In the spring of 2026, Vladimir Putin met Russia’s Central Election Commission (TsIK) members. Among other things, Ella Pamfilova, the chair of the commission, told Putin about the GAS Vybory 2.0 (‘Elections 2.0’) digital government platform — a new version of its electronic system used for elections. For the first time, this version will be implemented at the federal level during the September 18–20 State Duma election.
“We have fully transitioned to the new architecture built on domestic hardware,” — Pamfilova told Putin, — “It has no equivalent anywhere in the world in terms of data storage capacity and of the operational subsystems number. It remains autonomous from the global network belonging to the enemy; it is fully centralized. In other words, the enemy won’t be able to get to it — that’s for sure.”
Just before the State Duma elections, hackers breached the infrastructure belonging to Tsifrotek, the company that developed the GAS Vybory 2.0 system. The hackers passed the obtained documents on to the IStories editorial team. We examined nearly 200 gigabytes of technical documentation, internal correspondence and the developers’ conference calls; independent technical and electoral experts assessed the archive at our request. Who created the new system, how was it made and how reliant and transparent is it?

The names of those involved in the development IStories spoke to are not disclosed for security reasons.
“An intricate work of art.” The origins of the GAS Vybory 2.0 system
Development of the new digital system for conducting elections in Russia began in 2019. First and foremost, the Central Election Commission (TsIK) wanted to replace the old platform created back in the late 1990s. It had been updated several times, but it was still ‘morally, physically and technologically’ outdated, TsIK head Ella Pamfilova noted.
The aim was to launch the new version in 2022, but development was delayed. According to IStories calculations , this project cost the state at least 20.5 billion rubles ($250 million approx.) from 2019 to 2025. During the same period, the Electoral Commission spent 18.8 billion more on supporting the first version of the system, which was operated simultaneously with the development of the new one and was only abandoned in early 2026.
The GAS Vybory 2.0 system became one of TsIK’s most expensive expenditures. During the 5 years with no federal elections, when TsIK was not spending money on running such campaigns, the GAS Vybory 2.0 system accounted for over 40 percent of the agency’s total annual expenditure.
In autumn 2024, TsIK approved the updated system’s development plan up to 2030. Oleg Kachanov, the project’s chief architect, explained that the platform would be moved to a centralized architecture with a shared database located directly at TsIK, and that it would run on Russian software exclusively. Furthermore, the new system would be integrated with other government services (such as the public services platform Gosuslugi, the Ministry of Internal Affairs and the Federal Tax Service’s platforms, etc.) to ensure that voter data is updated in real time. Electoral law experts criticized this approach, arguing that it would be impossible to monitor independently.
Only one TsIK member was discontented with the new concept — Yevgeny Kolyushin, a representative of the Communist Party of the Russian Federation (KPRF). He raised questions about the lack of transparency regarding voter lists and electronic vote records, and attempted to find out how secrecy and lack of fraud would be ensured, but his concerns were ignored. The concept was adopted by a majority vote.
Despite the extensive development work, the new system largely replicates the old one. This decision is understandable, says an anonymous technical expert who examined part of the developers’ archive at our request: “It is extremely difficult to rewrite a huge legacy system from scratch whilst elections are taking place continuously, so the old stack was retained for the sake of compatibility,” they note. Ella Pamfilova also spoke about this: “GAS Vybory 2.0 took all the best features from our first system,” the Election Commission chair said.

According to the expert’s assessment, the developers spent most of their time trying to understand the old system, getting it up and running on new hardware and making a few tweaks, and then fixing the errors that would emerge. They describe the essence of the contractor’s work as follows: “to change things in a way that doesn’t change anything” and to migrate the system to domestically produced infrastructure.
The Election Commission is particularly proud of this shift to domestically produced systems (a part of the general “import substitution” campaign — Ed.), which was one of the project’s key principles: the commission’s chair, Ella Pamfilova, and both key development coordinators (Nikolai Bulaev, the commission’s deputy chair, and Oleg Kachanov, the chief architect of the system and deputy head of the Ministry of Digital Development) have repeatedly emphasised that the updated system exclusively runs on Russian software.
The developers of the system were sceptical about such statements. Here is how they commented on the TsIK executives’ remarks in their work chat groups:
“What domestic software are we talking about? We only use foreign software in development”
“How unpatriotic. The platform owner said it’s domestic, so that’s what it is”
“Well, we’re no longer using Kafka [a foreign platform for data transmission and processing], it’s Кафка now. And it’s Джава instead of Java, the domestic version”
Internal documents reveal that the developers also use foreign platforms (Jira and Confluence) to set and track tasks and store documentation. The team discussed plans to switch to ‘Yaga’ (a recently developed “import substituting” Russian equivalent of Jira developed by Rostelecom — Ed.) — on several occasions, but, according to the team members, “it didn’t take off, and the idea was shelved.”
At the same time, the GAS Vybory 2.0 developers must comply with the import substitution requirements set for state-owned companies. “We have to buy Russian laptops, and, since recently, keyboards, mice and monitors as well. We’re trying to purchase the highest-quality, most functional equipment possible,” they write in chat rooms. The developers bear the cost themselves. They complain that the import-substituting hardware heats up too much, whilst domestic software is not particularly reliable: “To put it mildly, this can be described as low reliability infrastructure; in other words, anything can crash at any time and at any scale.”

In early 2026, the GAS Vybory 2.0 was put into permanent operation. “It’s the birth of a beloved child,” Nikolai Bulaev, the commission’s deputy chair, commented at the time. He also described the new system as an “intricate work of art.”
TsIK was delighted with its ‘beloved child’: at the end of 2025, more than 20 people involved in its development received medals, certificates of honour and letters of thanks from the institution. “A huge, full-scale effort was made to develop a completely unique system with no global equivalents. We were navigating a ‘digital minefield’; everything was being done for the first time. The practically impossible was achieved,” Pamfilova praised the new system.
“You have to work in the basement.” The system’s developers
The main developer of the updated system is Tsifrotek, a subsidiary of Rostelecom, Russia’s state-owned digital service provider. This is a single-project company created specifically for developing the GAS Vybory 2.0 system. Tsifrotek states that its mission is to create a “comprehensive solution for digitizing the Central Election Commission of Russia and the country’s electoral commissions at all levels” and to completely replace the old version of the platform.

The company is operating at a loss. According to Tsifrotek’s financial statements, losses had reached 1.7 billion rubles ($20 million approx.) by the end of 2025. The company’s revenue was 426 million rubles ($5 million approx.) lower than planned, whilst the operating loss was 304 million rubles ($3,5 million approx.) higher than expected, as Alexey Gusev, the CEO of the company, explained to the staff during an internal conference call.

Tsifrotek explicitly states that the reason for the losses is its “work on a complex, years-long project of national importance — the development and maintenance of the GAS Vybory 2.0 system.” In its early years, the company was actively engaging contractors using borrowed funds, as it lacked the in-house expertise to carry out such work, but needed to meet “high reliability and security requirements.”

The company’s budget was also hit by fines from the state customer. In 2025 alone, the contracting authority imposed fines totalling 152 million roubles on the company (for the system maintenance, the CEO told staff whilst explaining the ‘bonus payments issues’ in the final quarter of 2025). According to him, the fines arise partly due to red tape: even if the developers meet the system maintenance requirements on time, “because of paperwork not filled in on time, the state customer has no choice but to issue fines.”

By 2025, Tsifrotek had already employed more than 300 people. That is also when the company began laying people off, according to its financial statements. One of our sources says this happened because the company “hadn’t calculated the budget properly”: “Firstly, there were a lot of fines following the unified voting day (in 2025, local elections in many regions of Russia were scheduled for the same day, September 14 — Ed.) Secondly, the staff had been paid generously for overtime work, even when it wasn’t actually necessary, and the budget ended up in a mess.”
“At the end of 2025, they simply sacked most of the team,” ex-employees complain in their reviews. They also mention the difficult working conditions: “A very challenging place to work, with a whole lot of services operating in a complicated, confusing way. You have to work in the basement.” One of those interviewed by IStories described the atmosphere within the team as follows: “The attitude towards subordinates was offensive, they didn’t hold back much in their language or jokes, let alone valuing [employment] rights. They were always short-staffed.”

According to reviews, Tsifrotek developers earn an average of around 300 thousand rubles per month ($3,500 approx.) The leaked data shows that the salaries are higher: in 2025, an ordinary developer would earn around 500 thousand rubles a month ($6,000 approx.), whilst a senior developer would earn up to 650 thousand rubles ($7,700 approx.). During the unified voting day campaigns, earnings could increase two- to threefold due to paid overtime.
“For some, the monthly income reached almost a million rubles (up to $12,000), even though their salary only amounted to 300 thousand. And yet, a developer could show up and just loaf around all day,” says one person engaged in the development. In addition, staff are paid quarterly bonuses. According to the leaked documents, in certain months even ordinary developers received over a million roubles. However, since the 2025 unified voting day, the company has had bonuses issues, the staff say: they either do not pay them in full or do not pay them at all.

“It’s just a regular IT company,” an employee tells IStories. “It’s not like everyone has to exercise every morning while listening to the Russian national anthem.” According to another employee, the company is staffed by “ordinary people” — “there’s no sign of some kind of mass Z (pro-war — Ed.) sentiment.” He describes most employees as an “amorphous, apolitical mass”: “Neither supporting [the war and the government policies in general] nor against it.” Sometimes at conference calls, he says, less-than-flattering comments about the authorities can be heard — especially upon VPNs being blocked en masse in 2025–2026 (since 2022, Russia has been blocking international social media and services, hence VPNs have been widely used to access most of them — Ed.) The team communicates on Telegram, so after the crackdown on VPNs remote developers had to “figure something out” to stay connected. It’s easier to access the Internet in the TsIK building itself: “There’s access, so at work you can chill and watch YouTube.”
“The staff would sleep at work.” The development process
Tsifrotek joined the project in 2023. According to internal conference calls, the company took over the development work from the Systematica company when it was underway.
“At the initial stage, no one had the source code — not Rostelecom, not the Electoral Commission, nobody. Deliveries were chaotic; it was unclear which version [of the system] was being used. The different versions were incompatible with one another. It was a real mess,” Alexander Minchenko, Tsifrotek’s then-director of development told employees at the time.
In 2025, the developers were due to carry out two system trials and then test it in a real election during the unified voting day in September. Alexey Gusev, Tsifrotek’s CEO, admitted during an internal conference call that, as of early 2025, the system was essentially not ready: “To say it’s not ready yet is an understatement.”
“The quality of the system was poor. We identified around 7,000 issues, of which around 500 were critical. There wasn’t a single report that functioned properly,” Alexander Minchenko, then Head of Development at Tsifrotek, said. “How did we conduct elections in such a situation? Well, it was an extremely risky move.”

The team handled the 2025 unified voting day thanks to working overtime — the staff “lived at work” and “carried the unified voting day on their shoulders,” Minchenko noted during a conference call. According to him, ‘a lot of things went wrong’ during the vote, but the developers quickly fixed the bugs — so quickly that the Central Election Commission didn’t notice any problems.
“The whole team simply gave it their all, pushing themselves to 1,000 per cent. I saw people sleeping whenever they could, right here in Room 110 of the data centre in the basement,” Yuri Sakun, Director of Integrated Digital Projects at Rostelecom, described the voting day.
The GAS Vybory 2.0 system features a closed network that cannot be accessed from the internet; consequently, Tsifrotek staff sometimes work within the TsIK building itself. According to one of our interviewees, all staff members are security checked by the Federal Protective Service (FSO) before being issued with a permanent pass to the TsIK. Not everyone passes the check.
The strict access regime has sometimes led to direct clashes between the developers and the FSO. “Today, FSO officers tried to detain an employee and hand them over to the police for leaving late,” one such incident was described in chat rooms in the summer of 2026. Sometimes passes are revoked without any explanation — one can only speculate about the reasons, says one of the Tsifrotek staff: for example, it can be accidentally “taking down the prod [the operating version of the system] at the wrong time,” liking a “wrong” video on YouTube, or simply somehow falling out of favour with the customer to find out later that their pass was no longer valid.

According to an internal conference call at the company, work on setting up the information security department at Tsifrotek only began in 2026. “We have the department, but no staff,” the company’s then-technical director admitted at the time, adding that Tsifrotek lacked the resources and expertise to oversee the contractor responsible for the project’s security, Rostelecom’s subsidiary Solar.
The staff have had basic security training by Rostelecom, an employee told us. “But if work-related communication takes place on Telegram, that speaks volumes,” they add. In the internal chat groups employees mention one of them being hacked. They also regularly discuss suspicious files infiltrating into the code base of the system.


The Central Election Commission states that the upcoming State Duma elections will take place in “extremely challenging conditions,” and that the agency’s top priority is security. According to Oleg Kachanov, TsIK is successfully combating digital threats, such as DDoS attacks. This fight leads to malfunctions and obstructs work, says a person involved in the development of the system: the internal services frequently crash, and the IP addresses used by the portal’s team themselves get blocked—“this has caused several outages.” “There’s a constant struggle when it comes to security. The client plays it safe and says, ‘Let’s block it,’ but because of that, we can’t work,” the developer says.
The development progress would be demonstrated at special presentations for the customers from TsIK’s Federal Center for Informatization, the government and Ella Pamfilova personally, according to internal discussions among the developers.
Errors were sometimes corrected at the last minute before demonstrations and report submissions. “We have an urgent problem <...> An error in mapping the campaign reports — the FCI is coming for the report at 9:00 a.m., and we won’t be able to provide it to them,” they wrote in the chat just 30 minutes before the deadline. The employee responsible for this replied that the cause was a misspelling of the “United Russia” party name: “They wrote ‘RUSSSIA’ with three S’s <...> But for the report, you can temporarily correct the mapping <...> Make it say ‘UNITED RUSSSIA.’”
On the customer’s (the FCI) side, the development was overseen by Rodion Shchekuteev, the deputy head of the agency, and Dmitry Gundin, head of the Department for the Collection and Processing of Information Resources at the GAS Vybory 2.0 system. New versions were personally approved by the FCI Director, Alexander Sokolchuk.
In 2023, the Tsifrotek employees discussed raising money for New Year’s gifts for several representatives of the customer: three of them, including Sokolchuk and Shchekuteev, were to receive “VIP gifts.” According to the chat logs, only 30 employees “voluntarily decided to financially contribute to the gifts” for the client’s representatives, and 2,350 rubles ($30 approx.) were raised from each of them.

“We had systems that were completely unfinished, but we had to submit what we’ve done according to the contracts,” says one of the sources interviewed by IStories. According to him, they would succeed in part thanks to such gifts: “We would come and say, ‘Yes, yes, we’ll definitely get everything done, but it’s not working right now. Here’s a nice gift, by the way. Please sign here; we need to close the contract.’” Most often, they would present alcohol in large amounts: “Not exactly bribes, but gifts. All those huge trunks were X-rayed by the Federal Protective Service at the entrance.”
“The systems are being refined as we speak.” Is the platform ready for its first federal election?
According to one of the Tsifrotek employees interviewed by IStories, the GAS Vybory 2.0 system is almost ready and operational, but some systems were “being refined literally as we speak.” After the 2025 unified voting day, the developers had many tasks, but the client’s requirements changed frequently. The staff had to find compromises, which is why many things don’t work the way they should, our source explains. Meanwhile, the developers are “working an awful lot of overtime,” and the terms of government contracts are often not being followed — “they turn a blind eye to what needs to be documented.”
This year, for the first time, State Duma elections will be held in the Ukrainian territories occupied by Russia since 2022. Before making this decision, the Central Election Commission consulted with the Russian FSB and the Ministry of Defense.
According to the sources interviewed by IStories,” the digital infrastructure needed to conduct elections in these territories was still not set up. “It’s total garbage, to put it mildly,” says one of the employees. “This is where it’s really possible to manipulate and alter things — it’s very difficult to verify the data coming in [from the occupied territories].”
The idea of voting in the annexed regions places an additional burden on the GAS Vybory 2.0 system — for example, in terms of communicating address data. At a call, developers discussed the way the system had to process larger address information files because of the occupied territories being included in the voting process. “If, for example, a long street is renamed, or a new region is annexed or separated — I don’t know, anything like that — the [address] file will take up over a gigabyte (at that time, the respective part of the system could only handle files smaller than 800 MB — Ed.).”
Confusion over addresses in the occupied territories has led to widespread malfunctions in the subsystem used to keep track of the voter registry. In the occupied parts of Ukraine’s Donetsk, Luhansk, Zaporizhzhia, and Kherson Oblasts, there were more than 95,000 “address-related incidents,” which amounts to about 10% of all current malfunctions in the subsystem, the developers noted. Problems with addresses have also been arising in the annexed Crimea. “There are now ZERO residents on the street,” “all voters from both addresses are gone” — Crimean Sevastopol system administrators wrote in their technical support requests in 2025 and 2026.
System tests continued until September 2026. Just a few weeks before the election, developers were still sorting through dozens of requests to fix errors, according to the internal documents. The system incorrectly calculated the percentage of election commissions that had submitted reports and produced values exceeding 100%; errors occurred while determining winners in multi-member districts and while generating the voting records.
In the region of Bashkortostan, deceased individuals have appeared on voter lists on several occasions. The most recent report on this issue was received on August 31. It is unknown whether the problem had been resolved before the election began. There were also candidate verification issues: the Bank of Russia reports would not arrive, and inaccurate tax information based on tax data would not be successfully generated.

To resolve some of the issues, developers changed the database manually, bypassing the standard protocols. Manual edits were performed during the testing process, but it remains unclear how such problems will be addressed during actual elections and who will be authorized to edit the result fields in the database.
This is just one of the potential vulnerabilities in the system.
The structure and vulnerabilities of the system
Doubts about the integrity of Russian election results have existed for a long time. As far back as 2011, Sergei Shpilkin’s calculation of fabricated votes cast in favor of pro-government candidates went viral.
Eight years later, Moscow tested the electronic remote voting system developed by the Moscow City Hall’s IT department for the first time, and this raised more questions: observers could not verify that the electronic votes had not been tampered with at any stage, or that voters had cast their ballots in person and did it voluntarily. At the same time, Rostelecom developed another remote voting system — a federal one — for other regions. In the September 2026 State Duma elections, the federal remote voting system will be used in 32 regions.
IStories examined the operation of the GAS Vybory 2.0 system, including the components involved in compiling voter rolls, interacting with the remote voting systems, and counting the votes. At our request, the documents from the Tsifrotek leak were also examined by Ivan Shukshin, an election analyst, and two technical experts who requested to remain anonymous. Together we identified the main vulnerabilities in the system the Central Election Commission could exploit to influence election results.
Our analysis is based on the documents and the module code available to us. It is possible that, as of the time of publication, the system’s components may function slightly differently than it was described there.
Vulnerability #1: tampering with the results
After the votes are counted at the polling station, the election commission prints and signs the final document containing the results. The voting results can then be entered into the GAS Vybory 2.0 system in two ways: automatically (by scanning a QR code or uploading a PDF file) or manually.
According to the documentation, manually entered data is not cross-checked against the original documents. However, results uploaded to the GAS Vybory 2.0 via a QR code can also be edited manually. The system stores previous versions of the documents and the username of the user who made the changes.
It was the loose treatment of the result transferring process that made it possible to rig the results at a polling station in Saratov in 2024. At that time the old Elections system was still in use. Vladimir Putin received 300 more votes than the local commission had recorded in their voting results documents. More than two hundred unused ballots were rewritten in his favor, while the number of spoiled ballots and votes for other candidates was underreported.
“Our election law states that results must be published at all polling stations; they’re always public,” explains a Tsifrotek developer interviewed by IStories. “Next, the final aggregate results must be published. Given that we now have AI, having the AI verify everything isn’t a problem at all. If someone wants to change something, it will be easy to spot.”
The results are indeed published in electronic format on the TsIK website. However, this data does not let one verify that the published results match the signed physical documents (which can also be falsified).
According to the discussions in the Tsifrotek chat, the result calculations in the system raises doubts among the developers as well: “Colleagues, you’ve apparently been working with TsIK for a long time now — why would anyone at a polling station need to assign or manipulate [votes] when there’s the wonderful PAIP, which aggregates the data and produces the results, and no one knows how it does it?” one of the developers wrote.
Vulnerability #2: voter list manipulations
In the leak, IStories discovered the data on 111.3 million voters from the RUIP register — including their names, dates of birth, residential addresses, and the polling stations to which they are assigned. This suggests that developers — and likely the election commission staff as well — can export unencrypted personal data of Russian citizens.
“Security experts were very concerned that personal data was being transmitted in plain text, with no one encrypting it,” one of the developers involved in the project told us. “There are opportunities for leaks, and there are a lot of them.”
The metadata from the voter files indicates that the data was uploaded in July 2026. The numbers of voters broken down by region largely match the Central Election Commission’s figures as of July 1 — discrepancies do not exceed 1%, except for the territories annexed in 2022 .
We compared the voter lists from the leak with the civil registry offices’ death registration data since 2022, which was provided by the Manticore project. According to our estimates, the data from the GAS Vybory 2.0 system included at least 104,000 people declared deceased in the occupied territories, including Crimea, as well as in the Kursk and Bryansk Oblasts.
The process of preparing voter lists for remote voting is one of the vulnerabilities in this subsystem. According to the documentation for the nationwide training session on using the GAS Vybory 2.0 system, system administrators at the territorial election commissions can manually enter applications for remote electronic voting into the database.
With direct access to voter rolls, system users could likely artificially inflate the number of e-voters. Such manipulation may have occurred in 2021, when several people interviewed by Meduza were surprised to discover that they had been registered for remote voting without their knowledge.


After the application file is uploaded, the system checks its structure, its compliance with reference databases, and whether the voters are present in the RUIP database. However, the origin of the file is not tracked: a user with privileged access can manipulate the voter list — according to the documentation available to us, no digital signature is required to upload it.
Vulnerability #3: remote electronic voting
The remote electronic voting (DEG) system is a “black box,” and observers can only evaluate its actual operation based on official statements from the developers. Two remote electronic voting systems will be used in the 2026 elections: the federal system and the Moscow system.
Tsifrotek is not involved in the development of either the federal or the Moscow remote electronic voting systems. The GAS Vybory 2.0 system receives votes that have already been processed from the blockchain. However, in their documentation Tsifrotek clarifies that the term “blockchain” in this case does not correspond to its generally accepted meaning, and they cannot guarantee that the remote electronic voting system operates exactly the way it was explained to them.

Results from the remote voting system are exported as a ZIP archive containing XML files, which must correspond to files with electronic signatures. In this case, altering the results in the XML file is supposed to trigger an error during verification. The archives containing the results are then uploaded to the GAS Vybory 2.0 system: the federal one to the MV DEG module; the Moscow one, to the MV Moscow module.
According to the DEG MV documentation, when a result archive is imported, a verification process starts: each XML file must have a corresponding signature file. It is unknown whether this process actually works as described.

However, the code for the MV Moscow component, where electronic voting results from the capital are uploaded, contains a significant vulnerability. The system locates the signature files but does not verify them, allowing files containing results to pass through even if they are not confirmed by an electronic signature. When the remote voting results reach the protocol, the system does not record the fact that the original results were not backed by an electronic signature.

“There’s no point in talking about vulnerabilities, because this software doesn’t record votes, it processes the finalized results, and those can be altered at every step: files can be manually edited, and changes can be made in the database after they’re imported,” a technical specialist who analyzed the MV Moscow module code told IStories. In his opinion, for the system to be trustworthy, its components must be independent: “If all of this is happening within Rostelecom, will Rostelecom argue with itself about fraud?”
Is the updated GAS Vybory 2.0 system trustworthy? Developers weigh in
The people who created the new version of Russia’s election platform have mixed views on whether its results can be trusted.
Some sincerely believe in the project: “I have a great deal of confidence in the new system. We’re building a fair tool that lets people vote however they want,” says one of our interviewees. “As for what happens outside the system, we can only speculate. I believe the system calculates [the election results] correctly. Then we look at the results, and everyone starts shouting, ‘It’s fraud!’ For me, this isn’t fraud, but the sad truth, unfortunately: apparently, [the election results] reflect the will of the people.”
“I still think that the fairer results wouldn’t affect anything. It’s just that, apparently, the number isn’t actually 80, but rather 60 [percent of those voting for ‘United Russia’],” he adds. “I did what I could to make an impact on my end. But from here on, it all depends on the people.”
Another Tsifrotek source interviewed by IStories disagrees: “You can rig or steal the votes in any system you have access to. As far as I’m concerned, the outcome is clear to everyone — we know who will win the election and who won’t.”
At the training sessions where developers tested the system, the outcome was also known in advance — the majority of seats went to the “United Russia” party.

Technology & Business Editor