An anonymous hacking group calling itself CikLeak claims to have infiltrated computer systems tied to Russia's election infrastructure, just days before the country opens three days of voting for a new State Duma on September 18, 2026. The group alleges it accessed internal documents, server configurations, passwords, source code, and employee communications belonging to Russia's Central Election Commission (CEC) and contractors including state-controlled telecom giant Rostelecom and its subsidiary Tsifrotekh. As of publication, the claim has not been independently confirmed at the system level, and this article treats it as an unverified allegation throughout.
What's Being Claimed
CikLeak says it "penetrated the infrastructure of the CEC of Russia and downloaded secret documents and internal chats of developers, received server configuration, passwords and much more." The group's alleged targets include Tsifrotekh, a Rostelecom subsidiary reportedly involved in developing GAS Elections 2.0 (also referred to as "Vybory 2.0"), the CEC's newly introduced election management platform.
Notably, the group claims a narrow, non-disruptive intent. In its own statement, CikLeak said: "We do not interfere in the work of election commissions and the voting process, but help shed light on how it works from the inside." The group added that it wants Russian citizens "to learn more about how the authorities can falsify elections," and it singled out remote electronic voting as, in its words, "the easiest way to steal votes" -- explicitly urging Russians to vote in person rather than online. Because these are the group's own characterizations of its access and motives, they should be read as claims rather than established fact.
Context: Russia's Parliamentary Vote
Voting for all 450 seats of the State Duma runs across three days, beginning September 18, 2026. This is the first federal election conducted on the CEC's newly deployed GAS Elections 2.0 platform, which replaces a system that had been in use since the late 1990s, and it is the first parliamentary vote held since the start of Russia's full-scale invasion of Ukraine. Election infrastructure has been a recurring target for politically motivated hacking activity tied to the broader conflict; during Russia's 2024 presidential election, Ukraine's military intelligence service later acknowledged responsibility for some cyberattacks on Russian voting-related systems. Against that backdrop, an unverified claim of this kind lands in an already tense environment around the legitimacy and security of Russian electoral systems.
Verification Status
Independent Russian investigative outlet Important Stories reviewed material supplied by CikLeak and said it was able to authenticate at least some of the documents. However, it remains unclear how deeply the alleged intrusion actually reached, and whether the hackers gained any access to systems directly involved in vote casting or ballot counting -- as opposed to peripheral contractor or developer environments. There is currently no independent technical confirmation of the scale or operational impact of the alleged breach.
Russian officials have not issued a clear, on-the-record confirmation or denial of CikLeak's specific claims. Tsifrotekh director Alexey Gusev, when asked for comment, said only, "This is the first time I've heard of it." Separately, CEC Chair Ella Pamfilova has acknowledged a broader surge in cyberattacks against election systems, saying "what is happening now is difficult to compare with anything in terms of intensity, volume and speed," and has previously described GAS Elections 2.0 as effectively "impossible to hack" because it runs on infrastructure isolated from the public internet. Those statements predate and do not directly address the CikLeak claim. Given the anonymous origin of the claim, the sensitivity of the timing, and the lack of confirmed technical detail, readers should treat the scope and accuracy of CikLeak's assertions as unresolved pending further verification.
Why It Matters
Claims like this sit at the intersection of election security and information warfare. Even an unverified breach claim, timed deliberately to land just before a national vote, can function as a form of psychological pressure -- undermining public confidence in an electoral process regardless of whether the underlying technical claims hold up. Hacktivist and state-linked groups have repeatedly targeted Russian government and election-adjacent systems since the escalation of the war in Ukraine, and such claims are frequently exaggerated, partially accurate, or difficult to verify in the fog of an active information conflict. For defenders, the episode is a reminder that election infrastructure -- including peripheral contractor and developer environments, not just vote-tabulation systems themselves -- remains an attractive target precisely because a credible-sounding claim can cause reputational damage independent of actual system compromise. Whether or not CikLeak's access was as extensive as described, the CEC's own acknowledgment of an intensifying attack volume signals that election-adjacent infrastructure will likely remain a contested target through and beyond this vote.