Mojave Research said a federal review of Dominion voting systems used in Puerto Rico’s 2024 elections uncovered at least a dozen high- or critical-severity weaknesses, including vulnerable commercial software, weak passwords, embedded credentials, disabled firewalls, open ports, poor cryptography, and active cellular modems that widened potential access paths. The firm said it successfully exploited five known vulnerabilities and described the examined environment as "deeply insecure," but reported no evidence that the flaws had been used in an intrusion or that votes were altered.
The work was conducted for the Office of the Director of National Intelligence and ended abruptly after a stop-work order and political friction, according to Mojave executives, who said the findings drew pushback because they did not support claims of election manipulation. Mojave said it produced an approximately 100-page preliminary report, sought additional time to determine whether any weaknesses had ever been abused, and has urged that the report be made public. Liberty Vote, which acquired Dominion’s election business, said it had not received the report and did not plan changes before November.

Map this exposure pattern across your cloud, code, and identities.
11 events from the most recent confirmed update back to the earliest known activity.
Reuters was cited as reporting that in May 2025, ODNI and the FBI investigated allegations that Venezuela hacked Puerto Rico's voting systems. The probe reportedly produced no clear evidence of Venezuelan interference.
The references state that the Dominion voting systems Mojave later analyzed were used in Puerto Rico's 2024 elections.
Wareham said Mojave had spent roughly a year pushing for its report to be made public and had recently been told it might soon emerge through a FOIA request.
Mojave publicly presented its Puerto Rico voting-system findings at DEF CON's Voting Village in Las Vegas.
Wareham said an ODNI official told him Mojave had been accused of receiving George Soros funding and that the accusation came from Kurt Olsen. The references also say Olsen pressed to broaden the work to find election-rigging evidence and later advocated terminating it after Mojave found no hack evidence.
ODNI said Mojave's contract ended because the company had completed its voting-machine analysis, offering an official explanation for the end of the work.
Wareham and Gulati said Mojave received a stop-work order and no additional funding on the day it expected the expanded contract to proceed during the government shutdown. They said the follow-on effort was abruptly shut down before it began.
Mojave produced an approximately 100-page preliminary document on its findings and sought additional months of work to investigate whether the weaknesses had ever been abused and to help remediate issues before the midterms. Company executives said federal officials initially supported expanding the effort and authorized follow-on work.
Jason Wareham said Mojave briefed the White House on some of its Puerto Rico voting-system findings around September.
During its review, Mojave identified at least 12 major or high- to critical-severity vulnerabilities, weak and embedded passwords, disabled firewalls, open ports, poor cryptography, and active cellular modems, and successfully exploited five known flaws. The firm said it found no evidence the weaknesses had been exploited and no evidence votes were altered.
Mojave conducted a roughly six-week security review for ODNI of one voting system from one manufacturer in one Puerto Rico jurisdiction. The work began after ODNI asked the company to travel to Puerto Rico and capture an image of a system used in an election.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.