Electoral Integrity Master Dossier · T71 · 2026 to 2028
UNCLASSIFIED // OPEN SOURCE // DEFENSIVE
Master dossier · one file · five decks

Electoral Integrity // Assessment, Engine, Corpus

The finished estimate, the coordination engine, the post-level authorship pipeline, the model backtest, and the doctrine annex, in a single page with the computed data embedded. No setup. Use the tabs.

Download the comprehensive compendium · Managed Erosion (PDF)Comprehensive report hosted at treadstone71.com
00 How to read this dossier

Scores, bands, and what they mean

Stress scores, 0 to 6

Each indicator is scored for observed intensity of a concerning condition. Higher is more adverse. A low score can mean the condition is genuinely low or that it is thinly measured, so coverage is tracked as a separate flag. The presence of a capability is never scored as persuasion.

The index, 0 to 100

The Electoral Integrity Threat Index is a weighted composite of five components, shown with its parts on the Index panel. It is a decision aid, not a measurement, and the weights are meant to be argued with.

Likelihood bands

Estimates use half-open probability bands: almost certain 95 to 99, very likely 80 to 95, likely 55 to 80, roughly even 45 to 55, unlikely 20 to 45, very unlikely 5 to 20, remote 1 to 5.

Confidence and sourcing

Analytic confidence, low, moderate, or high, is reported separately from likelihood and reflects evidence depth and source agreement. Sources are graded on reliability A to F and credibility 1 to 6, never averaged. Verified fact and adversary claim stay in separate sentences.

The scoring instrument and the collection tradecraft behind these read-outs are house-proprietary and are not detailed here. What is published is the result and its meaning, at a tearline depth.

01 Bottom line up front

Mechanically sound, politically contested

The system that certifies U.S. elections is intact. The system that legitimizes them is under sustained strain. The dominant new variable for 2026 is the disposition of state force around civic life, set against a defensive posture cut at the moment of need.

One-sentence judgment. It is likely (55 to 80%) that 2026 produces localized intimidation, at least one AI deception referencing voting, and one or more certification disputes, while a systemic breach of the count remains unlikely (20 to 45%). Confidence moderate, bounded by four structural gaps.

Fact and adversary claim kept in separate sentences. Presence of a capability is never scored as persuasion.

02 Composite index

Electoral Integrity Threat Index

0
index

A construct, not a measurement, published with its parts. Foreign election-nexus, relative U.S.-surface estimate: .

ComponentWtScore0-100 anchor

How to read: the ring fills to the composite score, higher is more adverse. The rows above are the weighted components and the line is the arithmetic that produces the index.

STEMPLES stress by dimension

How to read: each spoke is a STEMPLES Plus dimension scored 0 to 6 for observed stress. Security reads highest because the defensive collapse is the best-evidenced condition. A short spoke can mean low stress or thin coverage, so gaps are tracked separately.

Collection maturation, six rounds

How to read: across six collection rounds the stress index and the count of measured indicators rose while open gaps fell. The lines show the estimate getting better sourced, not the threat growing.
03 Key judgments

Likelihood and confidence, kept separate

04 Threat system

Ten vectors, graded

Vector risk matrix · likelihood by impact

Upper right is priority. State force and certification carry the highest impact; the defensive collapse is realized at high impact.
05 Folded strands

Satellite, alt-right, and PIR-9

Satellite / GNSS

No documented GNSS manipulation of a U.S. election system (gap). Starlink is poll-book connectivity, not tabulation. 2020 flip claims assessed false, held as pre-bunk. Recurrence very likely (80-95%); an actual GNSS event very unlikely (5-20%).

Alt-right ecosystem

America First and Groyper network as an online influence vector distinct from physical presence. Electoral-denial amplification and harassment of officials documented. Foreign-nexus link is a gap.

PIR-9 state-actor

Executive-branch actions consolidated: counter-influence capacity, threat prosecution, federal-force near sites, voter-data and citizenship policy, pressure on officials and vendors. Discrete actions, not a single master plan.

06 Competing hypotheses

Directed op, convergence, or domestic dynamic

EvidenceH1 Directed foreignH2 ConvergenceH3 Domestic + state
Verbatim foreign-to-U.S. reposting+ ++0
Only paid Tenet link proven– –++
No shared cross-network infrastructure– –+ +0
Measured vote effect null0+
Defensive collapse is domestic policy0++ +
State-force deployments domestic, public++ +
VerdictRejectedMost consistentStrongly supported

H1 rejected: no shared infrastructure, one proven control link, null measured effect. Weight on independent convergence plus domestic and state-driven dynamics. Confidence moderate.

07 Estimates, predictions, and emergence

How the risk emerges, and what we estimate

The systemic risk here is emergent. No single actor produces it. It arises from five components that interact and reinforce each other, and it is the interaction, not any one part, that sets the level.

The emergence mechanism

Five components

Cheap AI synthetic capability. A hollowed federal defense. A laundering seam that converts foreign or fringe content into domestic-seeming speech. The disposition of state force around civic sites. A depressed, partisan-asymmetric trust baseline.

Three feedback loops

Trust erosion drives certification friction, which drives further trust erosion. Defensive cuts lower detection, which raises perceived impunity, which invites more activity. Laundering builds domestic ownership, which frustrates attribution, which invites more laundering.

Tipping conditions

The system moves from managed erosion toward contested certification when a decisive-county refusal, a tally-moment deepfake, or federal force at a site couples with the low trust baseline. These are the tripwires modeled on the Foresight tab.

Consolidated estimate

It is likely (55 to 80%) that 2026 produces localized intimidation, at least one AI deception referencing voting, and one or more certification disputes. A systemic breach of the count is unlikely (20 to 45%). Trust stays depressed, very likely (80 to 95%). Confidence moderate across the set, bounded by four structural gaps that open collection cannot close.

Predictions and accountability

The estimate is committed to six dated, falsifiable predictions on the Forecast Tracker, each with a resolution date and a Brier scoring plan. The intent is a scored track record, so the assessment can be graded rather than merely believed.

Assumptions, and what would break the theory

The emergence theory assumes the paper-and-audit backstop holds, that courts keep treating certification as a ministerial duty, and that no foreign actor gains witting control of a large organic domestic channel. It would be falsified by a disclosed outcome-altering intrusion of the count, by courts permitting discretionary certification refusal, or by proof of foreign direction of a major organic amplifier. Any one of those forces a rewrite, not a patch. Confidence in the emergence model is moderate.

08 Strategic foresight

Computed cone, fire a tripwire

Posterior is proportional to prior times a per-scenario likelihood ratio, then normalized. Toggle tripwires to update the weights live.

How to read: bars are the current scenario weights. Firing a tripwire multiplies the prior by a per-scenario likelihood ratio and renormalizes, so one switch moves all four weights; the arithmetic prints below the bars.

09 Calibrated forecast tracker

Falsifiable, dated, scored

n/a
Running Brier
0
Resolved / total
0.25
Coin-flip baseline
IDForecastpResolvesOutcomeSet
10 Recommendations and opportunities

What to do, and where the edge is

Defensive, non-operational, and prioritized. Recommendations are ordered by marginal value for a state or county principal. Opportunities are strong points where the defender is already ahead or the adversary is weak.

Recommendations

PriorityActionOwnerTrigger
1Put the marginal security dollar on tabulation and canvass venue integrity, not broad content takedownSoS / county registrarBefore ballots print
2Stand up a first-seen-origin watch on the captured channels; measure who posts first, not who posts loudestAnalyst cellNow
3Pre-position sourced rebuttals for the recurring machine-flip and satellite-flip narratives; publish on first sighting, not after spreadCommsPre-election
4Backfill lost federal monitoring through a state information-sharing memorandum or a paid equivalent serviceStateThis quarter
5Pre-brief counsel to enforce the ministerial certification duty at known chokepoint boardsLegalPre-certification
6Activate an officials-protection protocol for the documented harassment surgeSecurityNow

Opportunities

Lead with the defended count

The paper and audit backstop is broad and the count is mechanically sound. Saying so plainly and early is the strongest single move against delegitimization.

Deny oxygen, not just content

The adversary model ranks patience above fabrication. The strongest defense is starving real domestic friction of the amplification the operator is counting on.

Own the tally moment

Detectors are weak in the wild, but provenance signaling plus a fast human correction still works at the one moment a deepfake would matter most.

Unlock the private corpus

A post-level export of the captured channels turns the wired authorship and origin-timing pipeline into a product no one else can produce.

Lean on the courts

Every reviewed case holds certification ministerial. That is a reliable legal backstop to pre-position around, not a hope.

Coalition backfill

State memoranda can replace much of the lost federal sharing at modest cost, and the window to sign them is open now.

11 The decision this changes

One customer, one date, one flip

01 Amplification graph

Built from real observed edges

0
Channels
0
Forward edges to hub
0
Shared-template edges
0
Coordination clusters

How to read: node size grows with connections and color marks the movement cluster. Orange lines are observed forwards from the source hub. Teal lines mark channels that share an identical automated preview string. Hover any node for detail.

First-seen-origin, honest bound.
02 Cadence and synchrony

Shared-template co-activity

03 Stylometry harness

Method wired, sample flagged

The real authorship run lives on the Corpus tab. This harness shows the method on the list-capture previews, which are below the reliable floor.

04 Adversary decision model

What a rational operator does

Transparent expected utility: EV = p_success x damage minus attribution_risk x penalty minus cost, plus a small reach term. A model, not a claim about intent.

#Optionp_succdamageattribcostEV
05 Red-team pass

Every judgment challenged

JudgmentDevil's-advocate challengeSurvives?
00 Real data · ingested channels

Four real channels, the origin chain, and a cross-channel matrix

The chain, measured end to end

The typology finding

Cross-channel authorship matrix

Fingerprint store

01 Authorship overlap

Function-word matrix and clusters

Burrows Delta over a 120-word function-word list, reposts stripped before attribution. Lower Delta means closer authorship. Cluster count chosen at the largest gap in merge distances.

How to read: each cell is the stylistic distance between two channels, darker teal meaning closer authorship. Colored dots group the channels the method judges to share an author, which is distinct from sharing content.

Sample adequacy gate

02 First-seen origin timing

The laundering trace

Origination profile

Cross-channel content units

03 Cadence cross-correlation

Coupled posting rhythm

Channel AChannel BPearson r
04 Run on real data

Export to findings in one command

In Telegram Desktop, export each channel as JSON. Lay them out one folder per channel:

corpus/
  Patriot Front/result.json
  Patriot Front Sightings/result.json
  Qanon Q17/result.json
  ...

Then run INSURRECT_CORPUS=corpus python3 insurrect_corpus.py. The same code produces a real authorship matrix, real origin timing, and real cadence over the captured channels. The synthetic banner disappears when real text is present.

01 Model validation

Backtest against 2020, 2022, and 2024

The scenario model was run backward on three real cycles. For each, the documented record set which tripwires fired; the model produced a posterior; the top scenario was compared to what actually happened; and the set was scored.

1 / 3
Hits, original tuning
3 / 3
Hits, recalibrated
0.52 to 0.37
Brier, before to after
0.75
Coin-flip baseline

What the backtest actually found

One win, one honest failure, one fix. The model correctly kept Infrastructure Shock near zero in all three cycles, which matches the record: no disclosed outcome-altering breach ever occurred, and the 2016 Illinois registration compromise remains the reference case for a disclosed successful intrusion. The model also correctly flagged 2020 as the highest Contested-Certification cycle.

The failure: as originally tuned, the certification-refusal tripwire is too strong. It pushed Contested Certification to about 50 percent in 2020 and 2022, when the count actually held and the realized outcome was Managed Erosion. Original argmax hit rate was 1 of 3.

The fix emerges from the data, not from taste: cutting the certification-refusal likelihood ratio from 3.0 to 1.8, and adding a severity gate that separates a resolved county refusal from a systemic scheme, makes the model call all three cycles correctly while keeping Contested Certification appropriately elevated in 2020. That is the difference between a number and a track record.

02 Cycle by cycle

Posterior, model call, and what happened

CycleTripwires firedPosterior (ME / CC / RH / IS)Model callActualResult

ME Managed Erosion, CC Contested Certification, RH Resilient Hold, IS Infrastructure Shock. Actual outcome for every cycle was Managed Erosion, since every count held and was certified. 2020 came closest to Contested Certification through the fake-elector scheme and January 6, but the certification completed.

03 Recalibration

The correction the record forces

Same three cycles, same fired tripwires, certification-refusal likelihood ratio reduced from 3.0 to 1.8. The model now calls all three as Managed Erosion, with Contested Certification held as the elevated second scenario in 2020 and 2022.

CycleRecalibrated posterior (ME / CC / RH / IS)Model callActual

Both versions beat the coin-flip baseline of 0.75. Mean Brier improves from 0.52 to 0.37 after recalibration. The lesson is specific and carried forward: certification drama that gets resolved by courts is weak evidence for a genuine certification crisis, and the model now treats it that way.

04 Tripwire scoring

Which fired, which did not, and why

Tripwire202020222024Basis, paraphrased from the record
Armed force at pollsnononoState National Guard was activated in support and cyber roles in 2020 and 2024, but per every responding state not stationed at polling places. Texas expressly ruled out any polling-place role in 2020.
Viral deepfake at the tallynonoyesThe January 2024 New Hampshire AI robocall imitating President Biden, plus federally attributed Russian fabricated videos in late October and early November 2024. Nothing comparable in 2020 or 2022; consumer generative AI arrived only in late 2022.
Certification refusal at the generalyesyesno2020 fake-elector slates and the Wayne County board reversal; 2022 the Cochise County refusal, certified under court order. In 2024 the refusal risk sat in the primaries and pre-election rule fights, and the general-election certification was clean.
Swing-state intrusion disclosednononoNo disclosed successful, outcome-relevant intrusion in any of the three cycles. Federal officials stated repeatedly that no votes were changed. The 2016 Illinois registration breach remains the reference baseline. Attempts, scanning, and a campaign hack are not the same as a disclosed successful breach.
Federal monitoring intactyesyesyesCISA, EI-ISAC, MS-ISAC, and the FBI task force were fully staffed across all three cycles. This stabilizer is the single most important change for 2026, since it was cut in 2025.

Sources paraphrased from CISA and ODNI and FBI statements, the FCC robocall enforcement actions, state court certification orders in New Mexico and Arizona, and Gallup, Pew, and MIT trust series. The one specification-sensitive call is the certification tripwire: score it at the general-election stage, not the primaries.

01 Threat-literature annex

The Condor question, answered

Is there a single thread anywhere, in any language, that lays out the full line from an information operation to an electoral takeover, the way a reader might extrapolate a war plan from a novel? The short answer is no. There is no unified master text. What exists is a modular literature: state military theory, investigated commercial playbooks, and academic taxonomies, each supplying a different piece, and none assembling the whole. This annex maps them so a defender can watch each stream on its own.

Descriptive and defensive only. This annex characterizes what already sits in the public record. It does not assemble the pieces into a usable method, and it reproduces no operational content.

02 State doctrine

Theory, mostly written to be defensive

Russian reflexive control

The theory, from Vladimir Lefebvre in the 1960s and later Chekinov and Bogdanov, is about feeding an opponent prepared information so that his own reasoned choice serves the initiator. Applied to an electorate, it means shaping the perceived choice-set so a population picks the manipulator's preferred outcome on its own. Timothy Thomas gives the standard English account.

Russian political technology

Andrew Wilson's Virtual Politics is the reference work. Practitioners such as Gleb Pavlovsky and Vladislav Surkov build a whole staged system of fake parties and phantom opponents and captured media, so democratic form is observed while real choice is hollowed out. Surkov's sovereign democracy is the ideological arm.

The Gerasimov misnomer

The so-called Gerasimov doctrine is a Western label its own coiner, Mark Galeotti, later disavowed. Gerasimov's 2013 article was a description of what Russia believed the West was doing through the Arab Spring and color revolutions, not an offensive playbook. It matters because it is routinely mischaracterized.

Chinese Three Warfares

Public-opinion, psychological, and legal warfare are codified in the PLA political-work regulations, with a newer concept of cognitive domain operations aiming at command of the mind. Taiwan is the documented target, including deepfakes during its January 2024 election.

Iranian activity

Documented through vendor disclosures rather than a published doctrine. Storm-2035 used language-model accounts to seed articles and comments on United States candidates on both sides, rated low impact. Iran-linked actors also phished a 2024 presidential campaign. Note that Storm-1516 is Russian, not Iranian, a frequent conflation.

The through-line

Across these, the common logic is not to change the count but to shape the environment so a chosen outcome looks legitimate and inevitable, while an opponent's own choices are turned against him.

03 Commercial playbooks

Where documented operational method actually lives

This is investigative and platform-takedown evidence, not published doctrine, and much of it is self-reported by operators with reasons to exaggerate.

Team Jorge and Tal Hanan

Exposed in 2023 by the Forbidden Stories Story Killers consortium. A former Israeli operative claimed involvement in dozens of national campaigns, using a fake-avatar management suite and account hacking to plant and then amplify material. Scope figures are the operator's own claims.

Cambridge Analytica and SCL

A military psychological-operations contractor lineage applied to civilian elections through psychographic microtargeting, built partly on tens of millions of harvested Facebook profiles. Documented by the whistleblowers and the United Kingdom Parliament. Independent scholarship treats its effect claims with caution.

Internet Research Agency

The Russian operation documented by the Mueller report and two United States Senate committee studies. A sustained cross-platform effort to polarize the electorate and depress specific groups, which exploited existing divisions rather than inventing them.

Archimedes and the hire market

An Israeli firm banned by Meta in 2019 for operations across several African elections, including a false-flag page to smear an opponent. Andres Sepulveda described, to Bloomberg, hacking-and-bot campaigns across nine Latin American countries for a Miami-based strategist. Both illustrate a mature disinformation-for-hire market.

The newer AI-enabled networks

CopyCop used language models to plagiarize, translate, and re-bias content across hundreds of fake sites. Spamouflage and Doppelganger are the documented Chinese and Russian analogues. The cost of entry is falling.

The pattern

The vendor market supplies the concrete methods the doctrine only theorizes: fake amplification, account compromise, and laundering of content into legitimate outlets, sold as a service.

04 Academic frameworks

Diagnostic taxonomies, written for defense

How democracies erode

Levitsky and Ziblatt describe elected leaders capturing referees and breaking unwritten norms. Nancy Bermeo names the modern forms: executive aggrandizement and strategic manipulation, the slow legal tilt rather than day-of fraud. This is the best-cited account of how the process actually runs.

How elections are rigged

Cheeseman and Klaas set out six techniques, from gerrymandering and vote-buying to hacking and fooling observers, and note the paradox that holding a rigged election can prolong a ruler's survival. The book is framed as a handbook for observers.

The authoritarian playbook

Protect Democracy synthesizes the scholarship into seven shared tactics, including politicizing institutions, spreading disinformation, corrupting elections, and aggrandizing the executive. Applebaum's Autocracy Inc adds the networked, transnational dimension.

Coups and self-coups

Naunihal Singh models coups as a coordination game won by projecting inevitability. The self-coup, or autogolpe, is a sitting executive seizing power and shutting other branches. Edward Luttwak's practical handbook is the classic that reads as a literal manual.

05 The mirror image

Color-revolution counter-doctrine

Russian and Chinese military science genuinely treats Western election and democracy promotion as itself a covert takeover method, named as color-revolution technology. Because they believe this sincerely, they justify their own interference in Western votes as defensive. Watching their military-science journals for this framing gives forward warning of escalation. Surkov's sovereign democracy is the domestic ideological answer to the same perceived threat.

06 Fiction as doctrine

The direct Condor parallel

The clearest case of a novel treated by a real movement as an operational blueprint is a piece of insurrection fiction that researchers tie to numerous attacks. It is documented here only as researchers characterize its role, with no operational content. The point for this question is the boundary: that case is about violent insurrection, not electoral takeover. There is no comparably documented novel that functions as an election-takeover blueprint, which is itself part of the answer. The true non-fiction analogue for seizing or defending power is the pairing of Luttwak's coup handbook and, inverted for liberation, Gene Sharp's list of nonviolent methods, which authoritarian states then re-read as a regime-change manual.

07 Synthesis and defensive use

Modular, not unified

The finding

No single thread runs the whole length. Doctrine supplies the theory, the vendor market supplies the methods, and the academic taxonomies supply the diagnosis, but no public text joins them into one operational plan. The absence is itself the answer to the question.

How a defender uses this

Map threats along three separate axes and assess each on its own: theory such as reflexive control and the Three Warfares, commercial vendors of the Team Jorge kind, and the diagnostic taxonomies. Use the academic checklists as the defensive instrument. Treat operator scope claims as claims, since efficacy is far weaker than the sellers assert, and remember that these operations mostly exploit existing division rather than manufacture it.

Treadstone 71 · Open-Source Analysis

THE FORENSIC FOOTPRINT

United States election fraud, petition irregularities, and official misconduct, 2018 to 2026. Every scheme left a trail. Every trail ran into a verification wall, and then into a courtroom.
3
Fraud typologies
7
Case jurisdictions
13,300+
Fraudulent signatures caught in Lincoln
0
National outcomes altered
Structural typology

Three ways people tried, and got caught

Between 2018 and 2026, state and federal agencies investigated, charged, and convicted operatives, circulators, and officials who tried to manipulate elections. The cases sort into three types. None altered a national outcome. Administrative verification caught most of them before certification.

TYPE 01

Commercial signature forgery

Pay-per-signature contracts without verification controls, so subcontracted crews forge sheets in bulk. Michigan 2022. Lincoln, Nebraska 2026.

TYPE 02

Absentee harvesting and drop-box tampering

Operatives insert themselves into the chain of custody between voter and ballot box. North Carolina. Bridgeport. Paterson.

TYPE 03

Insider system compromise

Sworn officials use their credentials to bypass access controls and copy voting software. Mesa County. Coffee County.

Chronology of the captured activity

The trail, 2018 to 2026

2016 to 2018 · North Carolina 9th District

Absentee harvesting sets aside a House result

Election-night tallies showed a 905-vote Republican lead. The state board found statistical anomalies in absentee returns and refused to certify. Operative Leslie McCrae Dowless, hired through a campaign consulting firm, ran an illegal ballot-collection operation.

Absentee harvestingAdm. BResult set aside, full redo ordered February 2019. Dowless died April 2022 before trial.
2020 · Paterson, New Jersey

An all-mail council election unravels

Audits flagged bulk mailings from single mailboxes and residents who never received the ballots recorded in their names. The state charged a council president and a councilman.

Absentee harvestingAdm. B20-count superseding indictment, including witness tampering.
January and May 2021 · Georgia and Colorado

Two insiders open the doors

In Coffee County, Georgia, a local supervisor let an outside forensics team copy Dominion software on January 7, 2021. In Mesa County, Colorado, the clerk used another person's credentials to admit an unvetted third party during a trusted-build update, and the images later appeared online.

Insider compromiseAdm. AMesa County clerk Tina Peters convicted and sentenced to nine years, October 2024.
2022 · Michigan gubernatorial primary

A signature ring knocks candidates off the ballot

Two firm owners took more than 700,000 dollars from campaigns and delivered tens of thousands of forged sheets. Inspectors caught full pages in identical handwriting and names of deceased voters. Five Republican gubernatorial candidates and three judicial candidates were disqualified.

Signature forgeryAdm. AJury convicted Wilmoth and Reed February 2026. Sentenced March 2026, one co-defendant acquitted.
2023 · Bridgeport, Connecticut

Drop-box footage forces a redo

Security video showed a town-committee official dropping thick stacks of absentee ballots into a City Hall drop box. A judge invalidated the Democratic primary and ordered a court-monitored redo.

Drop-box tamperingAdm. AFive charged February 2025, one facing 92 counts. A canvasser pleaded guilty July 2025.
2026 · Lincoln, Nebraska

Paid circulators, caught by hand-verification

Three petitions to amend Lincoln's charter drew more than 30,000 signatures. Hand-verification rejected most of them and flagged more than 13,300 as fraudulent. Investigators placed the circulators' phones in the county when the sheets were signed.

Signature forgeryAdm. AFive out-of-state circulators arrested, several warrants outstanding. Petitions failed to qualify. Investigators found no political organization involved in the fraud.
How the wall held · Lincoln, 2026

The detection funnel

The safeguard worked exactly as designed. Every signature was checked against the voter file by hand, and the fraud collapsed before a single measure reached the ballot.

Signatures submitted
30,100+
Validated
~10,400
Rejected
~19,700
Flagged fraudulent
13,300+
Arrested
5
Measures on the ballot
0
Signatures submitted across three petitions, hand-verified against the statewide voter file. More than 65 percent were rejected and the petitions failed to qualify. Source graded Admiralty A on official statements, B on regional reporting.
Outcomes

What the courts handed down

Wilmoth (MI)
4 to 20 yrs
Reed (MI)
2 to 20 yrs
Peters (CO)
9 yrs
Powell (GA)
6 yrs prob.
Hall (GA)
5 yrs prob.
Edmonds (CT)
3 yrs susp.
05101520 yrs
Prison-term ranges in orange, probation and suspended terms in gray. Michigan sentences carry restitution of 376,601 and 333,817 dollars. Powell and Hall pleaded to misdemeanor conspiracy counts. Figures from attorney-general releases and court records, Admiralty A.
Vulnerability and safeguard

Where the risk lives, and what closes it

VectorRisk mechanismPrimary detectionSafeguard response
Commercial petition canvassingPay-per-signature incentives drive bulk forgery and false affidavitsAutomated signature matching, voter-roll address cross-referencingBans on per-signature pay, mandatory registration of third-party firms
Absentee ballot processingUnlawful third-party harvesting, drop-box stuffing, witness forgeryDrop-box video, signature verification, postal trackingRestrictive return laws, drop-box surveillance, chain-of-custody tracking
Electronic voting accessInsider compromise of software, password leaks, physical trespassTrusted-build integrity checks, access logs, security footageDual-person access, state oversight of updates, mandatory video logging
Bottom line

The count held

Across seven jurisdictions and eight years, deliberate fraud left a forensic footprint every time, and administrative verification caught it before a national result turned on it. The disruption landed on primaries, local initiatives, and municipal contests. The verification wall held, and the schemes ran into courtrooms.

Read the full analysis · Managed Erosion
Copyright 2026 Treadstone 71  ·  www.treadstone71.com  ·  Defensive, open-source only. Verified fact and party claim are kept separate. Likelihoods, where stated, follow half-open probability bands.

Trademarks of Treadstone 71 LLC

Brand
Treadstone 71™
The T71 Standard
The T71 Standard™, The Adversary Index™ (TAI™), Cognitive Warfare Threat Report™ (CWTR™), Public Attribution Series™ (PAS™), Decision Advantage Standard™ (DAS™), Cognitive Warfare Operating System™ (CWOS™), Embedded Cognitive Warfare Officer™ (ECWO™)
Frameworks
STEMPLES Plus™, Cyber Intelligence Capability Maturity Model™ (Cyber Intelligence CMM™), Insider Threat CMM™, Cultural Nexus Framework™, Advanced Analytic Dominance™ (Advanced SATs™)
Decision Engines
ATCRI™, ACS™, CWC™, CWIA™, HTIM™, CARM™
Methods
Integrated Behavioral Threat Analysis™ (IBTA™), The Convergence™, Project Omega™, Decoy's Dilemma™, Pitch Black Tetrad™
Notice on Proprietary Methods and AI Restrictions · Copyright, trade secret, and trademark laws protect all Treadstone 71 LLC frameworks, engines, and analytic tools. We strictly prohibit external entities from ingesting our materials into artificial intelligence systems, large language models, or automated pipelines without a prior written license. Unlicensed scraping, embedding, vector indexing, or generating derivative products constitutes severe intellectual property infringement. Such actions explicitly violate global copyright structures, including the EU Directive 2019/790, Article 4 TDM-Reservation.