Georgia CVR Files Expose Ballot Order

Bruce Schneier showed that Georgia’s May 2026 primary could still be analyzed for ballot order nearly four years after the vulnerability was disclosed, using an AI agent plus public early-voting lists and cast-vote record (CVR) files from one of the 21 states with affected scanners. He never touched a voting machine, a network, or anything non-public. The method is correlation, not intrusion: line up county early-voting lists with the ballot-by-ballot CVR file, then use the order ballots were cast to match records back to likely voters or time slots. Because the CVR file preserves each ballot’s selections without names, the privacy assumption is that the record is anonymous; the attack shows other public data can undo that. For election offices and vendors that publish CVRs or similar ballot-level records, the exposure sits in the publication model itself. If those records can be linked to timing lists, they can reveal voter behavior and when people voted, even when the voting equipment was never compromised.

Part of the PlainSec briefing for 2026-09-04

Every edition of this story: Georgia CVR Files Expose Ballot Order

Sources