Full Report
Group-IB publishes an analytical report based on the results of a study of audience voting in the finale of the 6th season of the television show “The Voice.Kids”.
Analysis Summary
# Incident Report: Automated Vote Manipulation in "The Voice.Kids" Season 6
## Executive Summary
An independent investigation by Group-IB confirmed large-scale automated vote manipulation during the finale of "The Voice.Kids" television show. The incident involved the use of automated SMS bots and coordinated IVR (Interactive Voice Response) calls to artificially inflate the ranking of a specific contestant (Participant 07). The discovery led to the invalidation of the final results and a televised rerun of the finale to restore integrity.
## Incident Details
- **Discovery Date:** Post-finale (April 2019)
- **Incident Date:** Finale and Grand Finale voting windows (April 26, 2019)
- **Affected Organization:** Channel One (Russia) / "The Voice.Kids"
- **Sector:** Media & Entertainment
- **Geography:** Russia (Specific clusters in Bashkortostan, Leningrad, Kursk, and Ulyanovsk regions)
## Timeline of Events
### Initial Access
- **Date/Time:** April 26, 2019, during the live broadcast voting window.
- **Vector:** Exploitation of the SMS and IVR voting gateways.
- **Details:** Attackers bypassed the "one person, one vote" spirit by using bot farms and specialized software to send bulk communications to the designated short-codes.
### Lateral Movement
- **N/A:** This was not a traditional network intrusion; however, the "movement" involved the coordination of thousands of phone numbers across different regional telecommunications hubs to simulate authentic audience participation.
### Data Exfiltration/Impact
- **Impact:** Over 8,000 SMS messages were sent from approximately 300 phone numbers in the Leningrad region. Additionally, over 30,000 IVR calls were placed using automated scripts from consecutive phone numbers in Bashkortostan.
- **Result:** Participant 07 received a mathematically improbable surge in votes, winning by a significant margin despite having 6x fewer unique voters than the runner-up.
### Detection & Response
- **Detection:** Public outcry and internal system audits flagged statistical anomalies (e.g., 97% regional vote concentration for one candidate).
- **Response:** Group-IB was hired to conduct a forensic audit of the voting logs and telecommunications data.
## Attack Methodology
- **Initial Access:** Bulk purchase/lease of SIM cards and use of VoIP/SMS gateways.
- **Persistence:** Not applicable; attack was time-limited to the broadcast window.
- **Defense Evasion:** Use of diverse regional pools (Leningrad, Bashkortostan, Kursk) to mask the centralized nature of the attack.
- **Collection:** Automated scripts were used to send SMS messages with the text "07" at high frequencies.
- **Impact:** Vote manipulation leading to the subversion of a national competition.
## Impact Assessment
- **Financial:** Significant costs associated with the independent forensic investigation and the production of an unscheduled "Special Edition" finale.
- **Data Breach:** None reported (integrity breach rather than confidentiality breach).
- **Operational:** Disruption of the broadcast schedule and total invalidation of the original finale results.
- **Reputational:** Severe; the show's integrity was questioned by the public, requiring a public apology and transparent reporting of the audit findings.
## Indicators of Compromise
- **Behavioral indicators:**
- Sequential phone numbers (e.g., +7-XXX-XXX-XX01, +7-XXX-XXX-XX02) voting for the same participant.
- 95-97% of all regional IVR calls concentrated on a single contestant.
- Maximum allowable votes (20 per number) reached by thousands of numbers simultaneously.
- Automated SMS logs showing technical signatures of bot-sending software.
## Response Actions
- **Containment:** Verification and isolation of the manipulated vote pools (IVR and SMS).
- **Eradication:** Exclusion of fraudulent votes from the final tally during the audit.
- **Recovery:** Channel One annulled the results and declared all finalists winners in a subsequent broadcast.
## Lessons Learned
- **Key takeaways:** Traditional SMS/IVR voting systems are highly susceptible to bot-farm manipulation if they lack behavioral analysis or rate-limiting based on geographic anomalies.
- **Weaknesses:** The system relied on the cost of a text/call as a barrier to entry, which proved insufficient against a well-funded attacker.
## Recommendations
- **Prevention:** Implement CAPTCHA-like challenges for web voting or utilize biometric/account-linked voting (e.g., via verified government portals).
- **Monitoring:** Real-time monitoring for "bursts" of sequential phone numbers and geographic outliers during live events.
- **Verification:** Require mobile operators to provide anonymized geolocation data in real-time to ensure votes are coming from disparate physical locations rather than a single server rack.