Initial results of the investigation into the voting of The Voice Kids presented to Channel One

Group-IB has provided Channel One Russia with the results of the first stage of its forensic investigation. Group-IB experts have analyzed the infrastructure used for the technical support of the online voting during Season 6 of The Voice Kids, as well as the IVR and SMS traffic in search of potential automated spamming programs and other technological methods of vote manipulation in the winner selection process. Channel One and Group-IB provided the first documented results of the audit to the Dutch-based company Talpa Media, which owns the rights to the show The Voice.

During the first stage of the investigation, Group-IB established that the SMS and IVR traffic data received by the company aggregating calls and SMS messages, and the voting results displayed during the final of The Voice Kids are identical. Group-IB specialists concluded that the voting system had not been interfered with neither by external cyber-attackers nor by insiders with the purpose of altering the results of the vote.

The analyzed traffic revealed massive automated SMS spamming in favor of one of The Voice Kids participants. That said, a technical problem arose on the side of the persons involved in the massive vote manipulation, which resulted in a piece of code designed to automate the sending of messages being included into the text messages in the form of «07 31: 2019-04-26 22:47:31», where 07 is the participant’s number. In total, about 300 phone numbers were involved in this manipulation, with more than 8,000 SMS messages sent from these numbers. All the phone numbers belong to the same mobile operator with the same rate plan used. The involved numbers were out of service at the time of investigation.

As part of the investigation, all voting regions were ranked. One of them was unusually active immediately after the start of the voting. The study shows that the IVR calls were made using automated programs. In particular, calls were made from unique numbers following in a row (for example, 8 (XXX) XXX-XX-38, 8 (XXX) XXX-XX-39, 8 (XXX) XXX-XX-40, 8 (XXX) XXX- XX-41 and others.). More than 30,000 calls were received from such numbers in support of one of the participants.

The results of the audit of the security of the show’s voting system have not been disclosed. All violations revealed at this stage are part of a comprehensive examination and will be complemented with further results of the investigation. Group-IB continues to work on the project and will finish the investigation by the end of this month.

Group-IB will not disclose the information on the regions where the unusually active voting was recorded, until the final report is published. Information about the voting process in the regions that is published by anyone other than Group-IB or Channel One, cannot be considered valid.

Channel One Russia reached out to Group-IB experts to conduct an independent investigation in order to assess the vote counting system’s security and perform a technical and forensic analysis of the calls and text messages in search of any anomalies, use of automated voting tools, and other technological methods of unfair competition among participants. The investigation does not assess the use of endorsements, or the ethical side of the issue.

About Group-IB

Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations.

Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities.

Group-IB’s decentralized and autonomous operational structure helps it offer tailored, comprehensive support services with a high level of expertise. We map and mitigate adversaries’ tactics in each region, delivering customized cybersecurity solutions tailored to risk profiles and requirements of various industries, including retail, healthcare, gambling, financial services, manufacturing, crypto, and more.

The company’s global security leaders work in synergy with some of the industry’s most advanced technologies to offer detection and response capabilities that eliminate cyber disruptions agilely.

Group-IB’s Unified Risk Platform (URP) underpins its conviction to build a secure and trusted cyber environment by utilizing intelligence-driven technology and agile expertise that completely detects and defends against all nuances of digital crime. The platform proactively protects organizations’ critical infrastructure from sophisticated attacks while continuously analyzing potentially dangerous behavior all over their network.

The comprehensive suite includes the world’s most trusted Threat Intelligence, The most complete Fraud Protection, AI-powered Digital Risk Protection, Multi-layered protection with Managed Extended Detection and Response (XDR), All-infrastructure Business Email Protection, and External Attack Surface Management.

Furthermore, Group-IB’s full-cycle incident response and investigation capabilities have consistently elevated industry standards. This includes the 77,000+ hours of cybersecurity incident response completed by our sector-leading DFIR Laboratory, more than 1,400 successful investigations completed by the High-Tech Crime Investigations Department, and round-the-clock efforts of CERT-GIB.

Time and again, its solutions and services have been revered by leading advisory and analyst agencies such as Aite Novarica, Gartner®, Forrester, Frost & Sullivan, KuppingerCole Analysts AG, and more.

Being an active partner in global investigations, Group-IB collaborates with international law enforcement organizations such as INTERPOL, EUROPOL and AFRIPOL to create a safer cyberspace. Group-IB is also a member of the Europol European Cybercrime Centre’s (EC3) Advisory Group on Internet Security, which was created to foster closer cooperation between Europol and its leading non-law enforcement partners.