Skip to content

Security1 publisher2 min readPublished

CikLeak hands Vybory developer chats to Important Stories days before Russia's Duma vote

The group says it took documents, server configurations, passwords and staff communications from Russia's Central Election Commission and the contractors building Vybory, and Important Stories says it authenticated the files.

The Watch · Security desk

Photograph accompanying CikLeak hands Vybory developer chats to Important Stories days before Russia's Duma vote
Photo: caliber.az

What happened

  • An anonymous group calling itself CikLeak says it got into systems at Russia's Central Election Commission and at the companies developing Vybory, the state platform used to administer elections.
  • The claimed theft covers internal documents, server configurations, passwords and employee communications from the commission and its contractors, including the telecom company Rostelecom.
  • The group gave the material to Important Stories, an independent Russian investigative outlet, which said it had authenticated the documents.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Server configurations and passwords held by platform developers put the build detail of Vybory within reach of anyone who reads the dump. Whatever the commission has hardened on its own systems, these files sit in a contractor's chat log.
  • constraint Authentication of documents establishes that the files are genuine. The depth of the access is a separate question, and nobody outside Russia can bound what the group actually reached before ballots open.
  • capability A leak-and-publish operation aimed at showing where results could be manipulated works without any access to the count. That is a different kind of pressure than the 2024 denial-of-service and impersonation activity.
  • contradiction The state's threat model and the claimed breach land on different parts of the same system: the commission's own pre-vote testing pointed at the video feeds, while the alleged loss sits on the developer side.

The claimed haul is contractor material: server configurations, passwords, employee communications and developers' internal chats taken from the Central Election Commission and the companies building Vybory, Rostelecom among them [2][3]. Files of that kind describe how the platform is assembled and who can reach it, and they stay useful after the count unless every credential in them is changed.

Important Stories said it authenticated the documents [4]. The intrusion behind them is harder to pin down. The Record reported that how deeply the hackers got into the election infrastructure, and whether they reached systems directly involved in voting or counting ballots, is not clear [5]. The group also published screenshots it said show compromised systems [8]. On its website it said: "We infiltrated the infrastructure of Russia's Central Election Commission and downloaded secret documents and developers' internal chats" [6].

Russian election officials had been describing pressure of their own before any of this surfaced [18]. "We have been dealing with this for years, but what is happening now is difficult to compare with anything in terms of the intensity, volume and speed of the various attacks," CEC chair Ella Pamfilova said [13]. In August she said the election system was fully protected against cyberattacks, and that voter information was updated online twice a year and stored in a closed-access system [14]. A day before CikLeak's disclosure, officials tested the Vybory portal, the remote electronic voting system and the video surveillance infrastructure, and the assessment named the uninterrupted transmission of the video feeds a "weak link" [12].

In March 2024, during the presidential election, the activity took a different form: denial-of-service attacks, phishing sites and fake Telegram channels imitating official Russian services [15]. Rostelecom said at the time that most of it came from Ukraine, Western Europe and North America and involved professional hacking groups [16]. Ukraine's military intelligence agency, HUR, later acknowledged that it was behind attacks on United Russia and on Russia's electronic voting system [17]. The operation claimed this week is exfiltration and publication, with a stated aim of showing how the electoral system works internally and where authorities could manipulate results [7]. The Record described the group only as anonymous [1].

Voting runs three days from Friday for all 450 State Duma seats [9]. It is the first federal election conducted on Vybory 2.0, which entered use this year in place of a platform that had been running since the late 1990s [11], and the first for the chamber since the full-scale invasion of Ukraine in February 2022 [10]. CikLeak urged Russians to vote in person on the final day, arguing that would make manipulation harder [8].

What to watch

  • Whether Rostelecom or the Central Election Commission confirms a contractor compromise or disputes the documents Important Stories authenticated.
  • Whether Important Stories publishes the underlying files and identifies Vybory contractors beyond Rostelecom.
  • Whether the three voting days bring disruption of the Vybory portal or of the video feeds officials called the weak link.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories