hope 400Walking Is Not a Crime: ZHRO's Walk for Freedom Targeted by Automated Attack

For ten years, members of the Zimbabwe Human Rights Organisation have walked for freedom, from Brighton to Hampton Court, through the streets of Leeds and Blackburn, and most recently along the coast from Scarborough to Whitby. We walk peacefully, in the open, to keep the plight of Zimbabwe's people in view. It now appears that someone has gone to considerable trouble to make that work look unwelcome.

Our website lets readers rate each article from 1 to 5. Few of our readers ever used it. Most of our articles have only a handful of ratings, many of them from our own members. Then we noticed something very different happening to a particular group of articles.

Thirty articles, about 6,400 fake votes

Our database shows that 30 articles have each received between 100 and 267 votes, almost all of them the lowest possible score. In total, around 6,400 such votes have been cast. No other article on our site has ever received more than nine.

The targeted articles span our entire history, from "ZHRO – Getting Started", our first article in 2016, through our 2017 walk report, the 2021 petitions to Downing Street, our 2022 approaches to the FCDO, BBC, AU and SADC, and our 2023 articles on the right to vote, to this year's Walk for Freedom reports and the petition we delivered to 10 Downing Street in May. They have one thing in common: each deals with the Walk for Freedom, our petitions, elections, or the abuses of ZANU-PF.

Our records show how many votes each article received but not when they were cast, so we cannot say how long this has been going on. What we can say is that someone has worked systematically through ten years of our archive, choosing precisely the articles that speak most directly about Zimbabwe's government.

How it was done

Our server logs show the attack in action. Between 18 and 22 September 2026, a single Walk for Freedom article received more than 5,700 automated vote submissions, at times almost one per second.

It began from one computer. In just twenty seconds, that machine submitted 28 votes while pretending to be 22 different devices: Windows, Mac and Linux, running Chrome, Firefox, Edge, Opera and Safari. A real computer cannot be a Windows PC and a Mac in the same second. The disguise was generated by software.

The method then changed. Almost every submission came from a different internet address, routed through a proxy network designed to hide its true origin and to defeat our website's protection against repeated voting. But the addresses were far less varied than they seemed: nearly all came from just five or six blocks of addresses.  Not one claimed to be a mobile phone, although most of our real readers visit on their phones.

These same address blocks appear on all thirty targeted articles in our database, going back to 2016. This is one operation, not thirty coincidences.

Our response

When the attack became apparent, UK-based members of ZHRO added 5-star votes to some of the recent articles. We mention this openly: those votes are easily told apart from the attack and do not change the picture. We have since switched voting off altogether, preserved our server records and database, and reported the matter to the Foreign, Commonwealth and Development Office.

This was not a disgruntled reader. It was an organised, resourced and persistent operation, aimed at ZHRO's peaceful campaigning over a whole decade. We cannot say from the records alone who is responsible, and we will not claim more than the evidence shows. Zimbabweans can judge for themselves who has an interest in making a human rights organisation look unpopular, and who has long experience of rigging votes.

We draw one lesson from this. Nobody spends this much effort discrediting work that nobody reads. Our walks, our petitions and our writing are being noticed. That is a reason to continue, and the next Walk for Freedom will go ahead. We invite every supporter to join us.