Thursday, 17 September 2026
Rīga TV

World and Latvian news in one place

WorldPublished: 17 September 2026 at 17:45

Russia's upgraded election tabulation system found to have vulnerabilities that could allow vote manipulation

Hackers obtained internal files from Tsifrotekh, developer of Russia's new vote-tabulation system GAS Vybory 2.0, revealing flaws experts say could be exploited to manipulate election results.

Foto: Meduza

Hackers have breached Tsifrotekh, the company building Russia's upgraded vote-tabulation system GAS Vybory 2.0, which is being used in a federal election for the first time this year. The stolen files were passed to investigative outlet iStories, which analyzed them with technical and electoral experts; Meduza summarized the findings.

GAS Vybory is a platform that collects and tallies vote results from Russian elections and referendums, both online and at physical polling stations. It is distinct from DEG, the separate system that lets voters actually cast ballots remotely online.

A costly, delayed rollout

The original GAS Vybory dates to the 1990s and had become outdated, prompting Russia's Central Election Commission to commission a replacement in 2019. GAS Vybory 2.0 was meant to be finished by 2022, but as of 2025 remained incomplete despite 20 billion rubles in spending, making it one of the commission's largest expenditures.

The system is built by Tsifrotekh, a subsidiary of state telecom operator Rostelecom created specifically for the project. Its developers earn roughly 500,000 rubles a month, though the company itself reports operating at a loss, which it attributes to work on a complex, multi-year project of national significance.

Repeated breakdowns during testing

During Russia's unified voting day in September 2025, used as a test run, the system repeatedly malfunctioned. Tsifrotekh's management later acknowledged that staff effectively lived at the office, scrambling to fix problems before the Central Election Commission could notice them.

GAS Vybory 2.0 went into full use in early 2026, but bugs persisted after launch: it at times showed more than 100% of election commissions having reported results, miscalculated winners in multi-member districts, and listed deceased people as voters.

Vulnerabilities identified

An electoral analyst and two technical experts who reviewed the leaked Tsifrotekh archive identified several security gaps. The system lacks protection against protocol substitution, and users have direct access to voter lists, which could be used to artificially inflate participation figures in electronic voting groups. It also accepts DEG results from Moscow without requiring confirmation by an electronic signature, a safeguard intended to prevent fraud.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category