California Democrats Becerra and Padilla identified 2016 election issues, then ignored and hid evidence that issues were addressed.
Attorney General Todd Blanche is carrying the fight for California’s statewide voter-registration records into 2026. Xavier Becerra’s signed 2018 warning places the gubernatorial candidate inside California’s unanswered election-security timeline.
By Christine Bish | A continuation of my three-part investigation of U.S. Senator Alex Padilla, California’s former secretary of state
Washington just blew open the election-security file.
The White House released declassified intelligence and government reports covering vulnerable voting systems, China’s acquisition of American voter data, voter-registration investigations and noncitizens on state voter rolls. The files identify centralized repositories—voter-registration databases, pollbooks and official election websites—as the systems most vulnerable to exploitation.
In its latest addition, the White House Transparency Task Force released a March 2020 email alleging that a senior National Security Agency official resisted sharing election intelligence involving 2016 and 2020 because disclosure could invite accusations of politicization and brand the NSA part of the “deep state.”
At the same time, Attorney General Todd Blanche is carrying forward the Justice Department’s fight for unredacted statewide voter-registration records, including California’s. DOJ sought the full electronic list—including names, birth dates, residential addresses and state driver’s-license numbers or the last four digits of Social Security numbers—to test California’s compliance with federal voter-list maintenance laws. California refused, and DOJ sued. A federal judge dismissed the California case in January 2026. DOJ appealed to the Ninth Circuit, and Blanche now says Supreme Court review remains a possibility in the broader voter-roll fight. The national question is no longer whether the warnings existed. They did. The question is who knew, who acted—and why the complete public record is still missing.
California’s answer begins with a signature.
On July 23, 2018, Xavier Becerra—then California’s attorney general—joined 20 other state attorneys general in warning Congress that hackers had targeted state and local election boards, invaded a state election website, stolen the personal information of approximately 500,000 voters and infiltrated a company that supplied voting software. The letter described “technologically vulnerable election infrastructures” and demanded comprehensive security risk assessments.
Becerra signed it.
Signatures are stubborn things. They tend to outlive campaign talking points.
By then, California had already documented an attack in the same threat family: abuse of a state election website using voters’ identifying information.
The White House election-integrity release includes a federal report that places Riverside County in its history of voter-registration-system breaches. The report says a bad actor used California’s voter-registration website and voters’ personal identifying information to change their party affiliations without their knowledge or consent.
That is the break: the new federal file places Riverside in the history of voter-registration-system breaches; Xavier Becerra’s signature proves he personally acknowledged the same threat categories; Alex Padilla’s record shows what California did next; and Sacramento shows what remained unfinished as 2020 arrived. California’s record tracks several of those warnings: an abused state registration portal in Riverside, contractor-built statewide infrastructure in VoteCal, administrative change orders and delayed security assessments.
THE SIGNED LETTER
The letter is four pages: two text pages and two additional signature pages. The two text pages—including the page bearing Xavier Becerra’s signature—appear below. The complete four-page original is linked in the source list.
PAGE ONE
Page one of the July 23, 2018 election-security letter.
PAGE TWO — XAVIER BECERRA’S SIGNATURE
Page two of the July 23, 2018 election-security letter, with Xavier Becerra’s signature highlighted.
The red box and arrow identify Xavier Becerra’s signature. The underlying letter is unchanged.
Source: California Department of Justice, Election Security Letter, July 23, 2018.
Riverside ended at Padilla’s office
During California’s June 7, 2016, presidential primary, voters in Riverside County discovered that their party affiliations had been changed through the state’s online registration portal. Riverside District Attorney Michael Hestrin said 20 formal complaints were filed and believed more voters were affected.
Investigators could not identify the actor because the state did not collect the visitors’ IP addresses. KQED reported that the investigation ended at the office of then–California Secretary of State Alex Padilla.
California did not pause the statewide rollout. On September 26, 2016—111 days after the primary—Padilla certified VoteCal as California’s official voter-registration system and connected all 58 counties to it. Padilla announced that VoteCal had passed security audits, accuracy testing and simulated-election performance review.
Then produce those audits.
Produce the exceptions. Produce the failed tests. Produce the remediation records. Produce the portal and transaction logs that investigators needed and California did not retain.
Padilla’s office denied evidence of a breach of the voter-registration database. That defense answers a narrower question than Hestrin raised. His investigation found that someone used the state’s legitimate online workflow and voters’ identity information to change official party affiliations. Whether the database itself was penetrated or the public portal was abused, official records were changed and the state lacked the IP logs needed to identify who did it.
Change Request #14
An official VoteCal specification reveals another decision the public has never received a full explanation for.
The document’s revision history states that on May 15, 2015, the project “removed voter activity from the synch check process as per Change Request #14.” The underlying change request is not included. The public document does not identify the complete effect of the change or explain who authorized it. Later sections still identify voter registration, voter participation history and images as synchronization categories.
That does not make Change Request #14 disappear. It makes the missing document more important.
The same final specification says county service-account passwords were initially set not to expire. It permitted the project team to conditionally accept the specification with outstanding deficiencies it considered non-material. The public approval page names the VoteCal project sponsor but displays a blank signature line.
The Legislature did not vote on Change Request #14. It did not vote to use non-expiring service-account passwords. It did not decide which deficiencies were “non-material.” Those were administrative and project decisions handled within Padilla’s department and its contractor structure.
The Motor Voter rush
The Legislature passed AB 1461 and authorized Motor Voter. It did not order then–Secretary of State Alex Padilla, the DMV and the Brown administration to launch it in April 2018 before the June primary.
County election officials said they warned Padilla personally that the system was not ready. Los Angeles County Registrar Dean Logan said he raised the concern directly with Padilla. California moved forward anyway.
A Los Angeles Times investigation based on approximately 1,300 pages of state records found that:
- Six days before launch, state security officials saw the DMV network attempting to connect to servers in Croatia.
- A senior programmer warned of a possible “international incident and major security and launch failures.”
- Three months of testing had been compressed into six weeks.
- Design and testing were occurring at the same time.
- Personal information sometimes remained visible on DMV touchscreens between customers.
Then the errors hit the voter file.
An official Los Angeles County report summarized letters sent by the DMV and California Department of Technology to Padilla’s office. Approximately 23,000 customers may have had records mixed together, transmitting incorrect political-party, language and vote-by-mail preferences. Approximately 1,500 additional customers may have been registered in error. Some people who chose to opt out still had their information sent to the Secretary of State.
Padilla called the failures “completely unacceptable.” Yet the transfers continued.
That was an administrative decision, not a vote of the Legislature.
Xavier Becerra’s escape route ends with his signature
Xavier Becerra was serving as a member of the U.S. House of Representatives during the Riverside incident and Secretary of State Alex Padilla’s 2016 VoteCal certification. Becerra became California attorney general in January 2017.
That is where his escape route ends.
In July 2018, as California attorney general, Becerra signed a warning identifying stolen voter data, penetrated state election websites and compromised software suppliers as direct threats to election integrity. In November 2019, the DMV notified approximately 3,200 Californians that seven outside government entities had improperly accessed information about whether a license holder had a Social Security number or verified Social Security card over four years.
California Civil Code §1798.29 requires a state agency that must notify more than 500 California residents because of a single breach to submit a sample notice electronically to the Attorney General.
DMV described one four-year access-control failure and mailed notices to approximately 3,200 people. If DMV treated that failure as the single breach described in its public notice, Becerra’s Department of Justice should have received the sample. The public file should show whether it did.
As of August 19, 2026, a search of DOJ’s public breach-notice database under the agency’s name did not reveal a 2019 DMV entry. That search result does not prove that no notice was submitted. It is a reason to demand the receipt, review record and investigative file. When did DOJ receive the notice? Who reviewed it? Was the improper access compared with the identity information used to manipulate voter records in Riverside? Was Padilla’s office contacted?
Those are no longer speculative political questions. They are document questions created by Becerra’s signature and California’s own notice statute.
Sacramento was the warning made local
My three-part series documented how then–Secretary of State Alex Padilla’s pre-COVID architecture landed in Sacramento County: VoteCal, Motor Voter, the Voter’s Choice Act, centralized mail voting, outside vendors, private election grants and an oversight system that was still unfinished.
The State Auditor warned Padilla’s office in October 2017 that it was conducting insufficient monitoring of county election practices. The Secretary of State’s chief counsel acknowledged that the office did not monitor county election materials for compliance and relied on the public to report criminal violations.
The Auditor recommended annual risk-based county reviews beginning in December 2018. Padilla’s office still described those reviews as something it was “exploring” in October 2020. The recommendation remained pending under his successor in September 2023, when the office listed a 2024 target.
Then came the Sacramento County Grand Jury.
Its 2019–2020 report found that the county Department of Technology was not regularly performing vulnerability scans and penetration tests. The Grand Jury could not determine when the last external election-system audit had occurred or who had conducted the penetration testing. Multi-factor authentication was still being rolled out. A Department of Homeland Security assessment was still on the roadmap.
After the election, Sacramento Registrar Courtney Bailey-Kanelos acknowledged that USB drives “should not have been left out” during a December 15 tour and said procedures were changed to secure them immediately after use. She disputed that the voting system had been connected to the internet and said a VoIP phone photographed in the room had been used only for a post-election safety test.
Her denials do not erase the admission: the USB drives were left outside their designated storage procedure, and the procedure changed only after the condition was documented.
They knew how to investigate—when they wanted to
California’s Constitution made then–Attorney General Xavier Becerra the chief law officer of the state. It gave him supervisory authority over district attorneys and the power to require reports concerning criminal investigations. Then–Secretary of State Alex Padilla had authority to examine election records and vote-counting programs and to refer violations to a district attorney or the Attorney General.
They knew how to use that power.
In October 2020, then–Attorney General Xavier Becerra and then–Secretary of State Alex Padilla announced a joint election-integrity investigation into unofficial Republican ballot boxes. Becerra said DOJ was monitoring election-related activity statewide and issuing subpoenas.
I found no comparable public investigative file for Riverside, VoteCal’s Change Request #14, the Motor Voter security warnings, the DMV breach notice or Sacramento’s unfinished security assessments. If one exists, California can produce it.
California has never suffered from a shortage of press releases. The investigative file is another matter.
That is the scandal.
Padilla’s office knew the operational failures. Becerra signed the warning and headed the department positioned to investigate them. Sacramento entered the 2020 election with several recommended reviews and security measures unfinished.
The Legislature authorized the voter-registration programs. That does not answer for rushed implementation, compressed testing, missing transaction logs, unexplained change requests or assurances offered without the underlying audit trail.
Becerra signed the warning. Padilla certified and expanded the system. Now they should be required to produce every record showing what they knew, when they knew it and what they did about it.
Now they want the public to move on
This is not history. It is the 2026 race for governor.
Xavier Becerra, who served in Congress during the Riverside episode and later served as California attorney general, is now a Democratic candidate for governor in California’s November 2026 general election. His campaign prominently emphasizes fighting the Trump administration. On July 16, 2026, he declared that California’s elections are “safe, secure, and accurate” and promised that, as governor, he would use “every tool at its disposal” to resist the President and protect the state’s election system.
That declaration collides with Becerra’s own signature.
The man now asking Californians to trust him with the governor’s office personally signed a warning about penetrated state election websites, stolen voter information, compromised software suppliers and technologically vulnerable election infrastructure. His own state had already experienced the Riverside abuse of its registration portal. His own Department of Justice was positioned to receive California’s DMV breach notice. His office had the power to demand investigative reports and pursue election violations.
Where is that file?
U.S. Senator Alex Padilla—California’s secretary of state from 2015 to 2021—is now the ranking Democrat on the Senate committee overseeing federal elections. He has opposed the Trump administration’s citizenship-verification order, federal access to state voter-registration data, voter-roll reviews and restrictions on vote-by-mail. He introduced legislation to repeal the executive order and block federal access to state voter records. He condemned the Justice Department’s attempts to obtain voter lists.
The direction of the demand matters. Attorney General Todd Blanche’s Justice Department is demanding California’s voter-registration records. California is refusing to produce them. Padilla is using his Senate post to defend that resistance.
Apparently, transparency depends on which direction the records are traveling.
Read that again.
Washington is demanding California’s statewide voter-registration records while the California public is still waiting for records from Padilla’s own system:
- Change Request #14.
- The security audits Padilla invoked when he certified VoteCal.
- The exceptions, failed tests and remediation records behind that certification.
- The portal and transaction logs Riverside investigators needed and California did not retain.
- The full record of the Motor Voter launch warnings and the decision to keep the pipeline running.
- The investigative file—if one exists—connecting Riverside, the DMV failures and Sacramento’s unfinished safeguards.
Gubernatorial candidate Xavier Becerra says California’s elections are secure. U.S. Senator Alex Padilla says federal scrutiny is an attempted takeover. Both have opposed central pieces of the administration’s election agenda. Neither has produced the complete California record that would allow the public to judge the system Padilla administered and Becerra later defended.
That is not oversight. It is containment.
They investigated Republican ballot boxes. They issued subpoenas when the target was outside their own administration. On Riverside, VoteCal, Motor Voter, the DMV and Sacramento, the public file remains fragments, assurances and missing documents.
Xavier Becerra is now asking Californians to elect him governor. Alex Padilla is using his U.S. Senate post to oppose the federal response. Before Californians decide whether to put Becerra in the governor’s office—or accept Padilla’s use of Senate authority to resist federal review—both should produce the California record beneath their “safe and secure” declarations.
Then–Attorney General Xavier Becerra signed the warning. Then–Secretary of State Alex Padilla expanded the system after the warning signs were already visible. Sacramento entered the 2020 election with several recommended reviews and security measures unfinished. Now both are opposing central parts of the federal election agenda while the evidence trail from their own tenure remains incomplete.
This record does not prove that California vote totals were altered. It proves documented notice, administrative expansion, delayed oversight and missing accountability records. That is enough to demand the file. Release the California file.
Continue the investigation
Part I — The 2020 Election Steal Was Built Before COVID.
Part II — The 2020 Election Steal Was Built Before COVID.
Part III — The 2020 Election Steal Was Built Before COVID.
Core documents
White House election-integrity release.
White House summary of the July 2026 declassified election-security release.
Newly released March 2020 NSA election-threat email.
Catherine Herridge report on the newly declassified NSA record.
Todd Blanche says the voter-roll dispute may reach the Supreme Court.
Justice Department lawsuit demanding California’s statewide voter-registration list.
United States v. Weber complaint detailing the records demanded from California.
Becerra’s signed July 23, 2018 letter.
Riverside investigation and Padilla connection.
Padilla’s VoteCal certification.
VoteCal specification recording Change Request #14.
Official Los Angeles County Motor Voter error report.
Motor Voter launch investigation.
California State Auditor findings.
State Auditor follow-up record.
Sacramento County Grand Jury election-security report.
Courtney Bailey-Kanelos response.
California Constitution, Article V, §13.
Becerra–Padilla 2020 election-integrity investigation.
California’s official June 2026 primary Statement of Vote.
Becerra’s July 16, 2026 election statement.
U.S. Senator Alex Padilla’s official biography.
Padilla’s bill to repeal the election executive order and block access to state voter data.
Padilla’s opposition to DOJ access to state voter-registration lists.
DMV’s 2019 notice to approximately 3,200 customers.
California DOJ breach-notice database.
Official biography of Attorney General Todd Blanche.
Justice Department opening brief in the California voter-records appeal



