Arizona Attorney General's Office 2020 Election Investigation
This page highlights some observations of the Arizona Attorney General's Office 2020 Election Investigation of allegations from the Arizona Senate from September 24, 2021. The Arizona Attorney General (AZ AG) is responsible for investigating criminal allegations related to Election Fraud committed within the State of Arizona.
This website is focused on identifying governance gaps within Arizona Counties for the purpose of showing the need for Legislative Action to pass laws that hold the counties accountable for listening to and addressing citizen concerns. The AZ AG's report was used to identify potential governance gaps.
Separate from the collection of data being collected from the AZ AG's report to identify potential governance gaps, some of the inspector's observations are worthy of being highlighted on this page. Key points may be lost during the comparison of county behaviors to the US GAO's Green Book, which was being used as a standard for good governance in the absence of any known standard being applied by Maricopa County.
Finally, some of the inspector's investigative practices appear shallow, considering this was referred to the Arizona Attorney General's Office as a criminal investigation. Generally speaking, the Inspector relied heavily on interviews to reach report findings. None of the findings resulted in criminal charges. For example, five procedure violations in Allegation #2 were confirmed. These procedure violations were no by themselves acts of fraud committed by Maricopa County workers. However, these procedure violations were lapses in security measures intended to protect against fraud. Thus, Maricopa County workers did not commit acts of fraud, they knowingly or unknowingly, facilitated acts of fraud by not protecting early ballot security. The AZ AG's inspector could not determine the willingness of MC workers to participate in fraud without intrusive investigation to find objective evidence.
In a sad perspective, the AZ AG's shallow investigation seems in some ways to reflect poor governance at the state level whereas this assessment is concerned about poor governance at the county level. At its worst, the shallow investigation would appear to show collusion in the cover up of fraud perpetrated by others.
Was Poor Posting of Public Document Intentional?
The Arizona Attorney General's Office 2020 General Election Investigation is a publicly available document, at the following:
The document was posted rotated 90 degrees. Extra effort is needed by the public to rotate the document into the proper orientation before it can be read.
The AZ AG's Office posted a poor image of the document. As an image, report content cannot be copied. Efforts to use an Optical Character Recognition (OCR) to convert to a text file were unsuccessful. Behind the text, the image background is dark and hazy, which inhibits the OCR identification of text characters.
The poor quality of posting was either intentional or sloppiness considering the purpose of the posting was to communicate the results of the AZ AG's investigation.
Origins of the Criminal Investigation
Report Origin
- Karen Fann - President of the State of Arizona Senate submitted the allegations to the AZ AG's Office.
- Mark Brnovich - State of Arizona Attorney General received the allegations.
- Keith Thomas #395 - Assistant Chief Special Agent Criminal Division / Special Investigations Sections conducted the investigation.
Allegation #1 - Signature Verification
Interviews
- Nabor, Celia - Assistant Director of Early Voting
- Valenzuela, Ray - Assistant Elections Director
- [Withheld] - Personnel from Runbeck Elections Services Inc.,
- [Withheld] - Level 1 Signature Verifiers (assumed to be among the 33 permanent MC employees, not 40 temporary workers)
Objective Evidence
- Signature Verification training materials provided by the Arizona Secretary of State
- Signature Verification training materials from Maricopa County Elections Department
- Signature Verification training videos by the Maricopa County Elections Department
- Election data provided by the Maricopa County Elections Department
Data Notes
- Additional details are available from Special Investigation Section #SIS-2021-0482.
- All Mail-In and Drop Box ballots are sent to Runbeck Elections Services Inc where the ballots are scanned into batches. These images are then sent to the Maricopa County Elections Department where Signature Verification Process begins.
- Early ballots are sent to Signature Verifiers in batches of 250.
- Level I Signature verifiers will flag an early ballot that does not have a signature OR the signature cannot be verified.
- Flagged early ballots are "cured" by Level II Signature Verifiers. Flagged early ballots may be resubmitted for tabulation after the Level II Signature Verifier determines the early ballot is valid via the curing process.
- 1,910,317 early ballots were submitted to MC
- 17,126 early ballots were sent to Level II Signature Verifiers for curing.
- 15,084 ballots without signatures were cured (verified valid)
- 1,455 early ballots without signatures were rejected (not valid)
- 587 early ballots were rejected for "bad signatures" (not valid)
- 73 Level I Signature Verifiers were involved in the 2020 General Election
- 29 fulltime MC employees received signature verification training
- 4 parttime MC employees received signature verification training
- 40 temporary employees performed Level I Signature Verification without training
- Level I Signature Verifiers are expected to complete an early ballot verification at a rate of one ballot per 7.2 second (250 ballots per 30 minutes)
Inspector's Findings
- The AZ AG's inspector found "no Improper Procedures" were discovered.
- However, no procedures were referenced in the report, which would have served as objective evidence for the finding. The inspector relied on interviews.
Hypothetical Questions for the Inspector
- Did the Signature Verification training verify the competency of the Verifiers? If not, the training was for show, not impact.
- If training did verify the competency of the trainee's Signature Verification, did the verify assure competency at a rate of 7.2 early ballots per second?
- For a criminal investigation, how were untrained Signature Verifiers to ensure compliance with A.R.S. 16-550-01 if they were untrained? This appears to be more than a procedure violation as presented in the Inspector's findings.
- If training was important for 33 MC employees, then why didn't the 40 temporary workers receive the same training prior to performing Level I signature verifications.
- Did 587 "bad signatures" flagged seem unreasonably small considering the 1,910,317 early ballots submitted?
- Given the subjectivity of signature verifications, did 587 "bad signatures" seem unreasonably small when compared to 16,539 ballots flagged for having no signature? Having no signature is an easy decision; it's binary, there is a mark in the signature box or no mark. An actual signature is more complicated. Therefore, there should have been far more early ballots flagged for "bad signatures" than "no signatures."
Allegation #2 - Drop Box Collection
Interviews
- Eckstein, Tim - Maricopa County Legal Council
- Honey, Heather - from Verify Vote, which was the source of the original allegation
- Novak, Ed - Maricopa County Legal Council
- Puli, Andrew - from Verify Vote, which was the source of the original allegation
- Wick, Jason - United States Postal Service Inspector
Objective Evidence
- Arizona Secretary of State Drop Box procedures
- Maricopa County Drop Box procedures
- Early Voting Ballot Transport Statements (EVBTS)
Data Notes
- Numerous EVBTS were missing data and/or signatures (see report for details).
- MC staff stopped counting ballots on October 21, 2020 because "the number of received ballots became too large to utilize the ballot counter."
- The inspector notes state, "the decision was made to weigh trays."
- They began weighing boxes of ballots to estimate the number of ballots received.
- They began transmitting estimated early ballots by email instead of using the EVBTS forms.
- Ultimately, five procedure violations were confirmed by the AZ AG's inspector, which were associated with the following deviations:
- Drop Box collection teams of two were procedurally required to have one team member from each political party (Democrat and Republican). However, 15 of the collection team members did not identify as Democrat or Republican.
- The signatures from both of the collection team members were required on the EVBTS forms by procedure. However, one or both signatures were sometimes missing.
- Departure times were not always filled in on the EVBTS forms, contrary to procedure requirements.
- Signatures were for receipt inspections were not always on the EVBTS forms, contrary to procedure requirements.
- Ballots were not aways counted, contrary to procedure requirements.
Inspector Findings
- The AZ AG's inspector confirmed five procedures had been violations.
- No report information was available to identify who was responsible for these procedure violations.
- No report information was available to identify any corrective actions implemented to prevent a recurrence of these procedure violations.
Hypothetical Questions for the Inspector
- Why weren't the 56,226 undeliverable early ballots investigated for fraud; the number was far to high to be rationalized as citizen errors during the voter registration process?
- Why weren't any clarifying questions asked about the security or chain of custody measures to assure all the undeliverable early ballots matched the number of early ballots destroyed.
- Were any extra security measures applied to early ballots beyond what is routinely applied to all undeliverable first-class mail?
- Were the voter registration forms reviewed to determine if there were any patterns in the data to suggest fraud, such as some voter registrants accounting for unusually high occurrences of fictious addresses?
Allegation #3 - Election Management System
Interviews
- Bilotta, Gary, Director of Geographical Information Systems
- Cotton, Ben - CyFir Owner
- Gates, Bill - Maricopa County Board of Supervisors
- Jarret, Scott - Director of Elections for Ballot Tabulation
- Logan, Doug - Cyber Ninjas Owner
- Ramirez, Brian - Election Information Technology staff member
- Richer, Steven - Maricopa County Recorder
- Young, Nate - Director of Information Technology
Objective Evidence
- Maricopa County Elections Published Records
- Requested forensic pre-view of Maricopa County Election System
Sub-allegation #1 - EMS Data Purged
Investigation Notes
- Per Director of Information Technology stated EMS data purge was required for logic and accuracy tests.
- Per Elections Department policy backups were createed between 10/20/2020 and 11/16/2020.
Investigation Findings
- Undetermined - Agents are pending a date to review achieved data to ensure all election files are present.
- According to Elections Department personnel backups were available, but the investigator did not review as part of a criminal investigation.
Sub-allegation #2 - Election Files Deleted
Data Notes
- Data files are shared/transferred over the local network to the EMS server.
- Data files are removed from the tabulation stations when data space (memory) on the computer begins to get full.
- Since these files are not associated to the tabulation files stored on the EMS server, they are not backed-up or archived.
Findings
- Undetermined - Agents are pending a date to review achieved data to ensure all election files are present.
- According to Elections Department personnel backups were available, but the investigator did not review as part of a criminal investigation.
Sub-allegation #3 - Corrupt Ballot Images
Inspector's Notes
- Maricopa County Elections Officials randomly selected images from the date periods that Ben Cotton from CyFir claimed were corrupted and the were able to open all images.
Inspector's Finding
- Undetermined. Agents are pending a date to review archived data to ensure all election files are present.
- This allegation was for corrupted ballot images, not missing data files and not inability to open files, as MC Election officials claimed they were able to achieve.
Hypothetical Questions for the Inspector
- If Maricopa County Election staff was under criminal investigation, why would you allow them to perform random samples for use as factual evidence?
- Why were no images reviewed to support or refute the allegation of corrupted ballot images?
Sub-allegation #4 - Missing Ballot Images
Investigator's Notes
- Cloned copies of hard drives were provided to Cyber Ninjas and they were able to locate the files they claimed were missing.
Investigator's Findings
- Undetermined. Agents are pending a date to review archived data to ensure all election files are present.
- This allegation was for missing ballot images, not missing data files.
- This allegation was initiated by CyFIR and delivery of files to Cyber Ninjas was credited as action taken towards resolution of the allegation.
Hypothetical Questions for the Inspector
- Why were no images reviewed to support or refute the allegation of corrupted ballot images?
Sub-allegation #5 - Failure to Follow Basic Cyber Security Practices
Investigator's Notes
- The EMS server along [with the] other election equipment is configured in an air gapped standalone system (no outside connectivity outside of the controlled access room).
- Maricopa personnel assert that Cybersecurity and Infrastructure Security guidelines do not apply to this air gapped standalone computer configuration.
- The EMS server along with the other election equipment resides inside a controlled access room under 24-hour video monitoring.
- Further security requirements include a two-person rule to enter the room.
Investigators Findings
- Unfounded Allegation. Cyber Ninjas presented its opinions on these areas. There has been no indication of malicious or criminal acts performed by Maricopa County Elections Officials. Cyber Ninjas suggest a better practice base on their beliefs; however, Maricopa County Elections was within compliance of state and federal law as it pertains to these areas.
- MC Election officials' assertion of appropriate behaviors seems weak for the malicious or criminal behaviors under investigation.
Hypothetical Questions for the Inspector
- How the EMS computer system considered a standalone air gapped system if it is connected to the local area network (See Allegation #3, Sub Allegation #2)?
- Were video surveillance records of the EMS server and ancillary equipment for the period under investigation reveiwed? If not, were you relying on the assertion of the Election officials under investigation as objective evidence for no malicious or criminal acts performed?
- How was the two-rule stated?
- Were there any access logs, recording when each individual entered and exited the access point for the EMS server?
- Does the two-person control measures for EMS access seem disproportionately weak when compared to drop box pick up, which was investigated as Allegation #2. For drop box collection, two people from two different political parties (Democrat and Republican) are required to document the collection times in accordance with a procedure with perhaps a few hundred ballots at risk of corruption. For EMS access, any two people may enter the EMS server area without any controlling procedure or enter/exit logs with 1,910,317 ballots at risk.
- Given that federal and state laws are generally written at policy level, not for implementation level, how is assertions of compliance to laws applicable to measures to securely tabulate ballots, regardless of what's specified in law.
- Prior to this event, had MC Officials ever detected a violation of the two-person rule? If not, were security measures and video surveillance adequate to deviation from the two-person rule?
- Prio to this event, had MC Officials ever disciplined an individual for a violation of the two-person rule. If disciplinary actions were never taken for two-person rule violations, it's not really a rule.
- In the absence of any disciplinary actions, how was the rule communicated to the staff and did it include consequences for violations?
Sub-allegation #6 - Subpoenaed Equipment Not Yet Provided
Data Notes
- All data and equipment were provided as part of "the settlement agreement."
Findings
- Unfounded Allegation. According to the statements made by Mr. Bill Gates and a letter dated September 17, 2021 by State Senate President Karen Fann to Attorney General Marck Brnovich, all materials were provided to the State Senate by Maricopa County.
Sub-allegation #7 - Anonymous Logins
Inspector's Notes
- There were five Type 3 logins (Logon Type 3, also known as a Network Logon, occurs when a user or device connects to a computer over the network rather than through the console or a remote desktop session).
- The five Type 3 logins occurred between 11/18/2020 and 3/5/2021 and were identified by PacketWatch.
- Apparently, the Cyber Ninjas allegations were for a timeframe noted for the five Type 3 logins.
- No "script-based activities were performed during these anonymous logins as per the PacketWatch report.
Inspector's Findings
- Undetermined. The allegations by Cyber Ninjas appear to have different activity dates as to that which was reviewed by PacketWatch. Agents have a pending request to review anonymous logins with Election Officials.
Hypothetical Questions for the Inspector
- Why was PacketWatch presented as investigative data when its time frame was different than the Cyber Ninjas allegation?
Sub-allegation #8 - Dual Boot System Discovered
Data Notes
- There was a second hard drive on one computer; the drive was not powered on or used at any time while in Maricopa County's possession.
- This drive did not play a role in any Maricopa County election as it was not plugged into the computer, and therefore not operational.
- County Elections stated they did not retain copies of photos for this portion of the SLI report but stated they are available by request from SLI.
- County Elections was unsure if it was the same computer identified by Cyber Ninjas.
Findings
- Undetermined. County Elections makes statement about SLI Compliance finding related to dual boot systems; however, within the SLI report, there is no mention of this finding. Furthermore, County Elections stated they did not retain copies of photos for this portion of the SLI report but stated they are available by request from SLI. County Elections was unsure if it was the same computer identified by Cyber Ninjas. Based upon the two date available from Cyber Ninjas and SLI, and the different naming conventions, it is unclear if it is the same computer.
- For what it's worth, no follow up action is stated. There is no evidence to suggest follow-up was taken to any of the other undetermined findings.
Hypothetical Questions for the Inspector
- Why did you assert in the data that only one computer was effected, but then later acknowledge that two computers may have been effected?
- Why would you rely on County Elections personnel to say the second bootable drive was not connected or powered on when they are the ones under investigation?
Sub-allegation #9 - Operating System Logs Not Preserved
Data Notes
- Election Officials explain "the EMS server could be remotely accessed via the local area network within the air gap system."
- The EMS server was often accessed from the EMS Admin Station located within the BTC.
- Three EMS server access events were identified, with justification provided by the Election Department.
- On April 12, 2021, the Election Department identifies Brian Ramirez, a County Elections Staff Member, as having access. The county asserts that the second individual with Brian Ramirez is a coworker, but was not identified.
Findings
- Agents have a pending request to review log entries with Election Officials. This review will allow for a better understanding of the logs, and help further identify why there are discrepancies between the logs identified by Cyber Ninjas and the logs notated by PacketWatch and County Elections. Additionally, further questions will be asked regarding what actions were taking place on 2/11/21.
Hypothetical Questions for the Inspector
- Why was one county worker identified by name as accessing EMS on 4/12/21, but the other coworker's name was omitted from the report?
- What was of special interest during the 2/11/21 access?
Sub-allegation #10 - Internet Connections to the EMS
Data Notes
- AddLevel I Signature Verifiers are expected to complete an early ballot verification at a rate of one ballot per 7.2 second (250 ballots per 30 minutes)
Findings
- The A
