#image_title

What’s Going on with the California GOP?

Court filings expose a widening donor-data crisis, weak internal controls, unresolved election-governance questions and a leadership problem as the November midterms approach.

By Christine Bish

(California Republican Party delegate, donor and formerly endorsed Republican congressional candidate)

The California Republican Party went to court, accusing its former finance director, Tiffany Qualls, of transferring confidential donor, fundraising, vendor, and finance records from party systems to personal email accounts. That would be serious enough if the dispute stopped there. It does not.

CAGOP’s own amended petition says its continuing review uncovered transfers that were “materially broader” than what it first described. The party says the transfers began around March 2026 – within weeks of Qualls being hired – continued through June, involved two personal email accounts, and included donor, fundraising, vendor and finance materials. The filing then makes the admission that should be at the center of this story: “The full scope of the transfers has not yet been established.” [1]

“The full scope of the transfers has not yet been established.” – CAGOP’s First Amended Petition

 

That sentence changes the story. This is no longer merely an employment dispute or a lawsuit about whether one former employee mishandled proprietary information. It is a governance and institutional-control story. It raises questions about hiring, vetting, supervision, cybersecurity, donor privacy, banking and fundraising systems, joint fundraising relationships, insurance, and who actually controls the California Republican Party’s finance operation.

It also arrives less than two months before the November 3 midterms, when Republican candidates, PACs and party organizations will be asking donors across the country to trust them with money and personal information. California’s congressional races are nationally important, and the Republican fundraising system is interconnected. That makes the undisclosed scope of this incident more than a Sacramento problem.

CAGOP Did Not Catch the Transfers in Real Time

The first major management problem is not an allegation from Qualls. It comes from CAGOP’s own Operations Director and Deputy Executive Director, Danielle Richards.

Richards states under penalty of perjury that after Qualls was terminated on June 22, her party email account was maintained as a shared inbox. Richards then reviewed the sent folder and found messages forwarded from Qualls’ CAGOP address to a personal UNLV alumni account. She prepared the original 49-message log by looking through the mailbox directly. Her declaration is explicit: she “used no software tool and ran no search.” [2]

Richards also acknowledges a limitation that cannot be brushed aside. If a message had been forwarded and then deleted before she reviewed the sent folder, it might not appear in the log. She therefore could not state that the original 49 messages represented the entire record of what Qualls may have transferred. [2]

In other words, CAGOP says confidential material had been leaving its systems, but the initial discovery appears to have happened only after Qualls was terminated and somebody manually opened her sent mail. There is no indication in that sworn declaration that a real-time security system stopped the transfers or alerted leadership while they were occurring.

Then the Problem Got Bigger

The initial public narrative focused on 49 messages from Qualls’ final week. CAGOP’s August 27 First Amended Petition expanded the timeline and scope. The party says a second personal account – an Outlook account – also received CAGOP material. The transfers identified “to date” began around March 2026 and continued through June. CAGOP listed sponsor information with mailing addresses, fundraising and finance plans, a contributions tracker, a vendor telemarketing plan and compilations of major campaign contributors among the categories found. [1]

The use of the words “to date” matters. So does the admission that the full scope remains unknown. When an organization is still expanding the timeline and discovering additional destinations weeks after the employee is gone, donors and partner organizations are entitled to ask whether management understands the full extent of the incident even now.

The 49-Message Log Raises an RNC Question

The actual titles in CAGOP’s court exhibit make the potential reach of this issue especially important. Among the forwarded messages were items titled “RNC Growth Plan – Events Section for Cost Allocation,” “RNC – Growth Plan Fundraising Report (Draft),” and “Victory 2026 Statewide Candidate Call Fundraising Support.” Another forwarded file was an expanded email list of roughly three megabytes. [3]

Other documents in the log included “New Majority Donors,” finance meeting summaries, a “Financial Governance & Decision Authority Framework,” an investment-account proposal, finance leadership agendas, direct-mail tracking information and internal risk assessments. [3]

Those titles do not prove that the RNC’s national donor database was copied. CAGOP also states that it is not alleging in the amended petition that Qualls transmitted the material to a third party. Those distinctions matter. But the documents make it reasonable to ask whether the RNC, NRCC, candidates, PACs or joint fundraising partners have been notified that materials connected to shared fundraising activity may be implicated.

Joint Fundraising Means Donor Data Does Not Live in One Place

Federal joint fundraising rules are designed around shared fundraising activity. Participating committees provide contributor histories to a joint fundraising representative so contribution limits can be checked, and the representative forwards required contributor information back to participating committees. The money and required donor records move through a network rather than remaining inside one organization. [4]

CAGOP has participated in exactly those structures. The FEC lists the California Victory Fund 2024 as a joint fundraising committee whose participants included the California Republican Party federal account, the NRCC and ten California congressional campaigns. The Kevin Lincoln Victory Fund similarly lists the California Republican Party federal account, Kevin Lincoln for Congress and The One America PAC as participants. [5]

That does not establish a national Republican data breach. It establishes why the boundary of the potential exposure cannot be assumed. If the transferred CAGOP files contained records created through joint fundraising, imported donor histories, candidate lists, cost-allocation documents or partner-generated data, other organizations may have an interest in knowing exactly what left CAGOP control.

Donor Information Is More Than a Mailing List

CAGOP itself tells the court why its donor records are valuable. Its filings describe nonpublic information that includes private email addresses and direct telephone numbers, donor segmentation, assessments of giving capacity and propensity, solicitation histories and responses, notes about donor relationships and interests, planned asks, fundraising calendars, prospect lists that have not produced reportable contributions, and private vendor pricing and terms. [6]

Qualls’ Employee Confidentiality Agreement is broader still. It defines confidential information to include nonpublic information concerning candidates and their family members, friends and associates; board members; employees; consultants; and financial, business, medical, legal, personal and contractual matters pertaining to CAGOP or related parties. [7]

That agreement does not prove that every category was transferred. It proves how sensitive the information environment was that CAGOP entrusted to its finance director.

As a CAGOP delegate, donor and formerly endorsed Republican candidate, I have a direct interest in the answer. The party maintains personally identifying information about delegates and processes donor transactions through fundraising systems. Contributions can also involve credit cards, bank accounts and checks. Federal committees have recordkeeping obligations that can include retaining an image or photocopy of a contribution made by check. [8]

The unanswered question is not whether political fundraising can involve sensitive information. It plainly can. The unanswered question is whether any such information was among the material transferred in this incident. CAGOP has not publicly provided that field-by-field answer.

Who Had Access – and Who Has It Now?

CAGOP should disclose the access-control map, not merely the organizational chart. Which employees, officers and consultants could access donor databases? Who could export files? Who held administrator rights for WinRed, Anedot, eFundraising or other fundraising tools? Who could access banking or deposit systems? Who could reach joint fundraising records? Who could add or remove users? Who received security alerts?

The same questions apply today. After Qualls was terminated, who inherited her permissions? Were every one of her credentials disabled immediately? Were tokens, shared passwords, forwarding rules, cloud sessions and application credentials revoked? Was there an independent forensic review of CAGOP’s own systems?

Scott Winn Put His Own Authority in the Court Record

The management chain is not speculative when it comes to Scott Winn. In a sworn declaration filed by CAGOP, Winn identifies himself as Chief Operating Officer and Executive Director and states that he is responsible for the party’s “day-to-day operations, including its personnel, its finance operations, and the administration of its information systems.” He also confirms that CAGOP hired Qualls as finance director and that she had access to donor, fundraising and vendor information in the ordinary course of her duties. [9]

Those are the precise areas at the center of the crisis: personnel, finance and information systems.

Officially, Jack Guerrero remains CAGOP treasurer and continues to sign federal reports in that capacity. I have separately confirmed through my own participation in the party that Guerrero attends meetings but does not exercise the operational control one might reasonably associate with the title. CAGOP can settle that question quickly by disclosing bank-signature authority, financial-system permissions, expenditure-approval authority and administrator roles. [10]

The point is not to argue over titles. It is to identify where actual authority sits and then match authority with accountability.

There Was a Finance-Control Warning Before Qualls

The Qualls dispute is not the only recent record raising questions about financial controls. In a November 3, 2025 response to an FEC inquiry, the California Republican Party federal account explained why it amended a report: the committee said it had recently hired a new bookkeeper who was reviewing multiple bank accounts and, during that training and reconciliation process, a wire received and sent through one of the committee’s bank accounts had been omitted from the internal account-reconciliation procedure and therefore from the original report. [11]

An amended campaign-finance report is not proof of corruption or intentional wrongdoing. It is, however, a concrete example of a financial-control failure during the same leadership era – and it makes the quality of internal controls directly relevant when the party later says its finance director transferred confidential finance and donor materials for months.

Who Hired Tiffany Qualls, and How Was She Vetted?

Qualls did not arrive at CAGOP with no political history. Her Nevada lawsuit states that she began as an intern at the Las Vegas office of McShane/RMC in December 2022 and was hired into the fundraising department in February 2023. In December 2025, she sued McShane-related entities in Clark County, alleging discrimination and retaliation. She filed an amended complaint in April 2026, while she was already serving as CAGOP finance director. Those are allegations in her Nevada civil case, not findings against McShane or RMC. [12]

The Nevada complaint stated that Qualls was then a Nevada resident. CAGOP’s later Sacramento filing states that she was residing in Sacramento County and had served as finance director from February until her June 22 termination. The record therefore supports that she relocated to California around the time of her CAGOP employment. [12]

The question is who vetted her, who recommended her, who reviewed the pending lawsuit against her prior Republican employer, and who approved giving her access to CAGOP’s donor and finance systems. I have independently confirmed through a source familiar with CAGOP operations that Qualls worked locally at party headquarters and that hiring decisions run through Chairwoman Corrin Rankin. CAGOP should respond to that account with documentation.

Her salary has not been publicly established in the records I reviewed. Neither has CAGOP publicly disclosed whether she was bonded or covered by fidelity, employee-dishonesty or cyber insurance, whether a carrier was notified, or whether a claim was filed. Those are basic risk-management questions when an organization alleges that a finance employee removed valuable confidential information.

What Happened to the Information?

CAGOP demanded return of its material repeatedly. Qualls told the court that she was preserving relevant data and had placed her personal MacBook under a voluntary freeze. She said she offered to return requested data but objected to the breadth of CAGOP’s proposed forensic protocol. CAGOP, in turn, argued that she retained party property and had not provided the accounting and certification it demanded. [13]

On August 7, the Sacramento Superior Court denied CAGOP’s emergency request for a temporary protective or preservation order, finding that the party had not made the required showing of immediate irreparable harm and noting Qualls’ sworn representation that her equipment was subject to a preservation freeze. That ruling did not decide the merits of CAGOP’s claims or declare the transfers lawful. [14]

There is no public evidence in the filings I reviewed that Qualls demanded money in exchange for returning the information. There is also no completed public forensic report establishing who else, if anyone, received copies. That is why the public should resist both extremes: neither declare a nationwide breach without evidence nor accept reassurance that nothing went further without a forensic basis.

This Governance Problem Did Not Begin With Donor Data

I was already preparing to publish concerns about CAGOP governance before the Qualls case broke. The common thread is not personalities. It is a recurring question about process, controls and accountability.

Paper Ballots for Policy. Clickers for Power.

In August, I prepared a delegate-election reform proposal after receiving a paper CAGOP ballot for party initiatives. The party mailed the ballot directly to delegates, required identifying information and a signature, received a physical record and established a counting process. That raised an obvious question: if CAGOP can use mailed paper ballots when delegates decide what the party stands for, why does it rely on convention attendance, proxies and electronic clickers when delegates decide who runs the party? [15]

My proposal did not accuse a particular election of being stolen and did not claim that a machine changed the outcome. It raised a system question. When an electronic device is assigned to an identifiable delegate, delegates are entitled to know what information is retained, who can access it and whether an individual supposedly secret vote can be reconstructed. I proposed one delegate, one paper ballot, one vote; no proxy voting for officer elections; observable verification and tabulation; reconciliation of ballots issued and counted; preservation of the ballots; and recounts when necessary. [15]

A separate 2023 convention voting report circulated among party activists raised allegations involving unexplained voting devices or voters and complaints about changed votes. Those allegations have not been independently adjudicated, and I do not present them as proof that a CAGOP election was stolen. They are exactly why an auditable physical process matters. A trustworthy system should not require delegates to take a vendor’s or leadership’s word for what happened inside a machine.

The Mike Cargile Proceeding: Leadership Was Warned About Due Process

The Mike Cargile unendorsement proceeding is another example. The Gateway Pundit, in an August 2022 article by Joe Hoft, published the recording of CAGOP’s proceeding to withdraw its endorsement of Cargile and criticized the way the hearing was conducted. [16]

I reviewed that recording and preserved the link in my own March 2025 email correspondence. During the proceeding, California attorney and CAGOP officer Randy Berholtz warned the executive body that Cargile had not been afforded due process. Berholtz ultimately voted with the body to withdraw the endorsement.

That sequence is important. The issue is not whether Berholtz personally supported Cargile or whether Cargile should have kept the endorsement. A private political party proceeding is not automatically governed by the Fourteenth Amendment in the same way a government court is, so this should not be confused with a judicial finding of a constitutional violation. The point is procedural: an attorney inside the governing process warned that the individual before them had not received due process, and the body proceeded anyway.

For me, that demonstrated a willingness to put the desired result ahead of the quality of the process. The Qualls matter now raises a different but related question: did CAGOP put operational convenience ahead of adequate safeguards for sensitive donor and financial information until the problem was already outside its control?

Proposition 50: A Costly Political Failure

The governance questions come against a record of political and fundraising weakness under the current leadership. California voters approved Proposition 50 in November 2025 with 64.4 percent of the vote. CAGOP was one of the largest independent spenders against the measure, reporting more than $10.2 million in advertising and messaging, according to a CalMatters analysis of state campaign-finance data. [17]

CalMatters later reported criticism that the party’s get-out-the-vote effort wasted money on mail sent to voters who had already returned their ballots weeks earlier. Rankin defended the effort, saying the party had “left it all on the field” and that she was proud of the work. [18]

The point is not that every losing campaign proves bad management. It does not. The issue is whether an organization facing a major defeat produces a transparent after-action accounting: what was spent, which vendors were used, when mail was dropped, how targeting was performed, what worked, what failed, and what changed afterward. Donors deserve that accounting before they are asked to finance the next operation.

The Fundraising Numbers Add to the Pressure

The state-level fundraising picture is equally stark. Capitol Weekly reported that the California Democratic Party’s main committee raised $17.4 million during the first six months of 2026 and held $25.5 million cash on hand, while the California Republican Party raised $119,893 and ended June with about $1.03 million in the bank. [19]

CAGOP’s federal account is a separate committee and presents a different picture. FEC data show approximately $7.47 million in receipts and $7.82 million in disbursements from January 1, 2025 through July 31, 2026, with about $574,523 cash on hand and $77,143 in debt at the end of that period. [20]

Those accounts cannot simply be combined, and the numbers do not by themselves prove wrongdoing. They do show an organization under financial pressure at the same time it is asking courts to recover information it describes as central to the value of its fundraising operation.

The National Ramifications Before November

California cannot be treated as an isolated state-party story in 2026. Proposition 50 changed congressional district lines in a way designed to favor Democrats, making California an even more important part of the national House battlefield. Republican candidates need money. The NRCC needs confidence in partner committees. The RNC needs confidence in state-party operations. Donors need confidence that the information they provide will be protected.

A California donor may contribute through a candidate committee, a PAC, a joint fundraising vehicle, a state party or a national organization. The same person can appear in several overlapping fundraising systems. When CAGOP itself says the scope of transferred material remains unknown, the uncertainty can affect confidence well beyond the individual files identified in a Sacramento lawsuit.

What Rankin and Winn Should Disclose

Before CAGOP asks delegates, candidates and donors to move on, the leadership should publish a factual incident report that answers the following questions:

  • The total number of messages, files and records transferred, including deleted-message analysis and all personal accounts or storage locations identified.
  • The number of donors, delegates, candidates, vendors and outside organizations whose information appears in the transferred material.
  • The data fields involved, including whether any driver-license, banking, payment-card, check-image or other protected personal information was present.
  • Every CAGOP, vendor, payment, banking, CRM, cloud, email and joint-fundraising system Qualls could access, and the date each credential was disabled.
  • Whether any RNC, NRCC, candidate, PAC, joint fundraising committee or other Republican organization has been notified and what data belonging to those entities was involved.
  • Whether CAGOP commissioned an independent forensic examination of its own systems and, if so, the scope and findings of that review.
  • Whether CAGOP determined that California breach-notification law was triggered, and the legal basis for any decision not to notify donors.
  • Whether Qualls was bonded or covered by fidelity, crime, employee-dishonesty or cyber insurance; whether a carrier was notified; and whether a claim was filed.
  • Who recommended, vetted and approved Qualls for the finance-director position, what qualifications were relied upon, and whether her pending lawsuit against her previous Republican employer was known before hiring.
  • Who currently controls CAGOP bank accounts, donor exports, administrator credentials, financial approvals and information-security decisions – by name and office, not merely by title.

A Ship Taking on Water

As a delegate, donor and formerly endorsed candidate, these incidents no longer look like isolated mistakes. They form a governance record: questions about the auditability and secrecy of officer elections; a recorded endorsement proceeding in which an attorney warned about due process before the body proceeded; a federal reporting correction tied to an omitted bank transaction; the Proposition 50 defeat and criticism of voter-contact spending; weak state-party fundraising; uncertainty over who truly exercises financial authority; and now a lawsuit in which CAGOP admits it has not established the full scope of confidential information transferred by its own finance director.

The Qualls lawsuit is not the iceberg. It is another hole in the hull.

A party cannot demand transparency from election officials, accountability from government and competent stewardship from public institutions while treating those standards as optional inside its own organization. The standard has to work in both directions.

Tiffany Qualls is entitled to defend herself, and CAGOP is entitled to pursue its claims. The court and arbitrator will decide the legal dispute between them. But no outcome in that case will answer the management question for Rankin and Winn: what controls were in place, what failed, who knew, when did they know, and why were donors and delegates left without a complete public accounting?

For me, the answer is now a matter of confidence. I do not believe the Rankin-Winn leadership has demonstrated the level of governance, financial control, procedural fairness or data stewardship necessary to carry the California Republican Party through a nationally consequential midterm election.

I am therefore calling on Chairwoman Corrin Rankin and Executive Director and Chief Operating Officer Scott Winn to resign immediately.

Read the full article here

Share.
Leave A Reply

Exit mobile version