news.mlab.sh
Back to the feed
threat-intel

Hackers claim breach of Russian election systems days before parliamentary vote

High
Summary

A hacking group called CikLeak claims to have breached Russian election systems, including those of the Central Election Commission and companies involved in developing Vybory, the state-run election platform. The group alleges it obtained internal documents, server configurations, passwords, and communications, aiming to expose potential manipulation opportunities. This follows a period of increased cyberattacks targeting Russian election infrastructure, with Ukraine’s military intelligence agency, HUR, previously attributed to some of the attacks. Russia is holding elections for its State Duma on Friday, utilizing the Vybory 2.0 platform for the first time.

A hacking group known as CikLeak has claimed to have infiltrated Russia’s election infrastructure, including systems belonging to the Central Election Commission and companies involved in developing Vybory, the state-run platform used to administer elections. The group stated on its website that it downloaded secret documents and developers’ internal chats. They also published screenshots purportedly showing compromised systems. CikLeak’s stated goal was not to disrupt voting, but to expose how the Russian electoral system works internally and what they described as opportunities for authorities to manipulate election results.

The claims come as Russia prepares to hold elections for all 450 seats in the State Duma, the lower house of parliament, over three days beginning Friday. This election marks the first federal election conducted using the Vybory 2.0 platform, replacing an earlier version used since the late 1990s. Russia’s Central Election Commission (CEC) had warned of growing cyber threats as voting approached, citing an increase in attacks targeting election systems and related infrastructure.

CEC Chair Ella Pamfilova indicated that the intensity and volume of these attacks were unprecedented. She highlighted that information about eligible voters is updated online twice a year and stored in a closed-access system. During the March 2024 presidential election, hackers launched distributed denial-of-service attacks and set up phishing sites and fake Telegram channels designed to imitate official Russian services. Rostelecom, a Russian telecom giant, reported that most attacks originated from Ukraine, Western Europe, and North America and involved professional hacking groups.

Ukraine’s military intelligence agency, HUR, later acknowledged its involvement in attacks on United Russia and Russia’s electronic voting system. The timing of these claims is particularly sensitive given Russia’s ongoing invasion of Ukraine and the potential for foreign interference in the election process.

Read the full article at The Record