
Tracing the Path of Election Vulnerabilities from Dandong to Washington
Roy Kim
Co-author of The Dandong Project: A Report on 21st-Century Hybrid Warfare
A Strange Parallel Between Two Democracies
On July 16, 2026, President Donald Trump publicly made three notable statements regarding U.S. election security and election integrity.
First, he stated that China had stolen the personal information of approximately 220 million American voters.
Second, he asserted that approximately 270,000 ineligible “ghost voters” had been found on statewide voter registration rolls, including those in Michigan.
Third, he identified North Korea—alongside Russia, China, and Iran—as one of the hostile states possessing the capability to threaten America’s election infrastructure.
Nearly three years earlier, on October 10, 2023, South Korea issued a remarkably similar warning.
In an official announcement, South Korea’s National Intelligence Service (NIS) concluded that external actors, including North Korea, could penetrate the National Election Commission’s computer network at any time and potentially manipulate voter registration databases as well as vote counting systems.
Although issued at different times, both warnings point to the same underlying concern: hostile foreign actors possess the capability to compromise critical election infrastructure.
Where do these two cases intersect?
This article traces that connection.
Its starting point lies in Dandong, China, in 2001.
1. The Seed Planted in Dandong — When North Korea Helped Build the System
In August 2001, Hana Program Center officially began operations in Dandong, China.
The center was operated by a South Korean company known as South-North Hanabiz, which conducted business domestically under the name Hanabiz.com. Its business model was straightforward: software projects contracted in South Korea were outsourced to North Korean developers working in Dandong.
The center also entered into a joint development agreement with Dasan CNS, a South Korean network equipment developer.
The project emerged during President Kim Dae-jung’s Sunshine Policy, which encouraged inter-Korean economic cooperation.
Officially, Hana Program Center presented itself as a software development company.
Its own website, however, publicly listed joint development projects that included “DASAN WEB NMS Application” and “DASAN NETWORK Equipment System.” Those records indicate that North Korean developers participated in projects involving Dasan’s network management software and network equipment systems.
Following the sinking of the ROKS Cheonan in 2010, South Korea suspended most inter-Korean economic cooperation under the May 24 Measures. Hana Program Center officially shut down the following year.
Exactly one year later, in 2012, one of North Korea’s most sophisticated cyber operations units—now closely monitored by both U.S. and South Korean intelligence agencies—began operating at full scale.
Its name was Kimsuky.
This is not speculation.
In June 2023, South Korea’s National Intelligence Service, National Police Agency, and Ministry of Foreign Affairs jointly issued a cybersecurity advisory together with the U.S. FBI, NSA, and Department of State.
The advisory officially identified Kimsuky as operating under Research Center 63 of the Third Bureau (Technical Reconnaissance Bureau) of North Korea’s Reconnaissance General Bureau (RGB). It further assessed that the RGB’s primary mission is to counter political, military, and economic threats perceived to endanger the survival and stability of the North Korean regime.
This raises a fundamental question.
North Korea was not simply an external hacking threat. It participated directly in building portions of the software and network management environment involved in these systems over an extended period. One of the most basic principles of cybersecurity is that those who design a system understand its architecture—and its weaknesses—better than anyone else.
That is precisely why this issue warrants an independent supply chain security investigation.
Another important fact deserves attention.
When the U.S. National Institute of Standards and Technology (NIST) cataloged the Dasan vulnerabilities in 2018, the company responded that the affected product was “a nine-year-old legacy product.”
If the product was already nine years old in 2018, its development dates back to approximately 2009.
That period coincides with the years when Hana Program Center was operating at its peak.
In other words, the equipment later found to contain critical vulnerabilities was designed and manufactured during the same period in which North Korean developers were participating in Dasan’s network management and equipment architecture projects.
This is not simply a case of an aging software product developing vulnerabilities over time.
The development period of the affected equipment directly overlaps with the period of North Korean participation in those development projects.
Whether that overlap has any technical or security significance is a question that should be answered through an independent technical audit—not speculation.
2. The First Step in Election Manipulation — The Voter Registration Database
When most people think of election fraud, they imagine someone secretly opening a ballot box in the middle of the night, swapping ballots, or stuffing fraudulent votes into the count.
Modern election manipulation, however, is far more sophisticated. The more significant attack surface is often hidden within computerized election systems and the processing of election data.
The starting point for any large-scale digital manipulation is the voter registration database.
The mathematics behind this are straightforward.
Assume a district has 200 registered voters, of whom 100 actually cast ballots. Candidate A receives 60 votes, while Candidate B receives 40.
Candidate A wins by 20 votes.
For Candidate B to reverse that outcome, at least 21 additional votes would be required—effectively increasing voter turnout by roughly 11 percentage points.
Under normal circumstances, generating that many legitimate votes is extraordinarily difficult.
Instead, a different approach becomes possible: creating fictitious voters rather than fictitious ballots.
There is a practical reason for this.
Fraudulent ballots inserted into the count without corresponding registered voters would immediately raise red flags because the total number of ballots would exceed the number of eligible voters.
For fraudulent ballots to appear statistically legitimate, an equivalent number of fictitious voters must already exist within the voter registration database.
Those entries could consist of deceased individuals, people who have moved away, or entirely fictitious identities.
That is why the voter registration database becomes the primary target.
Which voting systems are most vulnerable to this type of attack?
Mail-in voting in the United States and early voting in South Korea share a similar structural vulnerability.
Neither system relies primarily on physical voter rolls at the polling place. Instead, election officials must verify voter eligibility in real time through centralized electronic voter registration databases.
If an attacker gains access to that verification process, it becomes a critical point of vulnerability.
Traditional in-person voting is more resistant because physical voter rolls exist on site and observers can directly monitor the process.
A computerized attack follows a different sequence.
An attacker would first manipulate the voter registration database by creating fictitious voter records.
During the early voting period, those fictitious voters could then be marked as having voted.
Fraudulent ballots corresponding to those records could later be introduced into the count.
Even if questionable ballots are later discovered during canvassing, the numbers would appear internally consistent because the voter registration database already reflects the same number of registered voters.
In that scenario, the manipulation does not begin inside the ballot box.
It begins much earlier—inside the database itself.
A similar concern surfaced in Venezuela in 2017.
Following the Venezuelan Constituent Assembly election, Smartmatic CEO Antonio Mugica publicly stated that the official results did not match the actual votes cast and asserted that at least one million votes had been artificially inflated.
He argued that the problem was not limited to the voting machines themselves, but could also arise during the transmission and aggregation of election data within the central system.
The Venezuelan case illustrates an important point: investigating election integrity requires more than examining voting machines alone.
Any meaningful audit must also examine voter registration databases, central servers, data transmission pathways, and vote aggregation systems.
President Trump’s reference to approximately 270,000 ghost voters in Michigan, together with South Korea’s National Intelligence Service warning about the potential creation of fictitious identities within the voter registration system, reflects the same underlying concern.
Although the two cases occurred in different countries, both point to vulnerabilities that can arise when voter registration databases become centralized digital systems.
3. AWEB — Exporting Election Systems Worldwide and a Troubling Pattern
The structural similarities between election vulnerabilities in the United States and South Korea did not emerge in isolation.
Part of the explanation lies in an international election assistance network led by South Korea.
The Association of World Election Bodies (AWEB) was established in 2013 under the leadership of South Korea’s National Election Commission.
Although AWEB is often perceived as an international organization, it is not a United Nations agency. Legally, it is a nonprofit corporation organized under South Korean law.
Even so, it has played a role comparable to that of an international organization in election assistance programs around the world.
South Korea also provides more than 90 percent of AWEB’s operating budget.
The flow of funding deserves equal attention.
The U.S. Agency for International Development (USAID) maintains a cooperative relationship with the Korea International Cooperation Agency (KOICA), which has supported AWEB’s overseas election assistance activities through Official Development Assistance (ODA) programs.
As a result, U.S. taxpayer funding flows indirectly through USAID and KOICA into AWEB’s international election assistance projects.
The concern is not the funding itself, but the outcomes associated with those programs.
According to The Dandong Project, election-related assistance provided by AWEB was followed by officially documented allegations of election fraud or the annulment of election results in 19 of the 29 countries that received such assistance—a rate of 65.5 percent.
In the Democratic Republic of the Congo, electronic vote-counting equipment supplied by the South Korean company Miru Systems became the focal point of election fraud allegations.
In Kyrgyzstan, the chairman of the Central Election Commission acknowledged widespread violations of election law, leading to the annulment of the election.
In Iraq, discrepancies between electronic vote tabulation and manual ballot counts reportedly reached as much as twelvefold in certain cases.
An even more striking pattern emerges upon closer examination.
Among the nineteen countries where election-related controversies followed AWEB assistance, 84.2 percent also participate in China’s Belt and Road Initiative (BRI).
Whether that overlap is merely coincidental—or reflects a broader structural relationship—requires independent investigation.
This article does not claim to answer that question.
It raises a different one.
If election systems promoted through AWEB repeatedly became the subject of controversy across multiple countries, and if a significant majority of those countries also fall within China’s Belt and Road network, then the process, implementation, and outcomes of those election assistance programs deserve independent scrutiny.
It is equally important to determine how those systems actually operated overseas, what technical vulnerabilities were identified, and whether any of those vulnerabilities have relevance to the election infrastructures of South Korea and the United States.
Moreover, if U.S. taxpayer funding was indirectly connected to those programs, Congress has ample justification to conduct its own independent review.
4. The Same Equipment, the Same Vulnerability — A Shared Weakness Across South Korea and the United States
The discussion now turns to the technical foundation of this issue.
On May 3, 2018, security researchers at vpnMentor disclosed two critical vulnerabilities affecting GPON (Gigabit Passive Optical Network) routers manufactured by Dasan Networks (DZS).
The U.S. National Institute of Standards and Technology (NIST) subsequently entered the vulnerabilities into the National Vulnerability Database (NVD) as CVE-2018-10561 and CVE-2018-10562, assigning both a CVSS severity score of 9.8 out of 10, placing them in the Critical category.
The attack itself is relatively straightforward.
By appending a specific string—“?images/”—to the router’s web interface URL, an attacker can bypass authentication and gain administrative access without a password.
When combined with the second vulnerability, an attacker can remotely execute arbitrary commands and assume complete control of the device.
Exploit code for both vulnerabilities was later published in public repositories, making exploitation possible even for individuals with limited technical expertise.
The larger concern is that these GPON routers were not deployed only in South Korea.
Approximately one million units were reportedly in operation worldwide, including widespread deployment in the United States.
A review of the timeline illustrates how long these vulnerabilities remained unresolved.
Timeline
May 2018 — NIST officially publishes the vulnerabilities. Researchers notify Dasan Networks and request a security patch.
2018 (Shortly After Disclosure) — Dasan responds that the affected product is a “nine-year-old legacy product” and that no security patch will be provided.
April 15, 2020 — South Korea holds its 21st National Assembly election.
November 3, 2020 — The United States conducts the 46th presidential election.
March 2022 — The Cybersecurity and Infrastructure Security Agency (CISA) issues an emergency advisory recommending that the affected devices be removed from service and powered down immediately.
March 31, 2022 — The product line is officially discontinued.
In other words, both countries conducted national elections while these critical vulnerabilities remained active.
For approximately four years, no official security patch was issued.
The vulnerability remained open.
At this point, an obvious objection deserves consideration.
If election networks operate on closed systems, how could they be vulnerable to external attack?
The answer lies in the architecture of South Korea’s election communications network.
The National Election Commission’s dedicated election network is not a physically isolated air-gapped system.
Instead, it operates over LG U+’s dedicated communications infrastructure using a logically separated virtual private network based on VPN and VLAN technologies.
While traffic is logically segmented, the underlying physical communications infrastructure is shared.
That distinction is central to understanding the significance of CVE-2018-10561.
The vulnerability targets the web management interface of GPON routers positioned along the network perimeter.
Rather than attacking an election network directly through the public Internet, an attacker could potentially compromise equipment located at the communications boundary and use it as an entry point into the internal election network.
CISA’s unusually strong recommendation that affected devices be removed from service immediately reflects the seriousness of that potential attack path.
South Korea’s National Intelligence Service reached a similar conclusion in 2023 when it warned that foreign actors possessed the capability to penetrate the National Election Commission’s systems.
South Korea’s procurement records further indicate that the affected equipment was deployed within the country’s dedicated election communications network.
According to the Korean Public Procurement Service (KONEPS), the National Election Commission and LG U+ signed a contract in 2019 to build the dedicated election communications network, and Dasan GPON routers, switches, and related networking equipment were installed along its wired infrastructure.
As a result, the communications path carrying election results from local counting centers to the National Election Commission’s central servers included equipment later found to contain critical security vulnerabilities.
5. A Modus Operandi Analysis
In criminal investigations, modus operandi (MO)—a perpetrator’s recurring method of operation—is often one of the most important investigative indicators.
When the same actor is responsible for multiple incidents, recognizable methods and operational patterns tend to reappear.
Viewed through that lens, a comparison of the election systems of the United States and South Korea reveals four notable structural similarities.
First, both countries rely on computerized voter registration databases.
A centralized digital voter registration system creates what cybersecurity professionals describe as a single point of failure.
When voter rolls were maintained in decentralized physical form, any attempt to manipulate them was largely confined to individual jurisdictions.
A centralized electronic database changes that dynamic.
If successfully compromised, a single point of entry could potentially affect voter records on a much broader scale.
Both South Korea and the United States employ computerized voter registration systems that introduce this type of structural risk.
Second, both countries operate remote voting systems that are difficult to monitor in real time.
In the United States, this takes the form of mail-in voting.
In South Korea, it is early voting.
Both systems depend on real-time verification against centralized electronic voter registration databases rather than physical voter rolls located at polling places.
That verification process becomes a critical point of vulnerability if an attacker gains unauthorized access.
Traditional in-person voting provides a greater degree of transparency because physical voter rolls are available on site and election observers can directly monitor the process.
Remote voting systems, by contrast, rely primarily on electronic verification, making independent observation considerably more difficult.
Third—and most importantly—the same networking equipment appeared in both countries’ election infrastructure.
The GPON routers manufactured by South Korea’s Dasan Networks (DZS)—the very devices that prompted CISA to issue an unusually strong advisory recommending that they be removed from service immediately—were reportedly deployed not only in South Korea but also within U.S. election infrastructure.
This was not a case of similar vulnerabilities affecting different products.
It involved the same manufacturer, the same hardware platform, and the same critical vulnerabilities—CVE-2018-10561 and CVE-2018-10562.
The same CVSS 9.8 backdoor vulnerability identified in equipment used within South Korea’s election communications network allegedly existed in equipment used within U.S. election infrastructure as well.
Fourth, the intelligence agencies of both countries independently identified the same category of threat actor.
In 2023, South Korea’s National Intelligence Service publicly warned that North Korea and other foreign actors possessed the capability to penetrate the National Election Commission’s systems and potentially interfere with voter registration and vote-counting processes.
Likewise, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has assessed that Russia, China, North Korea, and non-state actors possess the capability to compromise U.S. election infrastructure.
Although the two assessments were produced independently by different governments, both point toward the same category of foreign cyber threat.
Taken together, the evidence from South Korea and the United States reveals multiple points of convergence—in the threat actors identified, the networking equipment involved, the vulnerabilities discovered, the timing of those vulnerabilities, and the overall architecture of the systems.
Those similarities suggest that this is not simply a South Korean issue.
They also indicate that the underlying concern extends beyond ordinary political debate and into the realm of election infrastructure security.
Whether these vulnerabilities were actually exploited during the 2020 U.S. presidential election remains a matter for official investigation and legal determination.
This article does not claim otherwise.
Nevertheless, examining whether the similarities identified in both countries represent coincidence or evidence of a broader pattern is a legitimate investigative question—and one that ultimately falls within the responsibility of the appropriate authorities.
6. Conclusion and Policy Recommendations — Investigate, Isolate, and Count by Hand
The cases examined throughout this article may appear unrelated at first glance. Yet each reveals recurring patterns involving the same technologies, similar organizational connections, and shared security vulnerabilities.
The priority now is to examine those elements individually, establish the facts through independent investigation, review the equipment and communications infrastructure used in election systems, and verify electronic tabulation against the physical ballots themselves.
Accordingly, this article urges the U.S. Congress, the Department of Justice, the FBI, and other appropriate authorities to consider the following actions.
Recommendation 1 — Conduct a Joint U.S.–South Korea Supply Chain Security Review
Dasan Networks (NASDAQ: DZSI) is a publicly traded company whose networking equipment has been deployed in communications infrastructure in both the United States and South Korea.
This is therefore not simply a domestic issue for either country.
It is a supply chain security issue affecting allied nations.
Through the U.S.–ROK Supply Chain Security Group (SCSG) and appropriate congressional oversight mechanisms, the following issues warrant a joint review:
First, conduct an independent technical audit of North Korean participation in equipment development through Hana Program Center, including any legacy code inheritance associated with those projects.
Second, determine how Dasan GPON equipment was supplied and deployed within the United States, including which telecommunications providers operated the equipment, where it was installed, and during what time period.
Third, examine why no official security patch was issued for approximately four years after NIST cataloged the vulnerabilities and CISA recommended that the equipment be removed from service, and determine whether applicable cybersecurity disclosure obligations were satisfied.
Fourth, determine whether the affected equipment was deployed within election-related communications infrastructure during the 2020 U.S. presidential election.
CISA has already formally acknowledged the security risks associated with these devices and recommended that they be removed from service.
Accordingly, reviewing the equipment’s supply chain and determining why the vulnerabilities remained unpatched represent reasonable and necessary follow-up measures for protecting election infrastructure.
Recommendation 2 — Congressional Oversight of AWEB and the Flow of USAID–KOICA Funding
U.S. taxpayer funds are indirectly connected to AWEB’s international election assistance activities through USAID and KOICA.
Congress should determine how those funds were used and whether additional oversight is warranted.
Specifically, Congress should examine:
First, how much USAID funding provided through KOICA ultimately supported AWEB-related projects, and how those funds were spent.
Second, whether the repeated election controversies in countries receiving AWEB assistance—and the high degree of overlap with China’s Belt and Road Initiative—reflect coincidence or a broader structural relationship.
Third, if U.S.-funded election assistance programs ultimately strengthened authoritarian election management rather than democratic institutions, what accountability measures and policy reforms should follow.
Recommendation 3 — Adopt Taiwan’s Manual Ballot Counting Model and Independent Audits of Voter Registration Databases
Restoring confidence in election outcomes does not necessarily require increasingly complex technology.
Taiwan offers an alternative model.
Ballots are counted manually, one at a time, read aloud in front of observers representing both sides.
Because the process does not rely on electronic tabulation systems, opportunities for server intrusions, communications-network attacks, or backdoor exploitation are significantly reduced.
Equally important, voters and observers can directly witness the counting process, strengthening public confidence in the results.
Three reforms deserve consideration in both the United States and South Korea.
First, establish mandatory post-election independent audits of statewide voter registration databases used for mail-in and early voting.
Second, immediately remove communications equipment from election infrastructure if it has not undergone adequate security validation.
Third, require independent verification comparing electronic tabulation results with the physical paper ballots.
Closing Statement
The greatest threat to democracy is not hacking itself.
It is allowing known vulnerabilities in election systems to remain unexamined and uninvestigated.
Protecting election integrity does not always require increasingly sophisticated technology.
Sometimes the most effective safeguards are the simplest ones: preserving paper ballots, having people verify them directly, and comparing those physical ballots against electronically tabulated results.
The issue before us is not merely the possibility of isolated cyberattacks.
It is whether vulnerabilities have accumulated over the past quarter century across election systems, communications networks, hardware, and administrative processes—and whether those weaknesses could affect the integrity of future elections.
If such vulnerabilities exist, they should be identified, independently investigated, and eliminated.
References
- National Intelligence Service (Republic of Korea). (October 10, 2023). National Election Commission Cybersecurity Assessment: Vulnerabilities in Voting and Vote-Counting Systems.
https://www.nis.go.kr/CM/1_4/view.do?seq=251 - U.S. Department of Defense. (June 1, 2023). North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media.
https://media.defense.gov/2023/Jun/01/2003234055/-1/-1/0/JOINT_CSA_DPRK_SOCIAL_ENGINEERING.PDF - National Institute of Standards and Technology (NIST), National Vulnerability Database (NVD).
CVE-2018-10561
https://nvd.nist.gov/vuln/detail/CVE-2018-10561
CVE-2018-10562
https://nvd.nist.gov/vuln/detail/CVE-2018-10562 - Cybersecurity and Infrastructure Security Agency (CISA). (March 31, 2022). Known Exploited Vulnerabilities Catalog – Dasan GPON Routers.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog - Korea ON-line E-Procurement System (KONEPS). (2019). National Election Commission–LG U+ Dedicated Election Communications Network Procurement Records.
Sky Daily. (December 13, 2024). LG U+ Base Station Equipment Manufactured by Huawei: Election Manipulation Concerns.
https://m.skyedaily.com/pdf_view.html?pdf_url=/data/skyn_pdf/2024/20241213/web/20241213-12 - Hana Program Center (Official Website). Joint Development Project List (DASAN WEB NMS Application; DASAN NETWORK Equipment System).
Tongil News. (March 24, 2004). Inter-Korean Economic Cooperation: Hanabiz Remains the Sole Survivor.
https://www.tongilnews.com/news/articleView.html?idxno=42717 - Voice of America (VOA Korean). (August 3, 2017). Smartmatic Says One Million Votes Were Manipulated in Venezuela’s Election.
https://www.voakorea.com/a/3969617.html - Westminster Foundation for Democracy (WFD). Democratic Republic of the Congo Program.
https://www.wfd.org/where-we-work/democratic-republic-congo-drc - Daegu Ilbo. (December 12, 2024). Full Text of President Yoon Suk Yeol’s December 12 Address.
https://www.idaegu.com/news/articleView.html?idxno=623282 - Edaily. (July 6, 2018). The Hana Program Center: A Decade of Collaboration with North Korean Software Developers.
https://www.edaily.co.kr/News/Read?newsId=03273446619271896&mediaCodeNo=257 - Electronic Times (ETNews). (September 11, 2012). The First Inter-Korean Joint IT Venture Established.
https://www.etnews.com/201209110678
Roy Kim (legal name Sang-Hoon Kim) is a South Korean data analyst specializing in election systems and cybersecurity-related research.
He earned his degree in Accounting from California State University, Long Beach (CSU Long Beach) and previously served as a senior researcher on a joint nanomaterials research project conducted by Sungkyunkwan University and Seoul National University.
Since 2020, he has focused on investigating structural vulnerabilities within South Korea’s election system and is known for identifying the follow_the_party algorithm through data analysis.
He is the co-author of The Fingerprints of a Hacker and Discovering the Fingerprints of a Hacker. In June 2026, he co-authored The Dandong Project: A Report on 21st-Century Hybrid Warfare with Professor Kim Mi-young.
Because Professor Kim is currently recovering from cancer surgery, this commentary is being published solely under Roy Kim’s name.



