Published · Updated

Hacker group claims breach of Russia's Central Election Commission infrastructure days before State Duma vote

The hacker group CikLeak says it breached infrastructure belonging to Russia's Central Election Commission and its contractor Tsifrotech, a Rostelecom subsidiary that developed the new GAS 'Vybory' 2.0 digital voting system. The hackers obtained internal documentation, source code for the new system, internal communications and a staff credentials database, then passed the archive to the Russian investigative outlet IStories, whose journalists confirmed the materials were genuine. The disclosure comes days before Russia's September 18–20 State Duma elections, the first federal campaign to use the new platform, and against the backdrop of Russia's CEC announcing a vulnerability check of DAS 'Vybory' and its video surveillance system hours earlier.

Key points

  • Hacker group CikLeak claimed responsibility for breaching Russia's CEC and its contractor Tsifrotech, a Rostelecom subsidiary.
  • Tsifrotech developed the new GAS 'Vybory' 2.0 / DAS 'Vybory' 2.0 digital voting platform launched at the start of 2026.
  • Hackers obtained internal documentation, source code for GAS 'Vybory' 2.0, internal correspondence, and a staff credentials database.
  • The archive was passed to the Russian investigative outlet IStories, which confirmed the materials were genuine.
  • Russia's September 18–20 State Duma elections will be the first federal campaign run on GAS 'Vybory' 2.0.
  • Hours before the hack became public, Russia's CEC announced a vulnerability check of DAS 'Vybory' and its video surveillance system.
  • In August, CEC head Ella Pamfilova had publicly stated the system could not be hacked.

Why it matters

The breach targets the very system Russia is about to use for its first federal election on the new GAS 'Vybory' 2.0 platform, and was disclosed only days before voting begins. The leak's authenticity was verified by an independent Russian investigative outlet, IStories, lending weight to claims the system is not as secure as Russian officials had asserted. The episode also sharpens scrutiny of voting that Russia plans to conduct on occupied Ukrainian territories, which Kyiv considers illegitimate.

What happened

The hacker group CikLeak claimed responsibility for breaching infrastructure belonging to Russia's Central Election Commission and its contractor Tsifrotech, a subsidiary of Rostelecom that built the new GAS 'Vybory' 2.0 / DAS 'Vybory' 2.0 digital voting system. According to the group, the breach yielded internal company documentation, the source code of the new voting system, internal work correspondence, and a database of staff passwords and credentials. The hackers handed the archive to the editorial team of the Russian investigative outlet Vazhnye Istorii (IStories), whose journalists confirmed the materials were genuine. The disclosure came days before Russia's September 18–20 State Duma elections, which are scheduled to be the first federal campaign conducted on the new platform. Hours before news of the hack became public, Russia's CEC announced a vulnerability check of DAS 'Vybory' and the video surveillance system. In August, CEC head Ella Pamfilova had stated publicly that the system could not be hacked.

How Ukrainian sources describe it

Ukrainian coverage frames the breach as a story about the integrity of Russia's election infrastructure, and ties it directly to Russia's plan to hold the September 18–20 vote on occupied Ukrainian territories. The reporting centers Ukraine's official position: the Central Election Commission has declared any Russian-organized 'elections' or 'referendums' on temporarily occupied territory illegitimate and their results legally void. Ukrainian outlets also highlight the Security Service of Ukraine's call for residents of the occupied territories to boycott the vote.

Background

GAS 'Vybory' 2.0 was launched at the beginning of 2026 as the first federal digital voting system of its kind in Russia. In August, CEC head Ella Pamfilova publicly said the system could not be hacked. Hours before the breach was reported, Russia's CEC announced it was conducting a vulnerability check of DAS 'Vybory' and the video surveillance system. In June 2026, Russia's CEC adopted decisions to organize voting on the temporarily occupied territories of Donetsk, Luhansk, Zaporizhzhia and Kherson oblasts, as well as Crimea and Sevastopol, carving them into 11 single-mandate electoral districts. Ukraine's Central Election Commission has declared any such 'elections' or 'referendums' illegitimate and their results legally void, and Ukraine's Security Service has urged residents of the occupied territories not to participate in the September 18–20 vote.