Taxonomy of Vote Reporting Vulnerabilities
I. Introduction
The case studies that precede this document examine what has gone wrong in American vote reporting — specific, documented instances in which the chain that runs from a voter’s mark on a ballot to a published official total broke down, in ways that either altered an outcome or left an outcome permanently in question. Each case study is a single story, chosen for its evidentiary strength and its methodological relevance. Taken one at a time, the stories can read as a miscellaneous assortment of unrelated failures: a memory card in one county, a software bug in another, an election-night courthouse closure in a third, a statistician denied access to audit logs in a fourth.
This document steps back from the stories and maps the structure. Its claim is that the failures in the case studies are not miscellaneous. They are instances of a comparatively small number of structural vulnerabilities that recur, across decades and across jurisdictions, because the architecture of American vote reporting has features that make them possible. Some of these vulnerabilities have been realized repeatedly, in incidents that have produced lawsuits, academic papers, journalistic investigations, and in some cases criminal prosecutions. Others are credible on the available evidence but have not yet been documented in public — vulnerabilities that the existing architecture permits and does not check, but for which no confirmed exploitation has surfaced in the public record. Both categories appear in the taxonomy, and they are distinguished from one another so that the reader can tell at any point which of the two is being discussed.
The taxonomy is organized by where in the reporting chain a vulnerability lives, not by whether the failure mode is error or fraud. This is a deliberate choice. The structural conditions that allow an innocent mistake to enter the official record unchecked are the same conditions that allow a deliberate manipulation to enter the official record unchecked. A verification system that closes the structural gap closes both modes of failure. Organizing the taxonomy around the architectural feature — the step in the chain where independent evidence is missing — rather than around the intent of any particular actor keeps the focus on the system rather than on the motivations of specific officials or vendors. It also keeps the argument for Actual Vote non-partisan in the only sense that matters structurally: AV addresses vulnerabilities that can be exploited in any direction, by any party, against any candidate, and it does so without relying on any judgment about who is likely to do what.
A clarification about scope is also in order. Election integrity encompasses many issues that this document does not address: voter registration, voter eligibility, ballot access, campaign finance, ballot design, the calibration of voting machines, and the adjudication of which ballots to count after canvass disputes. These are important and contested topics, and many of them are the subject of their own well-developed literatures. What this taxonomy covers is narrower: the chain that runs from the count produced at a precinct-level scanner through aggregation, transmission, certification, and publication; the layer through which the published official record is delivered to the public; and the ability of the public to verify, independently, that the numbers reported as official match the numbers that the scanners produced. That is the reporting layer, and it is the part of the chain at which Actual Vote operates. The taxonomy treats vulnerabilities beyond the reporting layer only briefly, in a section set aside for that purpose, and is explicit about what Actual Vote does not catch.
II. The Reporting Chain and the Three-Layer Model
The methodology document for this collection introduces a three-layer model for the integrity of an election — the ballot-assignment layer, the counting layer, and the reporting layer, in sequence; see also the fuller treatment of the counting/reporting boundary in the manual’s Conceptual Foundation. The reporting chain that this document maps sits inside the third of these layers.
Zooming in: after polls close, a modern American precinct’s tabulator prints a poll tape — a paper receipt of the per-candidate totals the machine counted during the voting day. In most jurisdictions, that tape is posted at the precinct for public view, and the data on it is also written to a memory card or transmitted electronically. The memory card, or the transmitted data, is received by the county election management system, which aggregates results across precincts and produces county totals. The county totals are reported to the state, which aggregates them further and publishes the official results on which canvassing boards, certifying authorities, and ultimately the public rely. The chain from poll tape to published state total involves at minimum several handoffs, each of which is a point at which the reported total can come to differ from what the precinct scanner actually counted. Some handoffs are physical — a memory card carried from a precinct to a county office. Some are electronic — data transmitted over a modem or network. Some are administrative — a human being reading a number off a tape and entering it into a form or state portal. Each handoff is a potential locus of failure.
The reporting chain has one further segment that the description above does not yet name. After the state’s certified totals exist as official records, those records must reach the public, the press, candidates, and downstream consumers, and that delivery occurs through a layer of public-facing infrastructure: state election websites, election-night reporting feeds, news-service data pipelines, mobile applications, content delivery networks, and the application programming interfaces by which third parties consume official data. This dissemination layer is structurally distinct from the chain that produces the official record: failures in dissemination do not alter the certified totals, but they shape what the public believes the totals to be during the window in which that belief is most consequential. The taxonomy treats dissemination as the fourth segment of the reporting chain.
Actual Vote operates at the top of this chain. A volunteer photographs the poll tape at the precinct, at the close of polls, before the data leaves the precinct and before any handoff has occurred. The photograph becomes an independent, citizen-held record of what the tabulator said the precinct produced. That record is compared against the published official total. If the two agree, every handoff in between can be inferred to have worked correctly, regardless of whether any particular handoff was directly observed. If the two disagree, something in the chain introduced an error — and because the comparison is arithmetic rather than procedural, the direction and magnitude of the discrepancy are immediately legible. The taxonomy that follows catalogs the points along the chain at which the two can come to disagree. It begins at the precinct equipment, works downstream through transmission, software, and central tabulation, extends through the public dissemination layer, addresses the meta-level of audit and evidence-preservation regimes, and treats the structural conditions of American election administration that produce and sustain the vulnerabilities described. A separate section treats access-to-evidence vulnerabilities — the ways in which the public can be prevented from verifying even correct reporting — and a final section treats the counting-layer vulnerabilities and alternative ballot-intake pathways that fall outside Actual Vote’s detection scope, included for completeness and for honesty about the limits of what independent tape verification can do. The taxonomy also names a category of threat vectors associated with the broad availability of generative AI, which sharpen several of the upstream failure modes and warrant separate treatment.
III. Category 1: Precinct Equipment Failures
The scanner counts correctly, but the results never leave the precinct in usable form.
The first category of reporting-layer failure occurs at the boundary between the precinct and the rest of the reporting chain. The scanner has done its work and the poll tape reflects an accurate count, but the mechanism by which the count is transferred to the county election management system fails in some way. The correct numbers exist on paper; they just do not arrive, or arrive in a form that is misinterpreted.
Several subtypes of this failure are documented in the case studies.
Memory card upload failure is the most common. A precinct’s scanner tabulates correctly and prints a tape, but the memory card carrying those results fails to upload to the county system. The votes exist at the precinct but are absent from the official results. The Georgia 2020 case study documents approximately 5,800 votes missing across four counties for precisely this reason, discovered only when Georgia’s full statewide hand tally forced a manual reconciliation. Without the hand tally, the missing votes would not have been detected. Gaston County, North Carolina, in 1998 represents a more extreme version: faulty data cartridges caused roughly one-third of the county’s precincts to report zero votes, triggering the crisis response that became the model for public observation of a recovery process.
Data cartridge corruption — physical media failing in the interval between the precinct and the county office — is closely related. Gaston County 1998 again illustrates the failure mode: the specific cartridges used by the county’s system were discovered to be unreliable after the election, prompting the vendor to replace them across its installed base. Failures of this sort are indistinguishable at the county level from upload failures; in both cases, the county sees an absence of data where data should be, and the reconstruction of what actually happened depends on the existence of the precinct-level tape.
Counter overflow bugs represent a subtler and less-remembered failure mode. Some older tabulation systems cap per-candidate totals at an integer boundary — the Gaston County incident involved a cap at 32,000 — and silently discard additional votes beyond the cap. The scanner continues to accept ballots, but the internal counter stops incrementing. Only when the aggregated totals reveal the anomaly does the fault become visible, if it becomes visible at all. Smaller jurisdictions are comparatively safe from this failure mode because they do not accumulate enough votes per candidate per precinct to hit the cap; larger jurisdictions are at risk whenever a software update or a ballot design change alters the effective maximum.
Batch misrouting via mislabeled media is a fourth subtype, and it is visible most clearly in Henrico County, Virginia, in 2020. A memory stick containing the results of 16,616 in-person absentee ballots was mislabeled as “provisional” rather than “absentee.” Because provisional ballots follow a separate processing workflow in the Virginia system, the entire batch was excluded from election-night totals. The tabulators had counted correctly. The tapes had printed correctly. The memory stick was physically intact and electronically readable. The failure lay entirely in the categorical label affixed to the container that carried the data from the precinct to the county system. This is not an upload failure, a corruption failure, or an overflow failure. It is a routing failure produced by a human-applied category error, with the consequence that a correctly counted batch does not reach the official count until the mislabeling is caught and corrected. It is a reminder that the reporting chain is not purely mechanical: at any point where a human being labels, categorizes, or routes a container of votes, a categorical mistake can exclude correctly counted ballots from the official record.
Several further failure modes in this category are plausible on the available evidence but are not documented in the public record. Power failures during upload could cause partial data transmissions to be treated as complete, particularly in systems without strong handshake protocols. Memory cards used across many election cycles could develop read errors consistent with hardware degradation, producing small per-precinct discrepancies that fall below obvious-anomaly thresholds but that would be detectable against an independent tape record. Poll tape printer failures — the tape physically failing to print, or printing incompletely — would eliminate the very evidence Actual Vote relies on, a vulnerability the case studies do not document but that is inherent to the method’s dependence on the printed artifact. Firmware version mismatches between the precinct scanner and the county aggregation software could cause correctly counted data to be imported in a misaligned form, with votes from one race attributed to another or dropped entirely; such mismatches would tend to occur in jurisdictions that update equipment heterogeneously.
A further class of failure that is now documented is ballot-definition configuration error producing wrong reported totals at the precinct or county level. Northampton County, Pennsylvania, in 2019 experienced a ballot-definition error on its newly deployed ES&S ExpressVote XL system that produced a cross-tabulation/reporting display error in a judicial retention contest (Pennsylvania Department of State — Northampton County 2019 investigation report; Andrew Appel — Voting Machine Error in Pennsylvania, freedom-to-tinker, 2019). Northampton in 2023 experienced a related configuration error in which an ES&S programmer mislabeled retention questions for two state Superior Court judges, causing votes for one to be recorded as votes for the other on the ballot, on the machine, and on the tape (Spotlight PA — Voting machines malfunction in Northampton County). The two Northampton incidents, and the Williamson County, Texas, 2020 case, establish that ballot-definition errors are a recurring precinct-level failure mode that can manifest either as a reporting-layer error (the scanner counts correctly, the report displays wrong) or as a counting-layer error (the scanner counts wrong, the tape reflects the wrong count). The two manifestations have different implications for AV detection and are addressed separately at the close of the relevant categories.
Actual Vote detects every failure in this category that leaves a correctly printed poll tape behind. The tape reflects the correct count; the official result does not; the discrepancy is visible. The single exception is poll tape printer failure itself: if the tape does not print or prints incorrectly, Actual Vote has nothing to compare against. This is a real limitation and it is one that the collection does not obscure.
IV. Category 2: Silent Software Bugs in Tabulation Systems
The software that aggregates precinct results introduces errors without producing an error message.
If the first category consists of failures that prevent correct precinct data from reaching the county, the second consists of failures that occur after the data arrives. Software running in the county’s election management system receives precinct uploads, merges them into a running county total, and produces the aggregated report that becomes the official county result. Bugs in that software can silently alter totals in ways that produce no operator-visible error signal — the system reports “upload successful” while having lost, doubled, or corrupted the data it was nominally processing.
The archetype is the GEMS upload sharing violation, documented in three separate case studies. The GEMS tabulation system, distributed under successive vendor names (Global Election Systems, Diebold, Premier) across thirty-four states for over a decade, contained a race condition: when multiple memory cards uploaded to the central system simultaneously, one card’s data could overwrite another’s, with the system recording a successful upload in both cases. The bug was discovered independently in Butler County, Ohio, in 2008, in Gaston County, North Carolina, in 1998, and in Shelby County, Tennessee, in 2015. The same structural defect — in the same software, from the same vendor chain — produced the same failure mode across a span of seventeen years. DuPage County, Illinois, in 2004 documents a variant of the same class: GEMS reported a successful upload while recording zero votes, with the failure detected only the next day by a staff member reviewing the reports.
The Butler County discovery in 2008 is significant beyond the specific bug because it revealed that the vendor knew. Internal documents and subsequent investigation established that Premier/Diebold had been aware of the upload defect for years and had not disclosed it to the election officials using the system. This converts the category from “a particular software bug that happened to exist for a long time” into a broader structural claim: that the relationship between vendors and jurisdictions permits the non-disclosure of known defects in software that produces official election results, and that the defects can persist across jurisdictions, across elections, and across decades while this non-disclosure continues. That second structural claim is the subject of Category 8.
Double-counting when a safeguard is removed is a distinct failure mode, documented most clearly in Monmouth County, New Jersey, in 2022. A previously installed software patch that prevented duplicate flash drive loads was inadvertently removed during a routine software reinstallation. Six flash drives were loaded twice. Every vote on those drives was counted twice. The resulting error changed the outcome of the primary election for county commissioner; the candidate who took office as the apparent winner had, in fact, lost. The county’s post-election audit reported “100% accuracy.” The error was detected only when a losing candidate requested a recount. Monmouth is, as far as is publicly documented, the only American election in which a reporting-layer software error is known with certainty to have changed an outcome. It is almost certainly not the only election in which this has occurred; it is the only one in which the error was caught.
Mail-in ballot data duplication is a further documented subtype. Washington County, North Carolina, in the 2020 Chief Justice race had an outdated tabulator that duplicated absentee ballot data during import, inflating precinct totals by a figure consistent with the full absentee count. The canvass process caught and corrected the error, but the discovery was sufficiently decisive to swing the statewide lead in a race ultimately decided by 401 votes.
Several additional failure modes in this category are plausible without having surfaced in the public record. Database merge conflicts during aggregation, in which concurrent writes to the same record silently overwrite data, are the same structural class as GEMS but can arise in any software stack that aggregates precinct data under concurrency. Character encoding and delimiter errors in batch imports are a common cause of data loss in business software and would manifest in election software as shifted or corrupted fields — a comma in a precinct name, a non-ASCII character in a candidate name, an unexpected line break — any of which could cause vote totals to migrate between rows or be dropped. Rounding errors in vote allocation beyond those exploited by the Fraction Magic attack architecture could arise innocently in systems that apportion votes across split precincts, calculate proportional allocations, or handle ranked-choice tabulation. Vendor patches that introduce new bugs — the Monmouth County case being the closest real example, in which a reinstallation removed a prior safeguard — could occur anywhere a deployed update changes data formats, rounding behavior, or memory-card compatibility. Time-zone and clock-synchronization issues could cause election management systems to silently discard or overwrite valid results if system clocks are misconfigured, treating a later upload as a correction of an earlier one.
Actual Vote detects every failure mode in this category. By design, a software bug in the county’s aggregation system produces a discrepancy between the precinct poll tape — which reflects what the scanner actually counted — and the official result, which reflects the bug’s effect on the data after it arrived at the county. This is the core Actual Vote detection case, and the category is the one for which the case for tape-based independent verification is most direct.
V. Category 3: Data Transmission and Formatting Errors
Results are transmitted correctly from the precinct but mangled during the conversion to official format.
Between the precinct and the public result, data is not only aggregated; it is reformatted. Scanners print tapes in one format. County election management systems store data in a second. State reporting systems — whose requirements have typically been specified independently of any individual county’s equipment — accept data in a third. At each reformatting step, the data is translated, and at each translation a new opportunity for error is introduced.
Tape-to-state format incompatibility is the documented archetype. In Prince William County, Virginia (2020), a ~4,000-vote reporting error survived certification and a statewide risk-limiting audit that confirmed the counting layer with 99%+ confidence — because the error was in the reporting layer, which that audit did not check. The error entered during the manual reformatting of correctly tabulated scanner tapes into the form the state reporting system required — split precincts straddling district boundaries demanded manual allocation — and was discovered more than a year later, by accident.
Transcription errors in manual data entry are a closely related subtype. Wherever precinct results must be manually keyed from a printed tape into a county or state system, human error produces wrong numbers. Prince William County’s error set included two adjacent precincts reporting identical vote totals across several races — an obvious copy-paste error, survivable only because nothing in the reporting pipeline compared adjacent precincts’ totals to flag improbable equality.
Format-coercion errors during inter-system data transfer are a documented failure class in adjacent government-data domains and are structurally applicable to election results pipelines that pass through Excel or CSV intermediates. The most rigorously studied instance is the United Kingdom’s Public Health England COVID-19 case-tracking failure of September 2020, in which approximately 16,000 cases were lost from the public-health pipeline because case identifiers exceeded the row limit of the legacy Excel format being used as an intermediate exchange medium (BBC News — Excel: Why using Microsoft’s tool caused COVID-19 results to be lost). The same coercion class — long integer identifiers reformatted as scientific notation, dates auto-detected from numeric strings, Unicode characters in candidate names broken by encoding mismatches — is structurally applicable wherever election results pipelines pass through Excel or CSV intermediates. The genomics literature has documented that approximately 30 percent of papers in major genomics journals contained gene-name errors traceable to Excel autoconversion (Ziemann, Eren, El-Osta — Gene name errors are widespread in the scientific literature, Genome Biology, 2016), establishing that the failure mode is sufficiently common in practice that its absence from the publicly documented election record is more plausibly explained by limited investigation than by absence of occurrence. CSV injection — a class of attack in which adversary-supplied content in a CSV cell is interpreted as a formula by a downstream consumer (OWASP — CSV Injection) — is a related concern wherever election results pipelines pass through CSV exchange formats with inadequate sanitization at the consumer end.
Several failure modes in this category are plausible but not documented in the public record. Automated format conversion with edge cases could fail on precincts with zero votes in a race, on write-in candidates with unusual characters, on provisional ballot counts appended after initial upload, or on precincts running different scanner firmware than the state’s conversion software expects. Network transmission corruption is generally prevented by TCP-level integrity checks but may not be guaranteed for proprietary protocols, removable-media transfers, or email-based transmission — all of which have been used in American election reporting at various points. Lossy compression of results data, if applied anywhere in the chain for storage or transmission efficiency, could silently alter vote counts for candidates whose totals differ from nearby totals by small amounts.
Actual Vote detects every failure in this category. The poll tape is captured upstream of every reformatting step; any error introduced during transmission or reformatting manifests as a discrepancy between the captured tape and the published result.
VI. Category 4: Central Tabulation Manipulation
Someone with access to the central tabulation system intentionally alters results.
The categories above concern errors. This category concerns deliberate manipulation. The structural vulnerabilities are similar — central systems that aggregate precinct data can be altered from within them — but the actor is different, and the threat model is different.
The historically documented instances involve returning boards and post-election administrative access. Returning board fabrication is the Tammany Hall model: returning boards in New York City in the 1860s and 1870s announced ward-level results “in bulk” without counting the ballots, fabricating totals to produce desired outcomes. The returning board was an administrative body whose function was to consolidate precinct returns into official ward totals; it had the authority to produce the official number, and no independent check on the relationship between what the precincts had actually produced and what the board announced. Post-election result alteration is the Baldwin County, Alabama, 2002 model: after the opposing party’s observer had been told the courthouse was closing and had left, central tabulation was reopened and approximately 6,300 votes were reduced from one candidate’s total at a single precinct. The governor’s race turned on the change; subsequent recount and investigation were blocked by statutory interpretation, and the physical evidence was destroyed by the state’s ballot-retention statute before the matter could be litigated. Post-election list padding is the LBJ 1948 model: 202 names were added to a poll list in Jim Wells County days after the election, in alphabetical order, in the same handwriting, in the same ink, copied from the local poll-tax roll. The United States Senate seat that Lyndon Johnson won by 87 votes in that runoff turned on those 202 votes. The physical evidence subsequently disappeared from the courthouse basement where it had been stored.
The taxonomy also treats documented vulnerabilities whose exploitation is unproven — architectural features of modern tabulation systems that make manipulation technically possible, but for which no specific incident of exploitation has surfaced in the public record. Two such features are worth naming at length.
Internet-connected election management systems. All three major American voting-system vendors — Election Systems & Software, Dominion Voting Systems, and Hart InterCivic — have acknowledged installing modems in tabulators and scanners to relay unofficial election results more quickly to the public. The modems connect to cell phone networks, and the cell phone networks connect to the internet. In January 2020, security researcher Kevin Skoglund and his team built a tool that scanned the internet for election management systems and found nearly three dozen of them online, systems that officials had told the public were not connected. Skoglund identified ES&S systems specifically; ES&S subsequently told NBC News that 14,000 of its DS200 tabulators with online modems were in use in American elections, even though the company’s own public-facing website had stated that zero of its tabulators were connected to the internet. This is a reporting-layer vulnerability rather than a counting-layer one: the systems in question are the central computers that aggregate precinct results and produce official totals, not the scanners that count individual ballots. An attacker with access to an internet-connected EMS could alter aggregated totals after the precinct tapes have printed. The related but distinct concern about internet-connected voting machines — scanners and DREs themselves — is a counting-layer vulnerability and is addressed in Category 11 below.
Vendor remote-access software on election management systems. In 2018, ES&S admitted to Senator Ron Wyden that it had installed pcAnywhere remote-access software and modems on election management systems sold between 2000 and 2006 — the machines used by officials to tabulate final results. ES&S stopped shipping pcAnywhere in late 2007 after new federal standards prohibited non-essential software on election systems. The admission contradicted the company’s earlier public denials. The security significance was compounded by the fact that pcAnywhere’s source code was stolen and leaked online in 2006, and that in 2012 security researchers found a vulnerability in pcAnywhere that allowed attackers to seize control of a system without authentication. No exploitation of this remote-access channel for vote manipulation has been proven in the public record. What is established is that for the period 2000 to 2006, the infrastructure for remote access to central tabulation systems existed, and the vendor that installed it had, at minimum, a non-trivial period during which it told the public it had not.
Several further failure modes in this category are plausible without having been publicly documented as having altered an American election outcome, though their structural feasibility has been established in the academic and operational security literature with sufficient rigor that their inclusion in the taxonomy is warranted on evidentiary rather than speculative grounds.
Credential-based intrusion of election management systems. Phishing, credential stuffing, and the absence of multi-factor authentication on systems with privileged access to the EMS are the standard initial-access vectors for cyber intrusions into state and local government infrastructure. The Senate Select Committee on Intelligence, in its public report on Russian interference in the 2016 election, documented credential-based and exploit-based intrusions targeting state election infrastructure in at least 21 states, including the compromise of VR Systems and the Illinois State Board of Elections (Senate Intelligence Committee Report on Russian Active Measures, Volume 1, 2019). The 2016 events did not produce a documented alteration of vote totals, but they established that the intrusion pathway exists, that it has been exercised by sophisticated actors, and that the defenses against it depend on operational security practices — multi-factor authentication, privileged-access management, endpoint detection — whose deployment across the more than 10,000 American election jurisdictions is uneven. CISA’s Joint Cybersecurity Advisories from 2020 forward have repeatedly identified credential compromise of state and local government infrastructure as an active and ongoing threat (CISA — Election Security Resources).
Authorized-insider tampering with central tabulation. The Mesa County, Colorado, case of 2021 is the cleanest documented modern instance: a county clerk with authorized access used her credentials to admit an unauthorized third party into the secure tabulation room during a Dominion software trusted-build update, allowing the third party to image the EMS hard drives. Forensic images and partial passwords were subsequently posted online (Colorado Secretary of State — Mesa County investigations). The clerk was indicted, convicted of multiple felonies, and sentenced to nine years in prison. The Mesa County case is significant for the taxonomy not because the underlying ballots or totals were altered — the structural failure was custodial rather than tabulative — but because it documents that the authorized-insider pathway to the EMS is real, that it can be exercised, and that the existing access regime depends on the good faith of the custodian whose conduct it is meant to govern. The same access pathway, exercised with intent to alter rather than to exfiltrate, would produce the kind of post-tape EMS manipulation the categories above describe theoretically.
USB-borne malware bridging air gaps. Election management systems are commonly described as “air-gapped” — disconnected from external networks — but operational practice routinely requires moving data between the EMS and other systems via removable media. Memory cards from precincts, software update media from vendors, and configuration files exchanged between county and state systems all bridge the air gap as a matter of normal operation. Malware delivered through removable media is a long-documented attack class against industrial and government systems and would, in an election context, persist past the air gap into the EMS environment. DEFCON’s Voting Village has repeatedly demonstrated that the operating systems and update channels of EMS-class equipment are vulnerable to removable-media-borne attacks (DEF CON Voting Village 2019 Report).
Supply-chain compromise of EMS software updates. Software updates distributed by election system vendors to county jurisdictions traverse a supply chain that includes vendor build infrastructure, code-signing systems, distribution channels, and county-side update procedures. Compromise at any point in the chain — most consequentially at the vendor’s build infrastructure — would propagate altered code to every jurisdiction applying the affected update. SolarWinds in 2020 (CISA — SolarWinds incident summary) is the canonical demonstration that this attack class is exercisable at scale against American government infrastructure. CISA has explicitly identified election system vendors as a category of supply-chain risk warranting specific defensive attention (CISA — ICT Supply Chain Risk Management).
Time-synchronization and audit-log integrity on the EMS. Reconstruction of what an EMS did during an election depends on the integrity of its audit logs, which in turn depend on accurate, tamper-evident timestamps and on storage that is not modifiable by the same actors whose conduct the logs are meant to record. Halderman’s expert analysis in Curling v. Raffensperger (Halderman & Springall expert report on the Dominion ImageCast X, 2021) documents that the audit-log architecture of the EMS-class equipment in question lacks tamper-evidence properties sufficient to support the role the logs are expected to play in post-election forensics. The general consequence is that an EMS compromise that includes log modification can be designed to be invisible to any reconstruction that depends on the same logs.
Ransomware and destructive cyberattacks against EMS infrastructure. Ransomware against state and local government is a documented and ongoing threat class (CISA — #StopRansomware resources), with multiple state and county election offices among the affected jurisdictions during the 2020-2024 cycles. The reporting-layer consequence of an EMS ransomware incident is not that vote totals are altered to favor a candidate, but that the EMS database is encrypted or rendered unavailable during the period in which it is needed to produce or certify totals, forcing reliance on backups whose integrity may itself be in question. CISA conducted over seven hundred cyber assessments for election infrastructure stakeholders during the 2024 cycle and has identified election infrastructure as regularly targeted by ransomware and denial-of-service attacks.
Remote exploitation of internet-connected EMS systems. Remote exploitation of internet-connected EMS systems is the same kind of vulnerability conducted from outside the jurisdiction; CISA has explicitly recommended that EMS systems not be connected to any external networks, and has noted that any internet-connected device on a local county network creates an exploitable path to the EMS. The existence of that recommendation is itself a data point about the realism of the risk.
Finally, this category is where the Fraction Magic architecture belongs in the taxonomy. The GEMS database schema stores per-candidate vote counts in fields of the DOUBLE data type — floating-point rather than integer — which is capable of representing fractional votes. The vendor’s own training materials document the feature. Demonstration videos by the researcher who discovered the architecture (Bennie Smith) show that the fractional-storage design permits vote reallocation in a way that moves totals between candidates while preserving aggregate totals in the aggregate, defeating the obvious sanity checks but producing per-precinct discrepancies relative to what the scanners actually counted. No specific election has been demonstrated in public evidence to have been altered through this mechanism. The architecture’s existence, however, is documented.
Actual Vote detects every central-tabulation manipulation that occurs after the poll tape is printed. The tape is captured before any of these vulnerabilities can be reached, and it is held by independent citizens outside the tabulation system, outside the vendor’s access, and outside the network on which the EMS runs. The exception is an attack that alters the tabulation software before the tape prints — corrupting the scanner’s output before it reaches paper — which would produce a corrupted tape matching the corrupted results. That is a counting-layer attack, and it falls into Category 11.
VII. Category 5: Public Dissemination Layer Vulnerabilities
The official record is correct, but what the public sees is not.
The first four categories concern the chain that produces the official record: precinct equipment, software bugs, transmission, and central tabulation. This category concerns what happens after the official record exists. The state’s certified totals must be delivered to the public, the press, candidates, and downstream consumers, and that delivery occurs through a layer of infrastructure — public-facing websites, election-night reporting (ENR) feeds, mobile applications, application programming interfaces, content delivery networks, and the data pipelines that connect state systems to wire services and broadcast networks. Failures in this layer do not change the underlying official record. They change what the public, the press, and political actors believe the record says, during the window in which that belief is most consequential. The threat model is genuinely distinct from the threat model for the EMS itself: the actors are different, the access points are different, and the consequences run through perception and narrative rather than through certification.
This category is included in the taxonomy for two reasons. The first is structural completeness: the chain from precinct tape to public belief does not end when the state publishes its official totals, and a taxonomy organized around the reporting chain has to cover the chain to its end. The second is that the existing case study collection contains one documented instance of this failure mode, and several plausible instances on the available evidence, which together illustrate that the dissemination layer has its own attack surface and its own consequences.
Election-night reporting site availability failures. The most directly documented subtype is denial-of-service against an election-night reporting website during the window in which unofficial results are being published. Knox County, Tennessee, in May 2018 experienced a distributed denial-of-service attack on its election-night reporting site shortly after polls closed during the county primary. A post-incident forensic investigation by Sword & Shield Enterprise Security, commissioned by the county, established that the attack overwhelmed the public-facing site for approximately one hour while leaving the internal tabulation systems — which were on a separate network — unaffected (Sword & Shield post-incident report, 2018; Knoxville News Sentinel coverage). The official count was correct and was eventually published. What failed was the public-facing dissemination of that count during the period in which press coverage, candidate strategy, and public expectation are most actively forming. The Cybersecurity and Infrastructure Security Agency has issued guidance specifically on this attack class, recommending mitigations that most local jurisdictions have not implemented at scale (CISA — DDoS Guide for Election Officials).
Election-night reporting site integrity failures. Distinct from availability is the case in which the public-facing site continues to function but displays altered or fabricated results. The mechanisms are familiar from web security generally: defacement through compromised content management system credentials, SQL injection or cross-site scripting vulnerabilities in custom-built election websites, BGP hijacking that redirects requests for the official site to an attacker-controlled server, DNS hijacking achieved either at the registrar or through cache poisoning, and content-delivery-network cache poisoning that serves manipulated results from infrastructure the state does not directly control. None of these has surfaced as a publicly documented incident affecting an American state election results page. Each is documented as a real attack class against state and local government infrastructure generally, and each is identified by CISA as a class of risk that election officials should defend against (CISA — Election Security Resource Library). The combination of an attack class that has been documented in adjacent contexts, a target that has been increasingly contested politically, and a window in which the public is actively forming beliefs about the result is the structural condition under which a future incident becomes more likely rather than less.
News feed and aggregator manipulation. The pipeline from state reporting systems to wire services and broadcast networks is itself a layer of infrastructure with its own integrity properties. The Associated Press operates the most widely consumed of these pipelines, drawing data directly from state and county sources and serving aggregated results to its member organizations and to the major broadcast networks (AP — How AP counts the vote). Edison Research’s National Election Pool serves a parallel function for the broadcast network consortium (Edison Research — National Election Pool). Adversarial security analysis of the state-to-AP and state-to-Edison feed chains is largely absent from the public literature. The structural question is the same one the EMS literature has answered in the affirmative for the EMS itself: a small number of pipelines aggregate a large fraction of the public’s view of election results, and those pipelines depend on data integrity properties — authenticated transmission, tamper-evident processing, redundant validation — that have not been publicly audited at the level of rigor that has been applied to election-management systems. The risk is not necessarily that the pipelines are insecure; the risk is that whether they are or are not is not publicly knowable, and the consequences of compromise — coordinated misreporting of results across every major network simultaneously — are severe.
Mobile applications and public-facing APIs. State and county election departments have increasingly published results through mobile applications and public APIs, both of which extend the dissemination layer onto infrastructure that is typically outside the direct control of the election authority. Mobile applications depend on third-party developer toolkits, app store distribution channels, and runtime environments whose integrity has been the subject of repeated security incidents in adjacent domains. Public APIs depend on rate limiting, authentication where applicable, and request validation that is rarely subject to the certification regimes that apply to voting equipment. None of the publicly documented American election failures that have surfaced to date involves an exploited mobile application or API, but the absence of documented exploitation should be read in the context of the absence of independent security research on these specific systems, not as evidence that the systems are sound.
Several further failure modes in this category are plausible without having surfaced as documented incidents. A coordinated disinformation operation timed to a brief window of ENR site instability could amplify the effect of a partial dissemination failure beyond what the underlying infrastructure failure would itself produce. A nation-state actor with the capability to perform BGP-level redirection — a capability publicly documented in non-election contexts — could route traffic for a state election website through infrastructure under its control during the election-night window without leaving traces in the state’s own logs. Cached or stale data served as authoritative is a documented failure mode in CDN configurations generally and would, in an election context, produce a window during which incorrect results were treated as official by aggregators that polled the cached endpoint rather than the origin.
Actual Vote’s relationship to this category is structurally different from its relationship to the categories upstream. In Categories 1 through 4, AV detects a discrepancy between the precinct tape and the official record. In this category, the official record may be correct; the failure is in the layer between the official record and what the public sees. AV provides two distinct contributions. First, when the public-facing infrastructure is unavailable — the Knox County case — AV provides an independent citizen-held source of precinct-level totals that the public, candidates, and press can consult without depending on the disrupted state infrastructure. The dissemination function shifts to a network of independently held records that are not subject to the same disruption. Second, when the public-facing infrastructure displays altered or fabricated results, AV’s per-precinct evidence is the comparison that exposes the alteration: the AV-aggregated total, computed from independently captured tapes, will not match the manipulated public-facing total, and the discrepancy is legible immediately. Neither contribution prevents the underlying attack. Both close the window in which the attack is consequential.
VIII. Category 6: Audit and Verification Failures
The safeguards designed to catch errors fail to function.
Every American election operates under some audit and verification regime. The regimes vary widely across states — risk-limiting audits in some, fixed-percentage hand tallies in others, logic-and-accuracy tests in almost all, recount procedures available in most — and they are the primary institutional mechanism for catching the failures described in the preceding categories. This section catalogs the documented failure modes of those regimes: the ways in which the verification layer itself fails to perform the function for which it is designed.
Audits reporting high accuracy despite documented errors is the most direct failure mode. Monmouth County, New Jersey, in 2022 conducted its standard post-election audit and reported “100 percent accuracy” while, in fact, six flash drives had been double-counted and the wrong candidate had taken office. The audit was not designed to detect the specific failure that had occurred, and it did not. The Monmouth case establishes a general principle: an audit’s guarantees apply only to the question the audit is structured to ask, and if the real failure lies outside the audited question, the audit’s passage provides no information about the failure’s absence.
Risk-limiting audits that miss reporting-layer errors is the Prince William County case: a ~4,000-vote reporting error survived a statewide RLA that confirmed the counting layer with 99%+ confidence, because the error lived in the reporting layer the audit was not examining. The failure is instructive as a general instance: risk-limiting audits as currently designed typically verify the counting layer of the three-layer model while leaving the reporting layer unchecked. The distinction matters because the two layers have different failure modes, and a verification regime calibrated for one is not a verification regime for the other.
Audit judges not performing required procedures is the Cook County, Illinois, 2016 case. Audit judges in Cook County were legally required to hand-tally 5 percent of precincts and compare to machine totals. In documented instances, they instead printed the official machine results, placed them on tally sheets, and signed off without performing the hand tally. When independently conducted comparisons revealed discrepancies, some judges erased and adjusted rather than investigating. The Cook County failure is distinct from the Monmouth and Prince William failures in that the audit regime was structurally adequate to catch the problem; it failed because the humans conducting it did not conduct it. This is not a vulnerability of the audit design but of the audit implementation, and it is worth naming separately because the two failure modes call for different remedies.
Post-election checks that do not cover enough precincts is the North Carolina Supreme Court 2020 case. North Carolina’s mandatory post-election audit sampled approximately 7.5 percent of precincts. The hand-to-eye comparison covered 3 percent. The machine recount covered all precincts but tested counting accuracy, not reporting accuracy. None of the three regimes systematically checked the full reporting chain. In a statewide race decided by 401 votes out of 5.4 million, the fraction of the reporting chain covered by any check was insufficient to resolve confidence at the margin.
Several plausible failure modes in this category are not specifically documented in public record. Statistical audits that do not reach their escalation threshold — because a distributed reporting-layer error produces per-precinct discrepancies smaller than the per-precinct detection threshold — could pass a risk-limiting audit without triggering escalation. An audit of the wrong thing, structurally similar to the Prince William case but occurring in a different race or jurisdiction, could produce high confidence in a question adjacent to the one that actually matters. Auditor fatigue and resource constraints, especially in jurisdictions with long ballots and many simultaneous races, could lead to audits that technically comply with legal requirements but cut corners in ways that miss real problems.
A further class of audit-design vulnerability has been documented in the academic literature on risk-limiting audits. The risk-limiting audit’s statistical guarantee depends on the integrity of the ballot manifest — the document that records, for each batch of ballots, where the batch is stored and how many ballots it contains — and on the assumption that the audit is sampling from the same population whose count is being verified. Stark and collaborators have repeatedly identified the manifest-integrity problem as the principal structural limit on what RLAs can prove (Stark — Conservative Statistical Post-Election Audits, Annals of Applied Statistics, 2008; Lindeman & Stark — A Gentle Introduction to Risk-Limiting Audits, IEEE Security & Privacy, 2012). An RLA conducted against a manipulated manifest can certify the audited contest at high confidence while the underlying population the audit purports to verify has been altered. The “compliance audit” — an audit of the manifest itself, addressed in some state RLA implementations and absent from others — closes part of the gap but introduces its own dependencies on procedural and physical controls. Appel and Stark’s broader treatment of evidence-based elections (Appel & Stark — Evidence-Based Elections: Beyond Election Forensics, Election Law Journal, 2020) develops the structural argument that RLAs are necessary but not sufficient for election verification, and that the assumptions on which their statistical guarantees rest are themselves verification problems that require independent evidence to address.
A second class of audit-design vulnerability concerns the logic-and-accuracy testing regime that many states require before each election. L&A testing is intended to verify that the equipment processes test ballots correctly under controlled conditions before being used in live operations. The structural limit of L&A testing is that it cannot reliably detect failure modes that emerge only at scale, only under election-day operational conditions, or only in specific configurations of ballot styles, precincts, and races that the test deck does not cover. Northampton County’s 2019 ES&S ExpressVote XL configuration error is the documented case in which the relevant L&A testing did not catch the configuration defect that produced the Election Day failure. The general property — that pre-election testing covers a fraction of the configuration and operational state space and that residual untested combinations exist by construction — is recognized in the EAC’s Voluntary Voting System Guidelines but is not closed by them (EAC — Voluntary Voting System Guidelines 2.0).
Actual Vote is not itself an audit. It is an independent data source that makes audits more effective. When an audit regime is calibrated to the wrong question, or conducted under conditions that prevent it from performing its function, AV provides the evidence that would have caught what the audit missed — evidence that is independently held, covers every precinct where volunteers participated rather than a statistical sample, and is indexed to the precinct rather than to the aggregate. In the cases where audits have failed, AV would have supplied the external check whose absence is what made the audit failure consequential.
IX. Category 7: Evidence Destruction and Chain-of-Custody Failures
The evidence that would resolve questions is destroyed, lost, or compromised.
Many of the cases in this collection involve questions that were not resolved not because the evidence was insufficient at the time, but because the evidence did not survive to be examined. This category catalogs the mechanisms by which that happens.
Ballot destruction by statute is the Baldwin County, Alabama, model. Alabama law required destruction of the county’s ballots on a schedule that foreclosed the independent recount that would have resolved the central question of what had actually happened at the Magnolia Springs precinct. The ballots existed; the statute required their destruction; the destruction occurred before the litigation that sought to examine them could reach the point of compelling production. The question is permanently unanswerable on the physical evidence. Baldwin County is not unique in this respect; states vary in their ballot-retention periods, and jurisdictions vary in the rigor with which they observe them.
Record destruction despite federal preservation orders is the Ohio 2004 model. Fifty-six of Ohio’s eighty-eight counties destroyed election records from the 2004 presidential election despite federal law requiring twenty-two-month retention and despite a federal court order directing preservation. No prosecutions followed. The case establishes that the existing preservation regime is, as an enforcement matter, substantially dependent on the good faith of the county officials whose conduct might be the subject of subsequent investigation. When those officials choose not to preserve, the legal consequences have historically been limited. The resulting evidentiary gap is structural: on matters where questions were raised about what Ohio’s reporting layer produced in 2004, the primary-source evidence is gone, and the good-faith assumption that would be required to accept the official record in its place is the assumption the questions themselves put into doubt.
Unsigned tabulator tapes and chain-of-custody gaps are the Fulton County 2020 model. More than 130 tabulator tapes covering over 315,000 votes in the Atlanta metropolitan area were discovered to be unsigned, in violation of Georgia’s own procedural rules. Ten tapes covering over 20,000 votes were missing entirely. The State Election Board formally reprimanded Fulton County in 2024 for more than 140 procedural violations during the 2020 recount. Every formal investigation concluded that the procedural failures did not change the outcome of the presidential race, which three separate counting processes confirmed. But the chain-of-custody gap is real, and it has proven sufficient — five years on — to sustain new cycles of allegation that the existing official record has been unable to decisively rebut.
Several plausible failure modes in this category have not surfaced as documented incidents. Selective evidence destruction, in which records from specific precincts disappear while the bulk of the county’s records remain intact, would be far more difficult to distinguish from administrative error than wholesale destruction and would be a correspondingly more effective form of manipulation. Digital evidence degradation — election records stored on USB drives, hard disks, or optical media that become unreadable with age — is an ordinary consequence of the retention of digital records on consumer-grade storage, and in jurisdictions without rigorous media-migration practices, it is a question of when rather than whether the records become inaccessible. Chain-of-custody gaps during the long interval between elections, when election materials are stored in facilities accessible to custodial staff, building maintenance, and others without election authority, are a real but structurally difficult vulnerability to close.
Actual Vote’s core structural advantage against this category is that its evidence exists outside government custody. Actual Vote records cannot be destroyed by the officials whose work they verify. They cannot be destroyed by operation of a state statute to which they are not subject. They cannot be lost in a courthouse basement because they were never in a courthouse basement. They cannot be rendered unreadable by aging government hardware because they are held redundantly, by volunteers, on consumer devices that can be refreshed and migrated as technology changes. This is, in the collection’s view, the single most important structural argument for independent evidence — not that Actual Vote catches more errors in real time than existing safeguards, though it does, but that its evidence persists when existing evidence does not.
X. Category 8: Systemic and Structural Vulnerabilities
Features of the election system itself that create and sustain vulnerability.
The preceding six categories describe specific points in the reporting chain where failures occur. This category describes the features of American election administration that make those failures possible in the first place, and that allow them to recur across decades.
Vendor non-disclosure of known bugs is the first such feature. The GEMS upload bug documented in Butler County 2008 had been known to Premier/Diebold for years before the Butler County discovery and was not disclosed to the jurisdictions running the software. The effect was that the same bug — in the same software, from the same vendor — affected thirty-four states across a decade and was rediscovered locally by each jurisdiction that encountered it, without benefit of the vendor’s institutional knowledge. This is not an incidental feature of the vendor relationship; it is a consequence of the legal and commercial structure under which election software is produced and sold. Source code is treated as a trade secret. Defect disclosure is not mandated. Jurisdictions sign purchase contracts that frequently include non-disclosure provisions. When a defect is discovered, no institutional channel exists through which its existence is communicated to peer jurisdictions that may be affected by the same defect.
Corporate acquisitions that transfer bugs without remediation is a related feature. The GEMS software passed from Global Election Systems to Diebold to Premier to ES&S to Dominion through a series of acquisitions and divestitures, with the underlying architectural features of the database — including the DOUBLE data type at the root of the Fraction Magic architecture — persisting through the ownership changes. Whether successor software retains particular defects depends on whether the acquiring vendor audits and remediates the inherited codebase, and in the absence of regulatory requirement or market pressure, such remediation is not systematic.
No mandatory reporting of election system malfunctions is a third feature. As of 2010, the Brennan Center documented that voting machine manufacturers were not required to report malfunctions to any government agency, and that approximately 99 percent of American jurisdictions used equipment that was not covered by federal certification or reporting requirements. The resulting information environment is one in which defects surface only when individual jurisdictions experience them severely enough to notice, and in which the resulting knowledge is dispersed across thousands of local officials rather than consolidated into any authoritative public record.
Fragmented jurisdiction compounds each of the preceding features. The United States conducts federal elections through more than 10,000 local jurisdictions, each making independent technology and procedural decisions under state-level frameworks that vary widely. A fix applied in one jurisdiction does not propagate to others. The same bug can be discovered, responded to, and apparently resolved in one county while remaining active in hundreds of others. The GEMS bug appeared in Gaston County in 1998, in Butler County in 2008, and in Shelby County in 2015. Seventeen years separate the first and last documented instances, and across that span the bug continued to produce discrepancies in jurisdictions that had not yet encountered it severely enough to diagnose it.
Cost-driven elimination of safeguards is a fifth feature. Shelby County, Tennessee, stopped comparing poll tapes to official results — the specific comparison that would have caught the 40 percent discrepancy Bennie Smith subsequently discovered — as a budgetary measure. The safeguard had existed; it had worked; it was eliminated. This is the general form of a class of decisions that election administrators routinely face under resource constraints, and in the aggregate those decisions have produced an audit and verification regime whose coverage of the reporting layer is substantially less comprehensive than the letter of state law would suggest.
Plausible but unobserved features in this category include monoculture risk — the concentration of the American election-system market in a small number of vendors whose products run on shared platforms and libraries, such that a vulnerability in a widely shared component could affect thousands of jurisdictions simultaneously — and institutional knowledge loss, the erosion of workaround knowledge that occurs when experienced election officials retire or leave office. Prince William County’s reporting error is partly explicable as a consequence of the latter: the departing registrar carried institutional knowledge about format incompatibilities that was not fully transferred to the successor. A third plausible feature is inadequate testing of jurisdiction-specific configurations: vendor testing occurs under controlled conditions, while each jurisdiction’s actual deployment is a unique combination of ballot design, precinct structure, scanner models, network configuration, and administrative procedures, and edge cases that do not appear in vendor testing can emerge in production for the first time on election day.
Actual Vote does not remediate these structural features. It does, however, detect their consequences, which is a different kind of contribution. More important, and more difficult to measure, is the effect that widespread AV deployment has on the incentive structures that sustain the structural features. If jurisdictions know that precinct-level results are independently captured and compared, the cost-benefit calculation that permits non-disclosure of known defects, cost-driven elimination of safeguards, and insufficient testing of local configurations shifts. The structural features persist in part because the cost of their persistence is borne primarily by the public, which has no direct mechanism for applying pressure on them. Independent evidence in citizen hands creates such a mechanism.
XI. Category 9: Adversarial Use of Generative AI Against the Reporting Layer
Threat vectors that have emerged or sharpened with the broad availability of generative AI, addressed for completeness and forward-looking accuracy.
The categories preceding this one identify failure modes whose underlying mechanisms have been operative for decades. This category names a class of threats whose mechanisms have existed in principle for some time but whose practical accessibility has changed substantially since approximately 2023 with the broad deployment of generative AI capabilities. The threats are addressed here briefly, with appropriate hedging on the maturity of the documented incident record.
AI-assisted social engineering of election officials. Phishing, business-email-compromise, and impersonation attacks targeting election officials with privileged access to EMS or reporting infrastructure have been a documented threat class for the past decade. Generative AI changes the cost structure and the linguistic quality of these attacks. CISA and the Multi-State Information Sharing and Analysis Center have flagged AI-augmented social engineering as a category of concern for the 2024 election cycle and beyond (CISA — #Protect2024). Specific documented cases of AI-augmented spear-phishing against American election officials, with public attribution, are limited at the time of writing; the underlying attack class against state and local government generally is well-documented.
Synthetic media attributed to election officials. Deepfake audio and video falsely attributed to election officials, secretaries of state, or candidates announcing or commenting on results has been theorized and demonstrated experimentally but, at the time of writing, has not produced a publicly documented executed instance against a US election that altered official results or perception in a measurable way. The Brennan Center’s 2024 treatment of the threat (Brennan Center — Preparing Elections in the Age of AI, 2024) and Microsoft’s election-cycle threat reporting (Microsoft Threat Analysis Center — election interference reports, 2024) document the underlying capability and the early indicators of deployment in adjacent contexts.
AI-generated disinformation about specific precinct or county results. Generative AI substantially reduces the cost of producing locally targeted false content — fabricated press releases, false social media posts attributed to specific election offices, fabricated screenshots of state reporting websites showing different totals than were actually reported. The Stanford Internet Observatory’s documentation of coordinated inauthentic behavior in the 2020 cycle (Election Integrity Partnership — The Long Fuse, 2021) establishes the baseline for the pre-AI version of this threat; the 2023-2024 literature documents the cost reduction and the increased volume now feasible.
Actual Vote’s contribution against this category operates through a different mechanism than against the categories upstream. Where the threat is a synthetic announcement of false results, AV provides authoritative independent precinct-level evidence that can be cited to refute the announcement. Where the threat is AI-augmented social engineering producing an EMS compromise, AV’s contribution is the same as against any other EMS compromise: the post-compromise altered totals do not match the precinct tapes captured before the compromise. Where the threat is AI-generated disinformation targeting specific precincts or counties, AV’s per-precinct ground-truth data is the comparison that establishes which claims are false. The category is included not because AV introduces novel detection capabilities for the AI-era variants but because the AV architecture, designed before the era, happens to produce evidence with exactly the properties the era’s threats most directly call for: independent, locally indexed, and held outside the institutions whose statements are being impersonated.
XII. Category 10: Transparency Failures (Access-to-Evidence Vulnerabilities)
The public is prevented from verifying correct or incorrect reporting, independent of any question about the underlying accuracy of the count.
The first seven categories are about what can go wrong in producing the official numbers. This category is about what can go wrong in the public’s ability to verify those numbers independently. It is a distinct category because the failure modes are distinct: an accurate election that the public cannot verify is not the same as an accurate election that the public can verify, and an inaccurate election that the public cannot verify is a harder problem than one in which the inaccuracy is at least visible. Transparency is a value independent of accuracy, and its specific failure modes deserve their own cataloging.
Public-records denials on primary-source evidence is the archetypal access-to-evidence failure. Open-records requests for poll tapes, tabulator memory cards, real-time audit logs, and cast vote records are routinely denied or restricted by state statute, by custodial practice, or by judicial interpretation. The Clarkson v. Lehman litigation in Kansas from 2014 through 2018 is the most thoroughly documented instance. Beth Clarkson, a chief statistician at Wichita State University’s National Institute for Aviation Research, identified a statistical pattern in Kansas returns that she believed warranted investigation, and filed an open-records request — under the Kansas Open Records Act — for the real-time audit log tapes from a small number of Sedgwick County precincts. Her request was denied, on the grounds that the tapes were “ballots” within the meaning of K.S.A. 25-2422(a)(1), the criminal prohibition on ballot content disclosure. Her first lawsuit (2013) was dismissed. Her second lawsuit (2015–2016) produced a trial-court ruling that upheld the denial. The Kansas Court of Appeals in 2018 dismissed the appeal as moot because the audit log tapes at issue had been destroyed pursuant to Kansas’s twenty-two-month retention statute while the appeal was pending. No court at any level ever reached the merits of whether the tapes should have been producible; the final resolution was not that Clarkson was wrong to ask, but that the evidence she was asking for no longer existed. The denial was effectively permanent regardless of the underlying legal merits.
Collateral estoppel and procedural bars is a closely related failure. Courts can and do foreclose successive requests for primary election evidence on the ground that an earlier denial has resolved the question, without the evidence ever having been produced or the underlying question ever having been reached on the merits. This converts a single denial into a permanent exclusion, and it does so without any affirmative determination that the public should not have access to the evidence. The Clarkson case illustrates this as well: the 2015 lawsuit was partially defended on the basis that Clarkson’s 2013 lawsuit had raised “the same issues,” which the trial court had rejected, and therefore that the matter should not be relitigated.
Late-resolving judicial access is a third failure mode that operates even when the legal system ultimately sides with the requester. Records requests that are initially denied can, in principle, be appealed. But the appeal process routinely consumes months or years. By the time a favorable ruling arrives, the underlying evidence has frequently been destroyed in the ordinary course — retention periods having expired, media having been recycled, storage having been reorganized — and the political moment to which the evidence was relevant has passed. The pattern is functionally identical to denial: access is not granted during the period in which it would have mattered.
Proprietary-software opacity is a fourth failure mode, of a different structural character than the first three. The voting and tabulation systems used in American elections are produced by vendors who assert trade-secret claims over the source code, the internal data schemas, and in some cases the administrative interfaces through which officials interact with the software. Independent researchers are unable to verify the behavior of the software that produces official results, and jurisdictions frequently lack the expertise or the contractual access to verify it themselves. The result is that primary-source evidence — the question of what the software is actually doing, as distinct from what it reports — is permanently unavailable for public inspection, not because of a records denial but because of a commercial regime that treats the evidence as the vendor’s property.
Statutory prohibitions on ballot-level inspection are a fifth mode, operating at a different layer of the system. Many states criminalize or sharply restrict public inspection of physical ballots after canvass, on privacy grounds. These prohibitions generally serve legitimate purposes — most directly, protecting the secret ballot — but they have the side effect of placing primary counting-layer evidence permanently out of reach for post-election verification. The Kansas recount statute construed in Clarkson v. Lehman is an instance at the statutory level, though the Kansas courts read it together with the ballot-disclosure prohibition in K.S.A. 25-2422(a)(1) to foreclose even tape-level access.
The observer-access gap is a sixth mode. Partisan and nonpartisan observers are entitled to be present during specific stages of the election process in most American jurisdictions. Their access, however, is typically limited to visual observation and excludes evidence capture — an observer who sees a tabulator tape being printed is not the same as a record of what that tabulator tape said. The gap matters structurally because it means that observer presence does not produce a durable public record of the primary-source material, even when the observer would have preserved it if permitted to do so.
Actual Vote’s distinctive contribution to this category is different in kind from its contribution to the preceding categories. In Categories 1 through 9, AV detects a reporting-layer discrepancy or supplies the evidence on which one would be detected. In this category, it is not a matter of AV catching a failure; it is a matter of AV producing the evidence that the denied records request was seeking, outside the access regime that produced the denial. AV evidence is not subject to open-records statutes because it is not a government record. It is not subject to collateral estoppel because it is not produced for a specific legal proceeding. It is not subject to vendor trade-secret claims because it is captured at the tape, downstream of the vendor’s software. It is not subject to ballot-privacy statutes because it records aggregate totals, not individual ballots. It is not subject to observer-access rules because it is captured at the point of public posting of the poll tape, which in many jurisdictions is a permissive-photography context. The Clarkson-type statistical analysis — the comparison of precinct-level results against precinct size and other covariates — becomes feasible at scale, immediately, without any request for custodial records. By existing outside the access regime that constrains primary-source election evidence, AV transforms transparency from a question of legal access into a question of citizen participation.
XIII. Category 11: Counting-Layer Vulnerabilities and Alternative Ballot-Intake Pathways (Beyond AV’s Detection)
Included for completeness and for honesty about the limits of what Actual Vote does.
All of the categories above concern vulnerabilities downstream of the scanner’s poll tape — vulnerabilities in the reporting layer or in the regimes that surround it. Actual Vote is designed for and limited to the reporting layer. The counting layer — what happens inside the voting machine, before the poll tape prints — is outside AV’s detection scope, and the vulnerabilities in that layer are not caught by comparing tapes to official results. This section catalogs those vulnerabilities, in part because completeness requires it, and in part because readers who have worked through the preceding categories deserve a clear statement of what AV does not do.
Ballot stuffing — extra ballots introduced into the count before the scanner reads them — is the classic counting-layer fraud. The poll tape reflects the scanner’s count of whatever ballots were present, including the fraudulent ones. AV sees a tape-to-official match and has no basis for flagging the underlying problem. Vote-flipping on DRE (direct recording electronic) touchscreens — the touchscreen recording a voter’s selection as a vote for a different candidate than the one the voter chose — is similarly invisible to AV. The tape reflects what the DRE recorded, not what the voter intended, and AV compares the tape to the official result without reference to voter intent. Machine miscalibration on optical scanners is a third subtype: if the scanner is miscalibrated such that it systematically misreads marks, the tape reflects the misreading and AV has nothing against which to compare it at the counting layer.
Three further counting-layer-adjacent vulnerabilities are worth naming for completeness. Voter suppression — eligible voters prevented from casting ballots, by registration purge, polling-place closure, intimidation, misinformation, or other means — operates at the ballot-assignment layer and produces no forensic trace of its own at the reporting layer. There is nothing for AV to detect after the fact. Ballot design problems — confusing layouts, misaligned bubbles, unintuitive instructions — produce errors in the voter’s marking action rather than in the machine’s reporting action. The butterfly-ballot episode in Palm Beach County, Florida, in 2000 is the archetypal instance. The scanner counts what the voter actually marked; the error is in the voter’s marking, induced by the ballot design, and AV cannot distinguish an intended vote from an elicited mismark. Counting-layer tabulation software manipulation — a compromised tabulator that alters the count during the scanning process, before the tape prints — is the Fraction Magic-adjacent case in which the tape itself is corrupt. AV would compare a corrupted tape against corrupted official results and see no discrepancy. This is a real limitation and the collection names it explicitly.
These are serious vulnerabilities. AV does not detect them, and the collection does not claim otherwise. What AV does claim is that the reporting layer is the most comprehensively unverified step in the chain, that reporting-layer failures are the most frequently documented class of failure in the case studies, and that a system in which the reporting layer is verified is strictly better than a system in which it is not — even where counting-layer vulnerabilities remain. Closing one structural gap does not require closing every structural gap. Verifying every step of the chain would be better than verifying the reporting layer alone, but the latter is available immediately, at low cost, through ordinary citizen participation, and the former is not.
These counting-layer tools and Actual Vote are complementary rather than competing. Risk-limiting audits, hand recounts, and ballot-image audits are designed to verify the counting layer; Actual Vote is designed to verify the reporting layer; and a jurisdiction that wants both forms of verification can have both. The objection sometimes raised — that AV is insufficient because it does not catch ballot stuffing or a corrupted scanner — mistakes a division of labor for a deficiency. It is like objecting that a smoke detector is insufficient because it does not prevent arson.
There is, however, a partial exception worth naming explicitly. The DeKalb County, Georgia, 2022 case involves a counting-layer error — a positional mismatch between ballot marking devices and precinct scanners that caused the scanners to misread every ballot at 32 of 40 District 2 precincts. The poll tapes printed by those scanners reflected the incorrect counts, and a naive AV comparison of poll-tape totals against the official county summary would have found the two matching, since both reflected the same scanner output. By the standard tape-vs-result mechanism, AV would not have caught it. But the tapes themselves were identifiable as wrong on inspection: candidate Michelle Long Spears showed zero Election Day votes in the precinct where she and her husband had voted, with the same impossible pattern repeating across most precincts in the district. Spears performed manually, by driving from precinct to precinct on the evening of and morning after the election, exactly the precinct-by-precinct poll-tape gathering that AV systematizes, and the public availability of the tapes was what made the inspection possible. The implication is that AV’s poll-tape transparency catches some counting-layer errors not by the standard comparison but by making the content of the tapes visible to anyone with knowledge of ground truth — most naturally, the affected candidate or her supporters. This is an additive capability, and it is reliable only for counting-layer errors that are large enough, patterned enough, or externally falsifiable enough to be visible on inspection. A subtler counting-layer manipulation that produced plausible-looking tape numbers would not be caught by this mechanism. AV remains structurally unsuited to catching counting-layer fraud as a general matter, but the DeKalb case extends the practical envelope of what poll-tape transparency can flag — particularly when the candidate herself is positioned to detect it.
A separate class of vulnerability falls outside AV’s detection scope for a different structural reason. The body of the taxonomy addresses the reporting chain that runs from the precinct scanner through the EMS to the published official total. A separate ballot-intake pathway, used in every state for some subset of voters and in some states for substantially larger populations, falls outside that chain entirely: the Uniformed and Overseas Citizens Absentee Voting Act (UOCAVA) regime, under which military and overseas voters in some jurisdictions return ballots through electronic channels — email, fax, web portal — rather than through the precinct equipment that the rest of the taxonomy covers. The UOCAVA reporting pathway has its own attack surface, its own documented vulnerabilities, and its own consequences for the integrity of reported totals, and it is included in this category because Actual Vote’s detection mechanism does not reach it.
The peer-reviewed academic literature on electronic ballot return is unusually substantive for an election-security topic. Specter, Koppel, and Weitzner’s analysis of the Voatz mobile voting system, used by several US jurisdictions for UOCAVA ballot return, identified architectural defects that would permit alteration of votes in transit, fabrication of votes attributed to legitimate voters, and disclosure of voter identity in association with vote choice (Specter, Koppel, Weitzner — The Ballot is Busted Before the Blockchain, USENIX Security 2020). Specter and Halderman’s subsequent analysis of the Democracy Live OmniBallot system, deployed for UOCAVA ballot return in additional jurisdictions, identified comparable defects (Specter & Halderman — Security Analysis of the Democracy Live Online Voting System, USENIX Security 2021). The joint federal risk assessment issued by CISA, the Election Assistance Commission, the FBI, and NIST (Risk Management for Electronic Ballot Delivery, Marking, and Return, 2020) classifies electronic ballot return at the highest risk level among the practices it evaluates and recommends against its use; the recommendation has not been universally adopted at the state level.
The structural property of the UOCAVA regime that places it outside AV’s detection scope is that ballots returned electronically do not pass through the precinct equipment that produces the poll tape on which AV’s evidence depends. There is no precinct tabulator counting these ballots, no tape printed, no AV capture point. The electronically returned ballots are processed centrally, typically aggregated into county or state totals through a workflow that varies by jurisdiction, and reported either as a separate line item or commingled with in-person and absentee totals at the county level. AV’s verification of the in-person component of an election leaves the UOCAVA component verified only by whatever additional procedures the jurisdiction applies to that pathway. In jurisdictions where UOCAVA volume is small relative to total turnout, the consequences are bounded; in close races and in jurisdictions where UOCAVA volume is substantial, the absence of AV-style independent verification is a structural gap that the taxonomy is obligated to name.
This is a real limit and, like the counting-layer limits addressed earlier in this category, the collection does not obscure it. Closing the UOCAVA verification gap requires solutions that operate at the point of UOCAVA ballot processing — verifiable cryptographic protocols, paper-record-of-record requirements, post-receipt independent audit — none of which AV provides. What AV provides is verification of the in-person and standard absentee pathways, which in most American jurisdictions account for the substantial majority of cast ballots. The gap is named so that the AV proposition is not misread as a claim to comprehensive election verification.
XIV. The Compound Risk
The preceding categories describe failure modes one at a time. The full risk picture for American elections requires considering them in combination. Any individual vulnerability might be rare, might be small, might be unlikely to change an outcome on its own. The systemic risk is in the interaction.
Consider a hypothetical election in which a single county has a memory-card upload failure in one precinct (Category 1), a second county has a silent aggregation bug in its tabulation software (Category 2), a third has a manual-transcription error in the state reporting portal (Category 3), a fourth jurisdiction’s election-night reporting site is briefly disabled by a denial-of-service attack during the window in which press coverage forms (Category 5), the statewide risk-limiting audit is calibrated to verify counting-layer accuracy rather than reporting accuracy (Category 6), ballot-retention statutes cause the physical evidence to be destroyed before post-election inquiry reaches the point of compulsory production (Category 7), and the relevant state’s open-records statute exempts tabulator logs from public inspection (Category 10). No single failure in this list needs to be large. No single failure needs to be deliberate. In combination, they describe an election whose reporting layer is unverified, whose errors are invisible to the audit regime, whose evidence cannot be preserved long enough to examine, whose dissemination layer can be briefly disrupted at a politically sensitive moment, and whose primary-source records cannot be obtained by the public. That is not a hypothetical picture. It is a composite of the case studies that precede this document, and it is a composite that can be assembled from the institutional features of many American states.
The case studies demonstrate the pattern repeatedly. Monmouth County’s reporting error survived a “100 percent accuracy” audit. Virginia’s Prince William County error survived a greater than 99 percent confidence RLA. Ohio’s 2004 evidence was destroyed despite a federal court order. Kansas’s tabulator tapes were destroyed during the pendency of Clarkson’s appeal. Fulton County’s 2020 tapes are in part unsigned and in part missing. The Knox County, Tennessee, 2018 case illustrates the same compound pattern at the dissemination layer: an underlying record that was correct, an audit regime adequate to the official process, and a public-facing infrastructure whose disruption nonetheless produced a window in which the public’s view of the result was effectively a separate question from the result itself. In none of these cases did a single failure produce the documented outcome. In each case, the documented outcome was produced by the interaction of a failure at one layer with a gap in the verification or preservation regime at another layer. The existing safeguards are not layered in a way that catches reporting-layer errors, because the failure modes distribute across categories that the individual safeguards were not designed to cover together.
The compound pattern has a temporal dimension as well as a structural one. The window between the close of polls and the official certification of results, typically lasting between several days and several weeks depending on the jurisdiction, is the period during which unofficial results circulate in public, the press forms its narrative of the election, candidates make decisions about concession and challenge, and the legal and political response to any anomaly is most consequential. Attacks and failures that would be readily corrected if they manifested only after certification can have substantially larger consequences when they manifest during this window. The Stanford Internet Observatory’s Long Fuse report on the 2020 cycle (Election Integrity Partnership — The Long Fuse, 2021) documents the pattern at length for that election: the most consequential post-election information failures were not the ones that produced false certified totals but the ones that produced widely held false beliefs about totals during the certification window, with downstream consequences that persisted long after the underlying claims had been refuted on the merits. The structural feature that makes this window distinctive is that the official record is not yet final. Unofficial results are explicitly preliminary; corrections to those preliminary results are expected; the public and the press are accustomed to results shifting as additional precincts report. Adversarial action that introduces false shifts during this window therefore exploits a baseline expectation of legitimate change, and the cost of correction is correspondingly high. The Brennan Center’s 2020 treatment of cyberattack and technical-problem preparedness during the voting and reporting windows documents the operational practices that close some of this gap and the practices that do not (Brennan Center — Preparing for Cyberattacks and Technical Problems During the Voting Process, 2020).
Actual Vote’s distinctive structural contribution is that it adds a layer independent of all the others. Its data is not produced by the election administration system. Its custody is not subject to the administration’s retention policies. Its comparison is not subject to the administration’s audit calibration. Its availability is not subject to the administration’s records-disclosure rules. It is not a replacement for any of the existing safeguards; it is an external check that persists when the existing safeguards fail in combination, because the failure modes that cascade across the existing safeguards cannot cascade into evidence that the administration does not produce, does not hold, and does not control. That the existing safeguards do not catch these failures is not a sign that they are poorly designed; it is a sign that they were designed for a different problem. Risk-limiting audits, recounts, and canvasses verify the counting layer, and they do so well; the reporting layer is simply outside the problem they were built to solve. Actual Vote’s contribution is not to perform their function more effectively but to cover the layer they were never intended to check.
XV. Conclusion: The Case for Independent Verification
The taxonomy this document has mapped consists of eleven categories of vulnerability in American vote reporting. Eight of them describe failure modes in the reporting chain itself, from precinct equipment through central tabulation, through the public dissemination layer, through the regimes of audit and evidence preservation, and through the structural features of American election administration that produce and sustain those failure modes. One describes a class of threat vectors associated with the broad availability of generative AI, whose practical accessibility has changed substantially in recent years and which sharpen several of the upstream failure modes. One describes failures of the public’s access to primary-source evidence of the reporting layer. One describes vulnerabilities outside the reporting layer — counting-layer vulnerabilities and alternative ballot-intake pathways such as UOCAVA electronic ballot return — that Actual Vote does not catch, included for completeness and for honesty about the limits of the method.
The case studies in the collection document more than a dozen specific instances drawn from this taxonomy, spanning from the 1860s through the present, across every major region of the country, under every major vendor’s equipment, and affecting races decided by margins ranging from 87 votes to the presidency. The taxonomy also identifies additional plausible vulnerabilities that have not yet surfaced as documented incidents but that are permitted by the same structural conditions that have produced the documented ones. The vulnerabilities are not rare. They are not confined to any particular decade, party, state, vendor, or technology. They are not theoretical. They recur because the architecture of American vote reporting has features that produce them, and those features persist because the existing verification regime does not produce pressure sufficient to eliminate them.
Actual Vote addresses the reporting layer — the most under-checked segment of the chain — and it does so in a way that is independent of the access regimes that constrain primary-source election evidence. It also operates at the layer of public dissemination, providing an independent source of precinct-level evidence that the public can consult when official dissemination infrastructure is disrupted, manipulated, or unavailable. It does not solve every problem in election security. It does not address the counting layer, alternative electronic ballot-return pathways, the ballot-assignment layer, or most of the voter-facing questions that election administration involves. What it solves is a narrower and more tractable problem: whether the numbers on the precinct tapes match the numbers in the official results, and whether independent evidence of those tape-level numbers is available to the public during the windows in which the answer is most consequential. It makes that comparison performable by any citizen, in any American jurisdiction, without a court order, a records request, or a vendor’s cooperation. And it makes the evidence on which the comparison depends persist outside government custody, so that questions about the reporting layer can be answered even years after the evidence held by the administration has been lawfully or unlawfully destroyed.
The strongest argument for Actual Vote is not any single case study. It is the pattern across all of them: the same structural vulnerability — an unchecked reporting layer, paired with a constrained access regime, paired with a preservation regime that depends on the good faith of the actors it is meant to check — appearing decade after decade, jurisdiction after jurisdiction, in equipment from every major vendor, under every type of audit regime and every open-records statute. The vulnerability persists because no one systematically checks it, and because the evidence needed to check it is systematically kept out of public hands. Actual Vote systematically checks it, and the evidence systematically stays in public hands. That is the structural contribution that the taxonomy is intended to make legible: not a new audit, not a new regulation, not a new piece of software inside the election administration system, but an independent data source, produced by citizens at the point of the precinct poll tape, available for comparison against official results by anyone who cares to make the comparison, and persistent beyond the custody of the institutions whose performance is the subject of the comparison.