Skip to main content
news

Russia upgraded the system that tabulates its election results. Experts found vulnerabilities that could be exploited to manipulate the vote.

Source: iStories
Shamil Zhumatov / Reuters / Scanpix / LETA

Hackers have breached Tsifrotek, the company behind GAS Vybory 2.0, Russia’s upgraded vote-tabulation system, which is being used in a federal election for the first time this year. The hackers gave the files to the investigative outlet iStories, which analyzed them with the help of technical and election experts. Meduza summarizes iStories’ investigation into how GAS Vybory 2.0 works and what vulnerabilities it has.

  • GAS Vybory is an electronic platform that collects vote results from Russian elections and referendums. It shouldn’t be confused with DEG, the remote electronic voting system: DEG lets voters cast their ballots online, while GAS Vybory tallies results both online and at polling stations.
  • The first version of GAS Vybory dates back to the 1990s and has long been outdated, which is why the Central Election Commission commissioned GAS Vybory 2.0 in 2019. The system was supposed to be finished by 2022, but as of 2025 it still wasn’t ready — despite 20 billion rubles spent on it, one of the commission’s largest expenditure items.
  • Tsifrotekh, a Rostelecom subsidiary created specifically to build GAS Vybory 2.0, is developing the system. Its developers earn about 500,000 rubles a month, but the company itself operates at a loss, which it attributes in its filings to “work on a complex, multi-year project of national significance.”
  • Developers tested GAS Vybory 2.0 during Russia’s September 2025 unified voting day, when something in the system kept breaking down. Tsifrotekh’s management acknowledged that employees “lived at work” and had only managed to pull off the test through sheer effort: things were constantly breaking, but staff fixed the problems before the Central Election Commission could notice.
  • GAS Vybory 2.0 went into full operation in early 2026, but developers kept fixing bugs after launch: the platform showed the share of election commissions that had reported results as above 100%, miscalculated winners in multi-member districts, and included deceased voters on voter lists.
  • An electoral analyst and two technical experts examined the leaked Tsifrotekh archive and identified vulnerabilities in GAS Vybory 2.0 that could be used to manipulate election results. The system has no protection against protocol substitution, and its users have direct access to voter lists, letting them inflate the number of participants in the electronic voting group, for example. It also accepts DEG results from Moscow even without confirmation by an electronic signature, the safeguard meant to prevent fraud.

At Meduza, we are committed to transparency about our use of artificial intelligence in the newsroom. The story you’re reading was written by one of our living, breathing journalists and translated from Russian using an AI model configured to follow our strict editorial standards. This translation process is the result of extensive testing and refinements to ensure our English-language coverage is timely and accurate. A Meduza editor reviews every draft before publication.

If you find any errors in this translation, please contact us at [email protected].

To read Meduza’s exclusive content in English, please subscribe to our newsletter.