
A software update meant to help pre-registered teenagers check their voter status instead threw open the confidential records of more than 133,000 Colorado voters for 11 days this month, state officials say. The Colorado Department of State says 59 of those voters had their profiles actually accessed before the error was caught on Aug. 25, and Secretary of State Jena Griswold has since apologized and taken responsibility for what happened.
According to Denver7, the exposure began Aug. 14, when an update to the state's Find My Voter Registration tool inadvertently made confidential voter profiles public. That update, according to the dossier's account of the state's reasoning, was performed to comply with a new Colorado law letting pre-registered 17-and-a-half-year-olds verify their registration status online. Normally, entering a legal name, full date of birth, and zip code should have blocked access to confidential voter records, but the flawed code let those searches through instead.
The breach came to light when a Secretary of State's Office employee, who is themselves a confidential voter, discovered on Aug. 25 that they could pull up their own protected profile using their name, birthdate, and zip code, Denver7 reports. Griswold has said the software update caused confidential voter profiles to become public, and that the issue was fixed within an hour of discovery once it was flagged.
What the Exposed Data Revealed
For any non-confidential voter, the tool displayed a full name, birth year, voter ID, registration status, party affiliation, and residential address, per the same account. Confidential voters are shielded from that kind of disclosure precisely because their addresses can be used to locate them.
Griswold has said the 59 affected voters likely accessed their own profiles themselves, a conclusion she based on conversations with those voters and on IP address data, according to Denver7's reporting. Her department has contacted 54 of the affected voters directly and mailed letters to the remaining five.
Why Confidential Status Matters So Much
Colorado's Address Confidentiality Program exists under Colorado Revised Statutes Title 24, Article 30 to give survivors of domestic violence, sexual assault, and stalking a substitute mailing address that shields their physical residence from government records, according to the Colorado Coalition Against Sexual Assault. Colorado House Bill 25-1195 later expanded those confidentiality protections beyond crime survivors to cover active and former law enforcement officers, firefighters, emergency medical service providers, and 911 dispatchers, per the Colorado General Assembly. Griswold has said confidential voters should not be able to look themselves up or have anyone else access their information at all.
The stakes of that failure prompted a swift response from prosecutors. The Office of the District Attorney for Colorado's Fourth Judicial District issued a media release warning that the online exposure created severe safety risks for vulnerable confidential voters, including law enforcement officers and abuse survivors, according to a statement posted to the Office of the District Attorney, Fourth Judicial District of Colorado. The Colorado Department of State has since asked the Colorado State Patrol and the Denver District Attorney's Office to conduct a joint risk evaluation for the 59 voters whose records were accessed during the breach.
A Second Website Failure in Two Years
This is not the first time the Secretary of State's website has exposed sensitive information. Denver7 notes that a previous technology error occurred two years ago, when an uploaded spreadsheet on the office's website exposed partial passwords to election systems across dozens of counties. Rocky Mountain Voice reports that the incident, in June 2024, exposed voting equipment passwords in 34 of Colorado's 64 counties for over four months before it was removed on Oct. 24, 2024.
A third-party investigation conducted after that 2024 password breach found that the Secretary of State's Office lacked pre-publication document review protocols, and it recommended mandatory multi-step quality checks, according to Colorado Politics. The office says it is now putting additional safeguards in place, including automated quality assurance and an added check after coders update infrastructure, though the latest breach suggests those earlier recommendations weren't fully in force by this August.
Political Stakes Rise During AG Campaign
Griswold has said that responsibility for publishing the flawed update is an HR matter that will be handled under the law, even as she has personally apologized for the error and accepted responsibility for it. The timing adds political weight: Griswold is currently competing in the 2026 Democratic primary for Colorado Attorney General, and her record on election administration and web data security has become a central campaign topic, as Hoodline has previously reported.
The breach also arrives weeks after a separate legal win for Griswold's office, when a federal judge dismissed with prejudice a Department of Justice lawsuit that had sought unredacted Colorado voter rolls containing protected personal fields. This latest lapse, however, gives critics fresh ammunition regardless of that earlier court victory, and it lands amid a broader statewide conversation over ballot security, including a mail-ballot voter ID measure that recently qualified for the November ballot.









