In September 2020, an Iranian hacker named Seyyed Mohammad Hosein Musa Kazemi broke into Alaska's voter registration database and walked out with more than 100,000 voter identities — names, Social Security numbers, driver's license information. He then recorded a video demonstrating how that stolen data could be used to generate fraudulent overseas ballot registrations through the UOCAVA system.
The FBI knew. CISA knew. The DOJ knew. They told us the opposite.
Three weeks after the breach, on October 22, 2020, the FBI and CISA issued a joint alert — FLASH alert AA20-296B — acknowledging that Iranian actors had targeted voter registration websites in at least 11 states. What the alert carefully didn't mention was that one of those breaches had actually succeeded. By October 30, CISA released a follow-up report that, once again, completely omitted the critical fact that Alaska's voter database had been compromised and over 100,000 records had been stolen.
Then came December 16, 2020. Chris Krebs — freshly fired by President Trump from his post as CISA Director — sat before the Senate Homeland Security and Governmental Affairs Committee and delivered the line that would become the establishment's favorite security blanket: "The 2020 election was the most secure in US history."
He said this knowing Iranian hackers had successfully breached a state voter registration system and stolen enough data to manufacture ballot requests. Under oath. On camera. To Congress.
The timeline here is everything. The breach happened in September and October 2020. The FBI's own alert went out October 22. Krebs testified December 16. And the indictment against Kazemi — filed in the Southern District of New York by U.S. Attorney Damian Williams — was sealed on October 20, 2021. It stayed sealed for nearly three years, until approximately August 2024, when FOIA documents obtained by investigative reporter Yehuda Miller finally dragged the full picture into public view.
For four years, the official government position was that 2020's election infrastructure held firm. No successful breaches. Most secure ever. Anyone who questioned that narrative — and we all remember this part — got labeled a conspiracy theorist, deplatformed, or dragged before congressional committees engineered to make them look unhinged.
Meanwhile, the people running those agencies had the receipts sitting in their own filing cabinets.
FBI Director Chris Wray was in the loop. DOJ Chief Bill Barr was in the loop. Krebs was in the loop. DHS was in the loop. The 2021 Cyber Risk Summary referenced the breach internally — but the public-facing messaging never did. Every press conference, every congressional hearing, every carefully calibrated statement was designed to maintain a story the people telling it knew wasn't complete.
The unsealed indictment from the Southern District of New York confirmed what the FOIA documents had already shown: the federal government's election security apparatus identified a successful foreign breach of American voter data, then systematically erased that fact from every public statement meant to reassure voters.
The predictable defense is already forming. "Alaska's breach didn't change any votes." "The data theft was contained." "The video Kazemi made didn't lead to actual fraudulent ballots being cast." These are the same agencies that spent four years insisting no breach occurred at all. Their credibility on the downstream effects of a breach they actively concealed is worth exactly what you'd expect it to be.
The question was never whether Iranian hackers single-handedly flipped an election. We can have that debate separately. The question is whether the people responsible for securing our elections lied to the public about whether those elections were actually secure. The FOIA documents answer that. They did.
And it wasn't a one-time omission under pressure. It was a sustained, coordinated suppression across multiple agencies, multiple hearings, and multiple official reports — all while the Americans raising concerns about election vulnerabilities were being systematically discredited by the very people hiding the evidence.
Krebs built an entire post-government career on that "most secure election" line. Cable news bookings, speaking fees, cybersecurity consulting gigs — all resting on a claim he made under oath while sitting on evidence that contradicted it. The FOIA documents had to be pried loose. The indictment stayed sealed for three years. The public statements were never corrected.
That's not an oversight. That's a business model.
