REPORT: The Paper Trail: Assessing Oklahoma's Election Integrity Against the Declassified Record

Executive Summary

In July 2026, the White House declassified and released intelligence documents that allegedly revealed "shocking vulnerabilities" in American election infrastructure. That claim is serious and deserves an equally serious vetting. Confidence in elections is not a partisan asset; it is the operating condition of self-government. When trust erodes, the consequences are real — decreased turnout, reactive public policy, and political violence.

Let's Fix This reviewed 33 documents and reports across the three areas the White House identified: Chinese acquisition and exploitation of American voter data, vulnerabilities in electronic voting and ballot-counting systems, and noncitizens on state voter rolls. Where the materials addressed Oklahoma directly, we examined the claims. Where they described the American election system generally — as most did — we compared those descriptions against Oklahoma state law and practice. Throughout, we held to a distinction the public conversation tends to collapse: the difference between a vulnerability that exists, an attempt to exploit it, a successful exploitation, and an exploitation that changed how an election was administered or how it came out.

Oklahoma's voting infrastructure is highly resistant to direct manipulation. Every Oklahoman marks a paper ballot, read by a tabulator that cannot be connected to the internet, and ballots are retained after the election. Chain-of-custody requirements, state ownership and maintenance of the equipment, bipartisan participation in election administration, and mandatory post-election audits layer on top of that. Even if a tabulator machine failed or was somehow compromised, the physical ballots remain an independent record of what voters actually chose.

The Oklahoma voter data identified in the declassified materials was not taken from the state. It was downloaded from a commercial website, and at the time it was gathered, Oklahoma law had made the voter list public information for more than thirty years. That law has since been tightened; it is now unlawful to knowingly provide the list to a foreign national, foreign commercial interest, or foreign government entity. The aggregation of Oklahomans' personal information by a foreign actor remains a legitimate concern, but that risk exists outside of our election infrastructure.

Documented voter fraud in Oklahoma is extremely rare. From 1982 through 2025, we identified six cases resulting in criminal convictions, and none for a noncitizen registering or casting a ballot. The absence of a conviction is not proof that nothing has ever occurred — the State Election Board referred three cases from 2024 involving suspected noncitizens — but the record does not describe a widespread problem.

The systems surrounding the ballot are harder to evaluate from the outside. Elections do not run on voting machines alone; they rely on voter-registration databases, county communications networks, ordinary office workstations, and voter-facing online services — and federal cybersecurity guidance is explicit that an attacker who cannot reach a voting machine may still find a path through a less protected one. From publicly available information, we could not independently assess the protections applied to those systems. Cybersecurity remains a top concern for governments, businesses, and individuals at all levels.

We therefore recommend three things: that Oklahoma preserve a voter-verifiable paper record as it modernizes its equipment; that the state publish more about the cybersecurity standards governing the systems around the ballot, where disclosure does not itself create risk; and that authentication for sensitive voter-facing actions be strengthened in ways that do not put new obstacles between eligible Oklahomans and their vote.

The remedy for doubt about elections is not reassurance, it is verification. Oklahoma's system was built to be verified — and on the evidence available, it holds up.

Key Findings

Oklahoma's core voting infrastructure is highly resilient to direct manipulation. Features like paper ballots, offline optical scanners, state ownership and maintenance of voting equipment, bipartisan election administration, chain-of-custody requirements, and mandatory audits create overlapping protections and preserve a record of voter intent independent of electronic tabulation. Audits and recounts have repeatedly confirmed the accuracy of reported election results.

The acquisition of Oklahoma voter data identified in the White House materials was not the result of a breach of Oklahoma's election infrastructure. The Oklahoma-specific voter information identified in the documents was publicly available and obtained from a commercial source. Foreign acquisition and aggregation of large amounts of personally identifiable information nevertheless presents a legitimate security concern, particularly when information from multiple sources can be combined.

The systems surrounding the ballot are more difficult to evaluate from publicly available information. Oklahoma's paper ballots and offline tabulators provide strong protections against direct manipulation, but election administration also depends on voter-registration databases, communications networks, ordinary workstations, and voter-facing online systems. We were unable to independently evaluate some of the cybersecurity protections applied to those systems from publicly available information. Importantly, this does not establish that those systems are insecure; it identifies an area where additional information would improve independent assessment of Oklahoma's preparedness.

Documented voter-fraud convictions in Oklahoma are rare. We identified six cases resulting in criminal convictions and found no case resulting in a conviction for noncitizen registration or voting. The absence of a conviction does not establish that noncitizen registration or voting has never occurred. Oklahoma also uses state and federal data sources to identify potentially ineligible registrations and has procedures for investigating and removing ineligible voters.

Introduction

In July 2026, President Donald Trump announced the release of intelligence documents concerning the security of American elections. Trump called for an election system "where cheating and interference are not just difficult, but virtually impossible," before concluding, "Unfortunately, the system we have today falls catastrophically short of that standard." He then announced "the immediate declassification and release of critical intelligence, revealing shocking vulnerabilities in our election infrastructure." [1]

We agree that election security is of the utmost importance. Free and fair elections that are accessible equally to all Americans are the cornerstone of American democracy. Even the perception that elections are compromised can impact voter turnout, drive policy decisions that have unintended consequences, or, most dramatically, contribute to events such as the January 6th Capitol breach. We wanted to review the claims made by the White House as they encapsulate the concerns that have been brewing about election security in recent years. We evaluate the evidence and reports they present, and assess how Oklahoma's voting process and policies withstand scrutiny. Our findings are that Oklahoma's voting process is robust and is particularly well insulated against interference. Oklahomans can be assured that our laws and practices protect their voice as well as their information and provide confidence in reliable election outcomes.

Methodology

We reviewed 33 documents and reports in three key areas of election integrity identified by the White House — China's Acquisition and Exploitation of American Voter Data, Vulnerabilities in Electronic Voting and Ballot-Counting Systems, and Noncitizens on State Voter Rolls. We examined these materials to determine the extent to which Oklahomans' data has been compromised; the role, if any, of the State Election Board in the dissemination or acquisition of that data; the documented frequency of noncitizen or other voter fraud in Oklahoma; and the vulnerabilities to which Oklahoma's voting infrastructure may be subject.

Many of the reports do not speak directly to issues in Oklahoma, but rather to broad vulnerabilities across the American election system, and so where there is no direct mention of the state, we compare what was indicated in the reports to what Oklahoma state laws or policies apply in those areas. In reviewing these materials, we distinguish between evidence of potential vulnerability, evidence that an actor attempted to exploit that vulnerability, evidence of successful exploitation, and evidence that exploitation affected election administration or outcomes. We similarly distinguish foreign influence activities intended to affect voter attitudes or confidence from attempts to interfere directly with election infrastructure or results.

Foreign Acquisition of Voter Data

Oklahoma is explicitly named in one report of those that we reviewed. [2] The document states, "Publicly available US voter registration information for six states was downloaded by a PRC [People's Republic of China]… CNE [computer network exploitation] actor on 14 January, 2022. The CNE actor…Colorado, Connecticut, Florida, Michigan, Oklahoma, Rhode Island voter registration information from US commercial websites and a US IP address" (ellipses denote a redacted section). The report further goes on to state that the voter registration information, which spanned at least 2013–2021, was publicly available for download and included names, party affiliations, email addresses, physical addresses, and phone numbers, though it is unclear from the report that the same type of information was available from every state.

While this data was obtained from a publicly available commercial source rather than through a reported breach of the State Election Board, it is pertinent to address the extent to which voter information is available to the public. At the time of this data acquisition, January 2022, 26 O.S. § 7-103.2 stated "County election boards shall maintain a current list of all registered voters in each precinct, which will reflect the address and party affiliation of each voter. Said list shall be public information" — and that had been the law since 1990. It was not until November of 2022 that the statute was first amended, and Oklahoma law still treats the voter registration list as public information, but access is now restricted. Following amendments enacted in 2025, the electronic voter list is available only to specified groups, including Oklahoma residents who are U.S. citizens, recognized political parties, candidates and their representatives, and others authorized by law. Applicants must provide identifying information and attest under penalty of perjury that they are legally entitled to access the list. Most significantly in light of the PRC's acquisition of Oklahoma voter data, state law now makes it unlawful for a recipient to knowingly provide the voter list to "a foreign national, foreign commercial interest, or foreign government entity." [3]

Among the materials reviewed for this report, we found no indication that China or another foreign actor breached an Oklahoma government database to obtain voter-registration records, but the acquisition and aggregation of Oklahomans' data by a foreign actor remains a legitimate security concern. Additionally, one document indicates that over 200 million voter-data records dated 2016 — including names, ages, phone numbers, and addresses — were "likely leaked" to China. The document does not indicate where or how that information was originally obtained. The document also lists approximately 100 more entries for data from numerous governmental, commercial, medical, educational, and civic sources. [4] The acquisition of voter data establishes that the information was obtained, but does not by itself establish the purpose for which it was acquired.

Intelligence assessments reviewed for this report indicate that China may have used personally identifiable information (PII) obtained from voter-registration databases and other sources to analyze election results [5] and target particular areas or demographic groups with information or trade actions [6] intended to influence public opinion. However, the reports reviewed did not conclude that China attempted to manipulate voting processes or election outcomes. [7]

Vulnerabilities in Infrastructure

The intelligence reports acknowledge the possibility of direct interference with American voting infrastructure, but also conclude that "it would be difficult for [foreign actors] to manipulate voting processes at scale and without detection" because of existing audits and verification procedures. [8] Oklahoma illustrates why. Many concerns about the security of electronic voting machines are substantially mitigated by the state's use of paper ballots and optical-scan tabulators. Oklahoma voters mark a physical ballot, which is read by a tabulator and retained following the election for up to 24 months. [9] Even if an electronic tabulator were compromised or malfunctioned, the physical ballots provide an independent record of voter intent against which electronic results can be checked.

Oklahoma layers additional safeguards around this system. Ballots and voting equipment are subject to chain-of-custody requirements, voting devices incorporate multi-factor authentication and anti-tampering protections, and audits conducted following every election under the direction of the Secretary of the State Election Board, Paul Ziriax, became mandatory in November 2025. [10] The State Election Board owns and maintains the state's voting devices and software and employs its own technicians to service the equipment, and the tabulators themselves are designed so that they cannot be connected to the internet. [9] Oklahoma law also requires participation by members of both major political parties in election administration, providing an additional check against unilateral control of the process. [11]

Many of the vulnerabilities U.S. intelligence has identified in the manipulation of electronic voting systems are mitigated by these practices. The most notable example of feasible direct election interference identified in the documents we reviewed occurred not in the United States, but in Venezuela. Intelligence reporting concerning Venezuelan elections attributed significant vulnerabilities to the ruling party's ability to exercise control over electronic voting machines, election personnel, results, and auditing. [12] Oklahoma's system distributes these functions and, critically, preserves a physical record independent of the electronic tabulator. The combination of verifiable paper ballots, bipartisan participation in election administration, state ownership and maintenance of equipment, and post-election auditing substantially reduces the opportunity for a single actor to manipulate an election without detection.

The voting machine itself, however, is not the only component of election infrastructure susceptible to attack. CISA has warned that election information is frequently stored or transmitted through networks and servers that may not have the same degree of isolation as voting equipment. An attacker does not necessarily need direct access to a voting machine if a less-secure device provides indirect access to a connected election network. Phishing, compromised credentials, malware, or other attacks against ordinary workstations can therefore create pathways into sensitive systems even where voting equipment itself remains offline. [13]

The Oklahoma State Election Board states that the network used to communicate securely with county election boards is owned by the State Election Board and that voter registration information is housed on a secure and encrypted server. We were unable, based on publicly available information reviewed for this report, to independently determine the extent to which that network is encrypted, segmented from other systems, or otherwise protected against the types of indirect access identified in federal cybersecurity guidance. This does not establish that Oklahoma's network is insecure. Rather, it identifies an area in which the state's security posture could not be independently evaluated from publicly available information. Greater public documentation of applicable cybersecurity standards — without disclosing operational details that could themselves create vulnerabilities — could strengthen public confidence that protections extend beyond the voting machines themselves.

Voter-registration systems present a related but distinct cybersecurity concern. The White House documents reviewed for this report demonstrate that foreign actors have obtained and aggregated large quantities of voter information, although the Oklahoma voter information specifically identified in those documents was publicly available and was not obtained through a breach of the State Election Board. [2] The fact that individual pieces of information are legally or publicly obtainable does not necessarily make their aggregation security-neutral. Names, dates of birth, driver's licenses, and social security numbers collected from multiple governmental and commercial sources may potentially be used for credential attacks, impersonation, or attempts to gain unauthorized access to voter-facing systems.

This distinction is particularly relevant to Oklahoma's online voter portal. An attacker would not necessarily need to alter vote totals to disrupt an individual's participation in an election; unauthorized changes to voter-registration information or fraudulent absentee-ballot requests could also interfere with the voting process.

These unanswered questions do not demonstrate a vulnerability, but they do identify an area deserving further examination. As Oklahoma continues strengthening election security, protecting the systems surrounding the ballot — including voter-registration databases, county election board communications, voter-facing portals, and authentication procedures — should receive the same attention given to the physical security of ballots and voting equipment. Election security presents a particular challenge, however, because many of these systems must remain accessible to the public. A secure election must prevent unauthorized access and participation without unnecessarily obstructing access by eligible voters. Security measures should therefore be evaluated not only by whether they address a potential vulnerability, but by the nature and likelihood of the threat they address, the protection they provide, and their effect on legitimate participation.

Voter Fraud and Noncitizens on Voter Rolls

Illegal voting is another vulnerability raised by the White House documents, with particular attention given to noncitizens appearing on voter rolls. Oklahoma law makes knowingly voting when ineligible, voting more than once, and several other forms of fraudulent voting a felony. [14] The available record, however, indicates that criminal convictions for voter fraud in Oklahoma are rare. From 1982 through 2025, we identified six cases resulting in convictions. [15] Three involved ineligible voting, two involved fraudulent use of absentee ballots, and the most recent involved voting multiple times in the same election. Convictions do not account for every suspected case referred for investigation. Misha Mohr, Director of Communications and Public Information for the State Election Board, explained that some referrals involve voters who may not have knowingly attempted to vote twice — for example, elderly voters who submit an absentee ballot, forget having done so, and subsequently appear at the polls. [16]

Noncitizen voting presents a narrower question. We were unable to identify a case in Oklahoma resulting in a conviction for a noncitizen registering or casting a ballot. That finding does not establish that no noncitizen has ever registered or voted in Oklahoma. We found that the State Election Board identified three cases in 2024 involving individuals believed to be noncitizens on Oklahoma voter rolls and referred those cases for further investigation. During the same period, two individuals were excused from jury duty because they were identified as noncitizens; following established procedures, the State Election Board was notified and the cases were referred for review. [16]

Oklahoma also has mechanisms for identifying potentially ineligible registrations. The State Election Board can compare voter-registration information against federal data through the Systematic Alien Verification for Entitlements (SAVE) program, and Oklahoma law authorizes the Board to compare the voter list with databases maintained by federal, state, or local government entities containing citizenship information. A particular challenge with identifying noncitizen voters and prosecuting those cases is the fluidity of citizenship status. An individual can legally register to vote while a citizen and subsequently become ineligible to vote, meaning that identifying a person as a noncitizen at a later point does not necessarily establish that the individual registered or voted unlawfully. Additionally, records or verification systems may not always accurately reflect an individual's citizenship status, and some individuals may be able to provide documentation establishing their eligibility when contacted.

Recommendations

  1. Preserve a voter-verifiable paper record as Oklahoma modernizes its election equipment. Oklahoma's paper ballots provide an independent record of voter intent that can be audited even if electronic equipment fails or is compromised. Future modernization should preserve that independent physical record, along with Oklahoma's existing requirements for chain of custody, bipartisan election administration, and post-election auditing.

  2. Increase public transparency around cybersecurity standards where disclosure does not itself create a security risk. Oklahoma provides extensive public information about the security of its voting equipment, but substantially less information is available about the standards applied to election-administration networks, voter-registration systems, and voter-facing services. Providing additional information about applicable cybersecurity standards and safeguards could allow the public to better evaluate protections surrounding the ballot without disclosing operational details that could create new vulnerabilities.

  3. Strengthen authentication without making election systems unnecessarily difficult for eligible voters to use. Additional authentication protections should be considered for sensitive actions through voter-facing systems, particularly changes to voter-registration information or absentee-ballot requests. Any new requirement should also provide alternatives for eligible voters who lack reliable internet access, mobile devices, or other technology required by the primary authentication method.

Next
Next

Oklahoma Changes Ballot Petition Rules: What It Means for Voters (OETA)