Hacking Group 'CikLeak' Claims Breach of Russian Election Infrastructure Ahead of Parliamentary Vote
An anonymous hacking collective, **CikLeak**, asserts it has infiltrated systems linked to Russia's election infrastructure, including the **Central Election Commission** and developers of the **Vybory** election platform. The group claims to have exfiltrated sensitive data, aiming to expose potential electoral manipulation rather than disrupt the upcoming parliamentary vote.
# Hacking Group 'CikLeak' Claims Breach of Russian Election Infrastructure Ahead of Parliamentary Vote
Just days before Russia commences voting for a new parliament, an anonymous hacking group, identifying itself as **CikLeak**, has claimed a significant breach of computer systems connected to the nation's election infrastructure.
## Allegations of Infiltration and Data Theft
**CikLeak** states it gained unauthorized access to systems belonging to Russiaβs **Central Election Commission (CEC)** and companies involved in the development of **Vybory**, the state-run platform used to administer elections. The group specifically named Russian telecom giant **Rostelecom** among the compromised contractors.
The hackers allege they stole a trove of internal documents, server configurations, passwords, and employee communications from the commission and its associated contractors. This material was reportedly provided to **Important Stories**, an independent Russian investigative outlet, which claims to have authenticated the documents. However, the full extent of the penetration into the election infrastructure, and whether systems directly involved in voting or ballot counting were accessed, remains unclear.
On its website, **CikLeak** declared: βWe infiltrated the infrastructure of Russiaβs Central Election Commission and downloaded secret documents and developersβ internal chats.β
## Exposing Electoral Manipulation, Not Disruption
**CikLeak** has clarified its intentions, stating that its goal is not to disrupt the voting process or interfere with election commissions. Instead, the group aims to expose the internal workings of the Russian electoral system and what it describes as potential avenues for authorities to manipulate election results.
To further its objectives, the hackers published screenshots purportedly showing compromised systems. They also urged Russian citizens to vote in person on the final day of the election, suggesting this would make manipulation more challenging.
## The Upcoming Russian Parliamentary Elections
Russia is set to hold elections for all 450 seats in the **State Duma**, the lower house of parliament, over three days beginning Friday. This election marks the first for the chamber since Russiaβs full-scale invasion of Ukraine in February 2022. It will also be the inaugural federal election utilizing the **Vybory 2.0** platform, a system introduced this year to replace an older version in use since the late 1990s.
## Growing Cyber Threats and Prior Attacks
The **CEC** had previously warned of escalating cyber threats as the election approached. A day prior to **CikLeak**'s disclosure, Russian election officials conducted a security assessment of the **Vybory** portal, remote electronic voting system, and video surveillance infrastructure. The assessment identified the video surveillance system, particularly the uninterrupted transmission of its feeds, as a βweak link.β
**CEC** Chair **Ella Pamfilova** acknowledged a significant increase in attacks targeting election systems and related infrastructure. βWe have been dealing with this for years, but what is happening now is difficult to compare with anything in terms of the intensity, volume and speed of the various attacks,β Pamfilova stated. These comments followed earlier assurances in August that the election system was fully protected against cyberattacks.
Russian election infrastructure has been a recurring target during previous votes. During the March 2024 presidential election, for instance, hackers launched distributed denial-of-service (DDoS) attacks and deployed phishing sites and fake **Telegram** channels mimicking official Russian services. **Rostelecom** reported that most of these attacks originated from Ukraine, Western Europe, and North America, attributing them to professional hacking groups.
Attacks also targeted online services belonging to **United Russia**, President **Vladimir Putin**βs political party, and government services in several Russian regions. Ukraineβs military intelligence agency, **HUR**, later claimed responsibility for attacks on **United Russia** and Russiaβs electronic voting system.