The group said it gained access to the infrastructure of Tsifrotekh, a subsidiary of state telecom operator Rostelecom created specifically for the GAS Vybory 2.0 system, according to Important Stories (Vazhnye Istorii). The outlet reviewed almost 200 gigabytes of material and showed the archive to an election analyst and two technical experts.
GAS Vybory is the electronic platform that collects voting results in elections and referendums. It should not be confused with DEG, the remote electronic voting system that lets people cast ballots online; GAS Vybory tallies results from both online and in-person voting.
The first version of the system appeared in the 1990s and became outdated. In 2019, the Central Election Commission ordered the development of GAS Vybory 2.0. It was due to be finished in 2022, but by 2025 it was still not ready, with 20 billion rubles spent. In 2025 the system was tested during the single voting day in September, and it was fully put into operation in early 2026.
The first vulnerability is the substitution of protocols. After votes are counted, the commission prints and signs a final protocol, and the results are entered into the system automatically (via QR code or by uploading a PDF file) or manually. According to the documentation, manually entered data is not checked against the originals, and protocols uploaded by QR code can be edited. The system retains previous versions and the username of the person who made the edit.
The second vulnerability involves manipulation of voter lists. A system administrator at a territorial election commission can manually upload a file with applications to take part in electronic voting: no electronic signature is required, and the origin of the file is not verified. According to Important Stories, this makes it possible to artificially inflate the number of DEG participants.
The third vulnerability concerns Moscow's electronic voting. According to the outlet, DEG results can enter the system even without a confirming electronic signature. The module locates signature files but does not verify them; the data passes through, and the final protocol carries no note that the signature was unconfirmed. Tsifrotekh itself is not involved in developing either the federal or the Moscow DEG: the system receives votes that have already been processed.
"It makes no sense to talk about vulnerabilities, because this software does not register votes but processes ready-made protocols, and results can be changed at every step: both by editing files by hand and in the database after import," a technical specialist told the outlet.
In the uploaded database, the journalists found data on 111.3 million voters. A source told the outlet that the data is stored in the open and is not encrypted. By cross-referencing some records with death data, the journalists found at least 104,000 deceased people who remained on the lists in the occupied territories of Ukraine, as well as in the Kursk and Bryansk regions.
Developers also manually corrected data on the test circuit, bypassing procedures. Whether such edits remain possible in the working system during elections is unknown. The journalists warn that individual components of the system may already have changed.
Voting in the elections will take place from September 18 to 20. In August, Central Election Commission head Ella Pamfilova said GAS Vybory could not be hacked.