
By Shaina Cole | Contributing Writer, Rocky Mountain Voice
For 11 days in August, the profiles of Colorado voters who had specifically asked the state to keep their information hidden were searchable by anyone who knew where to look and had the information the tool required.
These are people the state allows to shield their records because they said public disclosure could expose them or a household member to criminal harassment or bodily harm.
On August 14, an update to the Secretary of State’s “find my voter registration” tool removed the setting that kept their records out of public view. The office didn’t notice until the late afternoon of August 25.
Fifty-nine of those profiles were pulled up before anyone caught the mistake.
What broke
The change was supposed to be routine. New state law requires Colorado to let pre-registered voters who are at least 17 years and six months old check their own registration online. To make that work, department staff updated the public lookup tool.
In doing so, according to the department’s statement, an existing limit preventing access to confidential voters’ profiles “was inadvertently overridden.”
For 11 days, a confidential voter’s record returned the same way anyone else’s would.
The office says it discovered the problem in the late afternoon of August 25, reversed the update, and went back through the logs to identify whose records had been searched.
The review turned up 59 profiles. It emailed or called the 54 voters it had contact information for and mailed letters to the remaining five.
As of August 26, Colorado had 133,449 active confidential voters. The department notes the 59 accessed profiles amount to .04% of that total.
“The majority, but not all”
Here is where the state’s account asks for some trust.
Griswold told FOX31 that the office believes most of the 59 searches were confidential voters looking up their own records. “The majority of voters said they had initiated the changes. We believe that the majority, but not all, did initiate those changes from the conversation with voters,” she said.
The majority. Not all. That leaves an unstated number of searches the office has not attributed to the confidential voters themselves. The department has not said how many, who, or why.
By the office’s own description, running a search is not difficult. It takes a voter’s legal first and last name, their zip code, and their complete date of birth. A returned profile displays the voter’s full name, birth year, voter ID, county registration date, registration status, party affiliation, date of affiliation, and residential address.
For a population that includes people who asked the state to withhold their address, that final field is the one that carries the risk.
Griswold acknowledged the office runs a quality-assurance process, but said the change was not caught in a third review before it went live.
A pattern of failures
This is at least the third time in Griswold’s tenure that avoidable mistakes inside the Secretary of State’s office have exposed sensitive information or sent election material to the wrong people. Each was attributed to a staff-level or technical error, and all three occurred during election years.
In 2024, department staff posted a spreadsheet to the Secretary of State’s website with a hidden tab containing partial BIOS passwords, the credentials that access a system’s basic functions, for voting equipment components.
By the office’s account, equipment in 34 of the state’s 64 counties was affected.
The spreadsheet went up June 21, 2024, four days before the state’s June 25 primary, and stayed online until it was taken down October 24, more than four months later.
The office did not find it on its own. As the department’s own update states, it “was informed of the data disclosure by a voting machines vendor.” Many county clerks, the same release notes, had already learned of the exposure from a press release issued by the Colorado Republican Party.
Griswold said the staff member who created the spreadsheet had left the department “amicably” before the leak came to light.
Gov. Jared Polis deployed state cybersecurity personnel to help reset the passwords, which the office completed by October 31. The department later engaged an outside law firm to investigate. The firm found the passwords were posted unintentionally but faulted the office for failing to review the document before it went public.
Two years earlier, weeks ahead of ballots going out for the 2022 election, the office mailed postcards to roughly 30,000 noncitizens, urging them to register to vote. It blamed a formatting error that failed to flag noncitizen driver’s-license holders as ineligible.
In a statement to Colorado Public Radio, which first reported the error, the office said “approximately 30,000 EBU [Eligible But Unregistered] postcard mailers were incorrectly sent to ineligible Coloradans.” The postcards were not ballots and not registration forms, and the office said the state’s system would block any noncitizen who tried to register.
What Griswold says now
“My office takes the confidentiality of each and every voter’s data extremely seriously,” Griswold said in the August 27 statement. “I sincerely regret that this happened. My staff identified this issue, and we immediately fixed it and are continuing outreach to affected voters.”
Griswold is term-limited as Secretary of State and is the Democratic nominee for Colorado attorney general in November, the office that enforces the state’s data-protection and privacy laws.
The department says it is adding new automated and manual testing so confidential voter information will not be visible this way again. After the 2024 password leak, the office likewise said it was dedicated to ensuring mistakes of that nature never happen again.