconstructs the handling of the September 2020 Albany Intelligence Information Report alleging that China produced fraudulent U.S. driver’s licenses to enable tens of thousands of ineligible mail-in votes for Joe Biden. It includes dissemination and recall flowcharts, internal emails and instant messages, policy standards, a follow-up investigation, and recall statistics.
Source and reporting problems
The original report rested on a newly opened FBI source whose information came indirectly through a sub-source in China claiming contact with unidentified PRC officials. The reporting had
no corroboration, and the FBI had opened the source only ten days before acquiring the allegation.
Internal personnel raised specific concerns that:
- the reporting conflicted with the wider Intelligence Community’s assessment and the FBI director’s congressional testimony;
- the source or sub-source may have supplemented claims with open-source information;
- related reporting included a claim about underground Chinese facilities spreading coronavirus in Republican states, which officials characterized as approaching conspiracy theory;
- the source’s access, competence, reliability, and actual connection to PRC officials had not been established.
Recall of the first report
The IIR was disseminated on September 25, 2020, and rapidly drew attention at FBI headquarters. Headquarters officials argued that it should not have been released after an initial source contact without a second interview and pressed Albany to recall it until the source could be questioned again. Albany personnel initially maintained that the report met the FBI’s “DRAIN” dissemination criteria, but it was recalled later that day.
The formal recall directed recipients to destroy the original report and explained that it was being withdrawn to permit a source re-interview. It continued to warn that the information was raw, not finally evaluated, and should not be acted upon without FBI coordination.
Reissue dispute
Albany later considered issuing a second version based on a new source-contact report and a more explicit caveat that the information’s veracity was questionable. Some field personnel argued that withholding potentially significant threat reporting because it contradicted leadership testimony or carried political implications would itself risk politicizing intelligence. They favored disseminating the report with strong source warnings so the wider Intelligence Community could attempt to corroborate or disprove it.
Headquarters and Foreign Influence Task Force personnel responded that their objection was substantive rather than partisan: the information was not sufficiently authoritative, the title made a strong allegation unsupported by reliable sourcing, and further investigation was needed. On October 8, the task force declined to approve reissuance; Albany agreed, and the second draft was deleted on October 15.
Follow-up on counterfeit licenses
The FBI asked its Chicago office to coordinate with Customs and Border Protection to determine whether seized counterfeit licenses had been used for voter registration. CBP replied that it did not retain a usable list of all names and addresses and that the overwhelming majority of counterfeit documents it encountered were obtained by people aged 18–20 altering birth dates to evade alcohol-age laws. The released material does not establish that any seized license was used to register or cast a vote.
Procedural significance
The episode led FBI headquarters to require field offices to coordinate election-related raw intelligence with the Foreign Influence Task Force, Cyber Division, or Counterintelligence Division before dissemination.
The handout also puts the recall in institutional context: the FBI recorded approximately
1,130 IIR recalls from 2019 through mid-2025, including 154 in 2020. Albany issued 86 raw intelligence reports in 2020 and recalled only one—the fraudulent-license report.
Bottom line: the handout documents both concern about possible political sensitivity and extensive, concrete doubts about sourcing. It does not validate the fraudulent-license allegation; instead, it shows why the report was recalled and never reissued.
2. PRC download of voter-registration data from six states
This revised network-defense notice reports that a PRC computer-network-exploitation actor downloaded publicly available historical voter-registration repositories for:
- Colorado
- Connecticut
- Florida
- Michigan
- Oklahoma
- Rhode Island
The information covered approximately 2013–2021 and was hosted mainly on
commercial websites, not necessarily official state election systems. The same actor attempted but failed to download an Ohio voter-registration application from a government website.
The downloaded records apparently included names, party affiliations, email addresses, physical addresses, and telephone numbers. Analysts said such PII could theoretically support future cyber targeting or election-influence activity, but explicitly stated that the actor’s actual motivation was unknown.
The principal defensive warning is that foreign actors can collect voter files from third-party commercial repositories outside government monitoring.
Bottom line: this document establishes collection of publicly available voter data by a PRC cyber actor. It does
not show that official registration databases were penetrated, that records were modified, or that election results were affected.
3. White House Government Transparency Task Force statement
The July 13, 2026 statement announces the first disclosure by a White House task force created to recommend documents for declassification. It characterizes the released intelligence as showing that voter rolls from at least 18 states and more than 200 million additional voter records were “compromised” by the PRC.
It identifies 16 jurisdictions:
Alaska, Arkansas, Colorado, Connecticut, District of Columbia, Florida, Georgia, Iowa, Kansas, Maryland, Michigan, New York, North Carolina, Ohio, Oklahoma, and Rhode Island.
This is a
public policy statement, not an intelligence assessment. It does not define “compromised,” state whether each dataset resulted from a breach, purchase, leak, or public download, or explain how the listed records were connected to the PRC. That distinction is important because one underlying document in this batch specifically describes legally public records harvested from commercial sites rather than an intrusion into official infrastructure.
Batch 3 themes to carry forward
The batch highlights three recurring distinctions:
- Raw allegation versus validated intelligence: the Albany report contained a dramatic election-fraud allegation, but its indirect, new, uncorroborated sourcing did not survive review.
- Data acquisition versus election-system compromise: PRC actors collected substantial voter information, but at least some of it was publicly available or commercially hosted. Collection alone is not evidence that official records were altered.
- Public characterization versus underlying documentation: the White House statement uses the broad term “compromised,” while the source documents describe several different mechanisms—possible leaks, purchases, public downloads, and alleged clandestine collection—that should not automatically be treated as equivalent.
Batch 3 complete.