When Insiders Are the Threat

Burbank (Dropsite News), Greenhalgh (Free Speech for People), Marks (Executive Director · Coalition for Good Governance), Jefferson

Voting Village @ DEF CON 33 · Day 1 · Voting Village

Overview

This talk, "When Insiders Are the Threat," presented at Voting Village, unpacks a series of coordinated, multi-state breaches of U.S. election systems, potentially representing the largest election security compromise in the nation's history. The speakers — Marilyn Marks, Susan Greenhalgh, David Jefferson, and Jessica Burbank — meticulously detail how partisan actors, often with insider assistance, gained unauthorized access to sensitive voting machine software and data across multiple states following the 2020 election. The core message underscores the profound implications of these breaches for election integrity, the ease with which current systems can be exploited, and the alarming lack of a comprehensive federal investigation into these interconnected incidents.

Watch on YouTube

Visual summary for When Insiders Are the Threat by Burbank, Greenhalgh, Marks, Jefferson
Visual summary for When Insiders Are the Threat by Burbank, Greenhalgh, Marks, Jefferson

Key moments

  1. 0:00 Introduction to the largest election security breach
  2. 1:40 Marilyn Marks unveils largest voting system breach
  3. 2:00 Details of the Coffee County software and data breach
  4. 3:55 Insider's recorded confession about copying Coffee County data
  5. 5:50 Videos proving breach surface despite official denials
  6. 7:30 CNN report: Surveillance video confirms Coffee County breach
  7. 9:50 Deep dive into the extensive nature of the data copying
  8. 11:20 Origins of the breach: Planning at Tamatley Plantation & Willard Hotel

When Insiders Are the Threat

Speakers: Marilyn Marks, Executive Director, Coalition for Good Governance; Susan Greenhalgh, Free Speech for People; David Jefferson; Jessica Burbank, Reporter, Dropsite News

Conference: Voting Village

YouTube: https://www.youtube.com/watch?v=OyUNja7QSv8

Overview

This talk, "When Insiders Are the Threat," presented at Voting Village, unpacks a series of coordinated, multi-state breaches of U.S. election systems, potentially representing the largest election security compromise in the nation's history. The speakers — Marilyn Marks, Susan Greenhalgh, David Jefferson, and Jessica Burbank — meticulously detail how partisan actors, often with insider assistance, gained unauthorized access to sensitive voting machine software and data across multiple states following the 2020 election. The core message underscores the profound implications of these breaches for election integrity, the ease with which current systems can be exploited, and the alarming lack of a comprehensive federal investigation into these interconnected incidents.

The presentation highlights the critical vulnerabilities exposed when trusted insiders facilitate access to election equipment for partisan entities. Unlike white-hat security research aimed at improving system robustness, these breaches were allegedly orchestrated to challenge election results and potentially leverage the acquired software for future manipulation. The speakers argue that the widespread circulation of this proprietary software, even in binary form, grants malicious actors an unprecedented roadmap to identify and exploit weaknesses in the very systems underpinning American democracy, posing a significant and enduring threat to future elections.

Background

▶ Watch: Introduction to the largest election security breach (0:00)

The genesis of this exposé lies in the contentious aftermath of the 2020 U.S. Presidential election, specifically the efforts by allies of President Trump to challenge election results through various legal and extra-legal means. Marilyn Marks, Executive Director of the Coalition for Good Governance and a key plaintiff in the Curling v. Raffensperger lawsuit in Georgia, stumbled upon the first signs of this widespread activity. Her organization was already engaged in litigation to address concerns about Dominion BMDs (Ballot Marking Devices) in Georgia. It was through this legal context that a startling revelation emerged: a stranger, during a recorded phone call, confessed to having chartered a jet to Coffee County, Georgia, to "copy everything" from the election systems, and claimed the same people were involved in similar activities in Michigan. This confession, initially dismissed by authorities, eventually led to the uncovering of surveillance videos and depositions that confirmed the breach.

The problem's existence stems from a confluence of factors: the highly politicized environment post-2020, the perceived weaknesses in election system security, and critically, the cooperation of local election officials. The talk details how, rather than pursuing military seizure of voting machines—a discussion reportedly held in the White House in December 2020—the strategy shifted to gaining "voluntary access" through insiders. This approach exploited the trust placed in local election administrators, turning them into unwitting or complicit facilitators of unauthorized access. The speakers emphasize that while the voting systems themselves have inherent vulnerabilities, the problem was exacerbated by the deliberate actions of partisan groups seeking to obtain and study the proprietary software for their own ends, rather than for public good or security improvement.

Key Findings

▶ Watch: Details of the Coffee County software and data breach (2:00)

The talk reveals several critical findings that collectively paint a picture of a coordinated and extensive attack on election infrastructure:

  • Discovery of the Coffee County Breach: Marilyn Marks's lawsuit unearthed the initial breach in Coffee County, Georgia, where, on January 7-8, 2021, and again later in January, a team of Republican operatives, allegedly arranged and paid for by attorney Sydney Powell on behalf of the Trump campaign, gained access to the entire election management system. They copied all software and data from the 2020 election and the 2021 Senate runoff, including election management software, electronic poll books, and other components. This was confirmed by newly surfaced surveillance videos and audio recordings, despite initial denials from the Georgia Secretary of State's office.
  • Multi-State Coordinated Network: The Coffee County incident was not isolated. Susan Greenhalgh and Jessica Burbank detailed how the same individuals and organizations were involved in similar breaches or attempted breaches across multiple states:
  • Antrim County, Michigan: Software access was gained during a legal challenge to vote counting errors, later shared more broadly.
  • Wayne County, Michigan (Detroit): An attempted breach, also paid for by Sydney Powell, using the same firm, Sullivan Strickler, that went to Coffee County.
  • Cross Village Township, Emmet County, Michigan: Two individuals in tactical gear allegedly accessed voting equipment, taking five tabulators for several months. Attorney Matt Tapperno reportedly boasted about figuring out how to "rig them."
  • Fulton County, Pennsylvania: Attorney Stephanie Lambert allegedly facilitated access to software for examination by Powell-hired individuals in March and July 2022.
  • Mesa County, Colorado: Election official Tina Peters was convicted for associated criminal activity that allowed Conan Hayes to access the system, with the software later appearing at Mike Lindell's "Cyber Symposium."
  • Maricopa County, Arizona: During the "Cyber Ninjas audit," Dominion software was accessed and subsequently given to Ben Cotton, who took it to his lab.
  • Key Individuals and Entities: A recurring cast of characters was identified across these incidents, including Sydney Powell (funding/orchestration), Doug Logan (Cyber Ninjas CEO), Misty Hampton, Kathy Leam, Jim Penrose (NSA/CIA cyber security expert), Stephanie Lambert, Conan Hayes, Ben Cotton, and Sullivan Strickler (the firm contracted for data collection).
  • Nature of Stolen Software: The stolen software primarily consisted of binaries, not source code, as election officials typically only have access to binaries. However, David Jefferson explained that these binaries are not obfuscated, making them relatively easy to reverse engineer using specialized tools.
  • High-Level Discussions: Susan Greenhalgh revealed testimony to the January 6th committee (not highlighted in the final report) indicating discussions in the White House Oval Office in December 2020, where President Trump and others debated seizing voting machines via the military or DHS, ultimately opting for "voluntary access" through insiders, which Sydney Powell and Rudy Giuliani claimed they could achieve.
  • Lack of Comprehensive Investigation: Despite allegations of criminal behavior (e.g., Georgia Secretary of State's comment on Coffee County, criminal prosecution in Michigan) and evidence of multi-state coordination, there has been a significant absence of a unified, comprehensive federal investigation. The FBI, for instance, reportedly stated it could only investigate if asked by local authorities, even when the Georgia State Election Board made such a request.
  • Identified System Vulnerabilities: Dr. Alex Halderman's report (partially redacted) identified "10 to 12 vulnerabilities that a reasonable undergrad computer science student would ask about" in Georgia's Dominion systems. Clay Periq publicly demonstrated hacking a voting machine in a Georgia court, citing "massive amount of vulnerabilities" and "poor configuration of the database." Experts could not identify a single cybersecurity expert who would endorse the Georgia system as reliable.

Technical Deep Dive

▶ Watch: Videos proving breach surface despite official denials (5:50)

The technical implications of these breaches are profound, primarily revolving around the unauthorized acquisition and dissemination of proprietary voting system software. David Jefferson elaborated on the nature of the perlloined software and the dangers it presents.

The attackers obtained code from various Dominion and ES&S systems. While jurisdictions use slightly different versions, the collection represents a significant sample of the software underpinning approximately 70% of U.S. voting machines. Critically, the software taken consisted of binaries, not the original source code. This distinction is important; election officials typically only have binaries, not the more easily readable source code. However, as Jefferson explained, this is not a significant deterrent for sophisticated adversaries.

The key technical vulnerability highlighted is that these binaries are not obfuscated. Obfuscation is a technique used to make software intentionally difficult to reverse engineer. The absence of obfuscation means that bad actors can employ "power tools" — specialized software for reverse engineering, decompilers, and debuggers — to analyze the code at their leisure. These tools allow them to step through the code, observe its behavior in detail, and even generate a "reasonably readable version of the source code" for specific sections. This capability means that the lack of original source code does "not slow attackers down very much."

The primary danger is multi-faceted:

  1. Vulnerability Discovery: With ample time (e.g., the two-year period between major elections), bad actors can meticulously study the code to identify latent vulnerabilities. These could be design flaws, coding errors, or misconfigurations that, once discovered, become immediately exploitable.
  2. Creation of Malicious Variants: The ability to understand the legitimate software's inner workings allows for the creation of malicious variants — altered versions of the software designed to manipulate election outcomes or data without detection.
  3. Deployment of Malicious Software: Getting these malicious variants onto live election systems poses the next challenge. The talk outlines several potential vectors:
  • Insider Confederates: As demonstrated by the breaches themselves, cooperation from election officials or their employees could facilitate the loading of malicious software. The historical accounts of officials granting access underline this risk.
  • Election Machine Viruses: Jefferson noted that it has been "demonstrated in publications" (though not observed in real-life elections) that software can be spread from one election machine to another, potentially introducing malicious code on a single machine that then propagates throughout a jurisdiction's fleet.
  1. Evasion of Detection: A particularly insidious aspect is the ease with which malicious software can be designed to bypass existing security checks. This includes:
  • Certification Programs: Standardized testing that systems undergo.
  • Logic and Accuracy (L&A) Testing: Pre-election tests performed on machines to ensure they are functioning correctly. Malicious code can be engineered to remain dormant during these tests and activate only during actual voting or tabulation.

The speakers also highlighted that the "white hat expert community" — those at Defcon, academic researchers, and court-appointed experts — typically do not have access to this proprietary code. This creates an asymmetry: while malicious actors are studying the systems in secret, those committed to improving election security are often denied the same level of access, hindering proactive defense. The revelation that experts in the Curling v. Raffensperger case could not identify a single cybersecurity expert to endorse the Georgia system as reliable underscores the deep-seated security concerns.

Demo / Proof of Concept

▶ Watch: CNN report: Surveillance video confirms Coffee County breach (7:30)

The talk explicitly references multiple instances of practical demonstrations and discussions of hacking election systems, underscoring the tangible nature of the vulnerabilities.

Firstly, Marilyn Marks announced a planned live demonstration at the conference itself: "Come tomorrow at noon, we are going to show you a live demonstration of hacking a Dominion touchscreen machine which is in the other room... The hacking is so easy even I can do it. And that is a very low threshold. I'm not a computer. I have no computer science training at all." This direct, accessible demonstration was intended to concretely illustrate the ease of exploitation for the audience, regardless of their technical background.

Secondly, Jessica Burbank highlighted a significant public demonstration that occurred in a court case. In the DeKalb GOP v. Raffensperger case in Georgia, a witness named Clay Periq "demonstrated how to hack into one of the voting machines from the witness stand that went on YouTube September 30th, 2024, just over a month before the 2024 election." Burbank emphasized the accessibility of this hack, stating that while "maybe not someone off the street," "an undergrad computer science student could certainly easily" replicate it after watching the YouTube tutorial. Periq's testimony cited "the massive amount of vulnerabilities in this system, the poor configuration of the database itself, even if you encrypted the database, someone mid-level could take over." This court-documented, publicly available proof of concept serves as a stark warning about the current state of election machine security.

These demonstrations, both planned and past, provide compelling evidence that the security concerns raised in the talk are not theoretical but represent exploitable realities within widely deployed voting systems.

Defensive Implications

▶ Watch: Origins of the breach: Planning at Tamatley Plantation & Willard Hotel (11:20)

The detailed exposure of these multi-state breaches and the inherent vulnerabilities of election systems necessitates a robust and multi-pronged defensive strategy. David Jefferson outlined core principles, while other speakers highlighted practical steps and systemic changes.

  1. Evidence-Based Elections: This is a foundational concept. The ability to verify election outcomes independently of the voting machines' software is paramount. This shifts reliance from trusting opaque software to verifiable physical evidence.
  2. Software Independence: Systems should be designed such that an error or malicious alteration in the software cannot cause an undetectable change to the election outcome. This typically involves paper ballots that voters can verify, which then serve as the authoritative record.
  3. Risk Limiting Audits (RLAs): These are statistically robust post-election audits of paper ballots. RLAs can detect if a reported election outcome is incorrect with a high degree of confidence, making it exceedingly difficult for malicious software to alter results without being caught. Jessica Burbank mentioned that CISA (Cybersecurity and Infrastructure Security Agency) has already released a recommendation for election audits, specifically where machines with identified vulnerabilities are in use.
  4. Replace or Update Vulnerable Systems: Given that 70% of U.S. voting machines are Dominion or ES&S systems, and critical vulnerabilities have been identified (e.g., Dr. Alex Halderman's report, Clay Periq's demonstration), CISA's recommendation to "replace them or update the software to patch the identified insecurities" becomes an urgent imperative.
  5. Increased Vigilance and Awareness: Election officials, particularly at the local level, must be acutely aware of ongoing threats. Susan Greenhalgh noted reports of individuals "claiming to be associated with the Department of Homeland Security or the Trump administration" still asking election officials for access to voting equipment. This highlights the need for strict protocols and skepticism regarding unofficial requests, regardless of the claimed affiliation.
  6. Comprehensive Federal Investigation: The lack of a multi-state, federal investigation into these interconnected breaches is a critical gap. As Susan Greenhalgh pointed out, despite evidence of interstate coordination and criminal allegations, federal agencies have reportedly been reluctant to act. A thorough investigation is crucial to understand the full scope, hold perpetrators accountable, and deter future attempts.
  7. Transparency and Access for White-Hat Researchers: The current model where proprietary software is inaccessible to independent security researchers, while simultaneously being stolen and analyzed by malicious actors, creates a dangerous imbalance. Responsible access for trusted cybersecurity experts could proactively identify and mitigate vulnerabilities before they are exploited.
  8. Protecting Ballot Secrecy and Voter Records: Marilyn Marks expressed concern that detailed voter records, especially when combined with compromised voting machine data, could potentially be used to trace ballots back to individual voters, undermining ballot secrecy, which is a fundamental tenet of democratic elections. Safeguarding these records from partisan access is vital.

The overarching defensive implication is a call for a paradigm shift from a reactive, trust-based security model to a proactive, evidence-based, and transparent one that can withstand sophisticated and coordinated attacks, especially those originating from within.

Key Takeaways

  • Coordinated Multi-State Breaches: A network of partisan actors orchestrated and executed breaches of U.S. voting systems in Georgia, Michigan, Pennsylvania, Colorado, and Arizona, with financial backing from figures like Sydney Powell.
  • Widespread Software Dissemination: Proprietary election software and sensitive data (e.g., election management system data, ballot images) were copied and circulated among these groups and reportedly on the dark web, making it accessible to potentially hostile foreign intelligence agencies.
  • Exploitable Binaries: The stolen software, though in binary form, is not obfuscated, allowing for relatively easy reverse engineering by bad actors to identify and exploit vulnerabilities, or create undetectable malicious variants.
  • Systemic Vulnerabilities: Current Dominion and ES&S voting systems, which constitute 70% of U.S. machines, possess critical vulnerabilities easily exploitable even by non-experts, as demonstrated in court and at the conference.
  • Lack of Federal Accountability: Despite clear evidence of criminal behavior, multi-state coordination, and requests from state election authorities, a comprehensive federal investigation into these breaches has largely been absent.
  • Urgent Defensive Reforms: Immediate implementation of evidence-based elections, software independence, and robust risk-limiting audits is crucial, alongside the replacement or patching of demonstrably insecure voting equipment.

About the Speaker(s)

Marilyn Marks is the Executive Director of the Coalition for Good Governance. She was the organizational plaintiff behind the Curling v. Raffensperger case in Georgia, through which she played a pivotal role in uncovering the initial breach in Coffee County, Georgia, and subsequently connecting it to a broader pattern of election system compromises.

Susan Greenhalgh is affiliated with Free Speech for People and served as a consulting expert to Marilyn Marks's lawsuit. In this talk, she acted as both a moderator and presenter, detailing the connections between the multi-state breaches and highlighting the lack of comprehensive investigation into these events.

David Jefferson is a technical expert who provided critical insights into the technical significance of the perlloined voting system software. He explained the ease of reverse engineering the binaries, the dangers of malicious variants, and the essential defensive strategies of evidence-based elections, software independence, and risk-limiting audits.

Jessica Burbank is a reporter from Dropsite News. She shared her experiences covering this complex story, emphasizing the challenges of getting the truth heard in the media landscape and the extensive reporting she conducted, including interviews with cybersecurity experts, election officials, and vendors.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A legitimate and important topic — coordinated insider-facilitated breaches of election systems across multiple states — but this is more investigative journalism and legal advocacy than security research. The technical content is real but thin, and the panel format means it never goes deep enough on any single vector to satisfy a technical audience.

Heather Calloway (CISO) — STRONG ACCEPT

This is one of the more consequential election security presentations in recent memory — not because of the technical depth, but because it documents a real, multi-state insider threat campaign with named actors, confirmed breaches, and a federal accountability vacuum that should alarm anyone responsible for critical infrastructure governance. The defensive recommendations are sound, if not novel, and the institutional failure story is the real finding.

→ Top-rated talks at Voting Village @ DEF CON 33

All talks from Voting Village @ DEF CON 33