The group said it obtained internal documents, server configurations, passwords and staff correspondence. It announced the breach on the eve of the State Duma elections, scheduled for September 18-20.

"We do not interfere in the work of election commissions or the voting process, but help shed light on how it is arranged from the inside," the hackers said. In their statement they urged Russian citizens to refuse remote electronic voting, calling it the easiest way to steal votes, and to vote in person at polling stations.

The group had a separate message for members of election commissions: do not take part in falsifications. "We know who you are. Do not help the regime continue the war and kill people," the statement said.

Alexei Gusev, director of Tsifrotekh, when asked by iStories to comment on the hack, said he was hearing about it for the first time. Tsifrotekh is a subsidiary of Rostelecom.

GAS Vybory 2.0 was launched in early 2026. In August, Central Election Commission head Ella Pamfilova asserted that the system could not be hacked. A few hours before reports of the breach appeared, the commission reported that it had analyzed vulnerabilities in GAS Vybory, remote electronic voting and the video surveillance system.

On September 15, Pamfilova reported a steady rise in "various kinds of attacks" on the commission's infrastructure. According to her, everything that "is now beginning to happen" had been predicted by the commission and it had "prepared well," so readiness on security was "one hundred percent." She named the polling station video surveillance service and uninterrupted broadcasting as the weak link in the entire system.

Six Russian regions bordering other countries were allowed to hold early voting. iStories is preparing an investigation based on documents it has obtained into how the Russian electoral system is arranged.