Skip to main content
explainers

Russia says it’s fighting scammers. Its latest proposals would push VPN services off Russian servers, tie eSIMs to devices, and expand telecom data retention.

Source: Meduza

Fighting fraud has been a major focus of Russian lawmaking in recent years. The country has already adopted two sweeping packages of anti-fraud measures, and the authorities often use the fight against fraud as a pretext to push through repressive measures. This was their justification, for example, for banning voice and video calls on Telegram and WhatsApp. This week, Russia’s Digital Development Ministry published provisions from a third package aimed at telephone and online fraud. It includes another set of major proposals that could impose much tighter restrictions on internet use in Russia. Meduza reviewed the document and breaks down its key proposals.

VPN services would find it harder to use Russian hosting providers

Roskomnadzor, Russia’s communications regulator, would create a separate registry of Russian hosting providers’ customers who use rented computing resources to run proxy or VPN services that help circumvent internet censorship. Individuals or companies found to be circumventing blocks would be barred from signing new contracts with any hosting provider in the country for a full year.

The government would have to establish a procedure for Roskomnadzor and hosting providers to exchange this information.

Federal Law “On Information, Information Technology, and the Protection of Information”

Article 10²⁻¹. Special rules governing hosting providers

5³. The federal executive authority responsible for regulating and overseeing the media, mass communications, information technology, and telecommunications shall maintain, under a procedure established by the Government of the Russian Federation, a registry of persons who use hosting providers’ computing resources to host information and telecommunications networks or information resources (a website and/or webpage on the Internet, an information system, or a computer program) that provide access to information resources or information and telecommunications networks blocked within the Russian Federation under this Federal Law, and whose owners have failed to comply with the requirements of paragraph 1 of part 7 of Article 15⁸ of this Federal Law. The Government of the Russian Federation shall determine what information must be included in this registry.

5⁴. A hosting provider may not supply computing resources for hosting information in an information system permanently connected to the Internet to persons listed in the registry provided for in part 5³ of this Article who apply to the hosting provider within one year of being added to the registry.

Russian hosting providers would have to disconnect customers at the FSB’s request

It is unclear whether, in practice, the security service, which oversees internet blocking, would use this power solely to combat cyberattacks or also against VPNs. The amendment reads:

Federal Law “On Information, Information Technology, and the Protection of Information”

Article 10²⁻¹. Special rules governing hosting providers

12. A hosting provider must cease supplying computing resources upon receiving a request to that effect from an agency conducting criminal intelligence operations or from the organization specified in paragraph 2 of part 2 of Article 5 of Federal Law No. 187-FZ of July 26, 2017, “On the Security of the Russian Federation’s Critical Information Infrastructure,” where necessary to counter cyberattacks.

Companies would have to report their VPN use to Roskomnadzor

The authorities currently allow companies to use VPNs capable of circumventing Russian blocks, provided they meet two conditions:

The company needs the VPN “for technical purposes necessary to its operations”

The company determines in advance which employees will use the VPN

Under the proposal, companies would have to notify Roskomnadzor that they are using VPNs to circumvent blocks, though the notification process remains unspecified. There would also be unspecified requirements for employees with VPN access, along with rules governing its use. The government would draw up these requirements and rules subject to the FSB’s approval.

Federal Law “On Information, Information Technology, and the Protection of Information”

Article 15.8. Measures to counter the use within the Russian Federation of information and telecommunications networks and information resources that provide access to information resources and information and telecommunications networks blocked within the Russian Federation

17. The provisions of this Article shall not apply to operators of state information systems, government bodies, or local government bodies, or to the use of software and hardware that provide access to blocked information resources and information and telecommunications networks, provided that the owners of that software and hardware determine its users in advance and that it is used for technical purposes necessary to the operations of the person using it.

18. The Government of the Russian Federation, with the agreement of the federal executive authority responsible for security, shall establish requirements and rules governing the use of software and hardware that provide access to blocked information resources and information and telecommunications networks in the circumstances specified in part 17 of this Article and by the persons specified in that part. These shall include the procedure for notifying the federal executive authority responsible for regulating and overseeing the media, mass communications, information technology, and telecommunications of the use of such software and hardware, and the content and format of the information to be submitted.

All websites and apps would have to give the FSB users’ registration and login data

The proposed requirement would apply to both Russian and foreign services. They would have to keep records of users’ registrations and every account login for three years. They would also have to give this information to the FSB, with “the information to be supplied and the procedure” still to be determined by the government:

Federal Law “On Information, Information Technology, and the Protection of Information”

Article 8. The right of access to information

10. The owner of a website and/or webpage on the Internet, and/or an information system, and/or a computer program, operating on the Internet within the Russian Federation, where access to information on that website and/or webpage, and/or in that information system, and/or computer program is provided to users who have logged in, must:

2) retain information on users’ account registrations, logins, and account closures for three years after those actions have been completed, and provide that information to authorized government agencies conducting criminal intelligence operations or ensuring the security of the Russian Federation, with the information to be supplied and the procedure determined by the Government of the Russian Federation.

Foreign websites and apps would have to authenticate Russian users exclusively by phone number

Currently, authentication requirements apply only to websites, information systems, and programs owned by Russian citizens or legal entities. They can choose how to authenticate users: by phone number, through the Gosuslugi government services portal, through the Unified Biometric System, or through another Russian system.

Article 13.55 of the Code of Administrative Offenses already allows fines of 500,000 to 700,000 rubles for companies that violate this requirement.

Federal Law “On Information, Information Technology, and the Protection of Information”

Article 8. The right of access to information

10¹⁻¹. A person specified in part 10 of this Article who is neither a Russian legal entity nor a citizen of the Russian Federation must authenticate users located within the Russian Federation using a mobile phone number.

Sole proprietors and private individuals would no longer be able to sell SIM cards on telecom operators’ behalf

Currently, private individuals, sole proprietors, and legal entities can all sell SIM cards if they have an agency agreement with a telecom operator.

The bill proposes removing that right from the first two groups. Only employees of those legal entities, working under employment contracts, would be allowed to sell the cards. Telecom operators would have to verify the information provided about those employees.

Federal Law “On Communications”

Article 44. Provision of communications services

7. Legal entities that are not telecom operators may enter into mobile telephone service contracts and process subscribers’ payments for those services only if they have written agency agreements authorizing them to act on a telecom operator’s behalf. The powers granted under those agency agreements may not be delegated to third parties. Such agency agreements may not be concluded with sole proprietors or private individuals.

For legal entities that are not telecom operators, employees working under employment contracts with those entities shall enter into mobile telephone service contracts and process subscribers’ payments for those services.

A telecom operator must verify the accuracy of information about an employee of the telecom operator or a person acting on its behalf who arranged the signing of a mobile telephone service contract, using the procedure and methods established in paragraph 6 of this Article.

Telecom operators would have to store additional information alongside the traffic data and metadata required by the Yarovaya law

Operators would have to store information “on network addresses and ports” used by a customer when signing a contract for communications services. They would have to keep it for three years. The government has yet to determine “the procedure for storage and the amount of information to be stored.”

It is hard to say exactly why the authorities want this information. Most likely, it would allow them to determine after the fact whether a subscriber had masked their IP addresses with a VPN or proxy servers when signing a contract.

Federal Law “On Communications”

Article 64. Telecom operators’ obligations and restrictions on communications service users’ rights during criminal intelligence operations, measures to ensure the security of the Russian Federation, investigative actions, the detention of criminal suspects and defendants, and the enforcement of prison sentences

1. Telecom operators must store the following within the Russian Federation:

3) information on network addresses and ports used by the subscriber and the telecom operator when concluding a communications service contract over the Internet, including the time the contract was concluded — for three years after those actions have been completed. The Government of the Russian Federation shall establish the procedure for storage and the amount of information specified in this subparagraph to be stored.

Embedded SIM cards would be tied to specific devices

When someone buys an eSIM, their contract with the telecom operator would include the identifier (IMEI) of the specific phone, tablet, or smartwatch they use. When an eSIM is reissued for another device, the contract would apparently be amended at the same time. Most likely, this is intended to deter fraudsters from even attempting to clone their victims’ eSIMs (which is no easy task).

Roskomnadzor would monitor telecom operators’ compliance with this requirement.

Federal Law “On Communications”

Article 44. Provision of communications services

1.1. To conclude mobile telephone service contracts, a telecom operator or a person acting on its behalf must use the following, which must meet requirements established by the Government of the Russian Federation:

Where user equipment (terminal equipment) has an embedded identification module whose information can be modified through software, and that information is needed to identify an individual subscriber and/or user equipment (terminal equipment) on a mobile carrier’s network, the mobile telephone service contract must include information about the user equipment (terminal equipment) in which that identification module will be used, including its identifier.

Where user equipment (terminal equipment) has an embedded identification module whose information can be modified through software, and that information is needed to identify a person using communications services under a subscription held by a legal entity or sole proprietor, and/or user equipment (terminal equipment) on a mobile carrier’s network, information about that equipment’s identifier must be entered into the Unified Identification and Authentication System by the subscriber that is a legal entity or sole proprietor, or, at that subscriber’s discretion, by the communications service user. Before providing communications services using that equipment, the telecom operator must verify that the information is present and accurate by submitting a query to the Unified Identification and Authentication System through the Unified System of Interagency Electronic Interaction.

Max would let users lift self-imposed restrictions and buy a new eSIM

Russians can currently bar themselves from obtaining a new phone number by visiting a telecom operator’s office in person or applying remotely through Gosuslugi. Beginning March 1, 2027, they will be able to block calls from abroad in the same way.

For now, the only way to lift these self-imposed restrictions is to visit a government services center in person. The Digital Development Ministry proposes allowing people to lift them remotely, including through the Max messaging app.

Users would also be able to buy a new eSIM through Max.

Federal Law “On Communications”

Article 44. Provision of communications services

1. Within the Russian Federation, telecom operators provide communications services to subscribers under communications service contracts concluded in accordance with civil law, this Federal Law, and the rules governing the provision of communications services.

Communications service contracts may be concluded over the Internet, except in the circumstance specified in the fifth paragraph of paragraph 1.1 of this Article, provided that an individual, including a sole proprietor, or a legal entity expresses consent through one of the following methods:

[…]

using an enhanced unqualified electronic signature and, in accordance with paragraph 4 of part 3 of Article 1 of Federal Law No. 156-FZ of June 24, 2025, “On the Creation of a Multifunctional Information Exchange Service and Amendments to Certain Legislative Acts of the Russian Federation,” providing information contained in documents establishing a Russian citizen’s identity through the multifunctional information exchange service, provided that, to enable the submission of that information through the multifunctional information exchange service, a photograph of the citizen submitting the information has previously been matched to that citizen’s biometric personal data held in the Unified Biometric System


Article 45. Special rules for providing communications services to citizens

7². The restrictions specified in paragraph 7¹ of this Article on concluding mobile telephone service contracts and on allowing user equipment (terminal equipment) to receive telephone calls originating from a foreign telecom operator’s network and bearing numbers corresponding to a foreign numbering system and plan may be lifted through one of the following methods:

3) using an enhanced unqualified electronic signature and, in accordance with paragraph 4 of part 3 of Article 1 of Federal Law No. 156-FZ of June 24, 2025, “On the Creation of a Multifunctional Information Exchange Service and Amendments to Certain Legislative Acts of the Russian Federation,” providing information contained in documents establishing a Russian citizen’s identity through the multifunctional information exchange service, provided that, to enable the submission of that information through the multifunctional information exchange service, a photograph of the citizen submitting the information has previously been matched to that citizen’s biometric personal data held in the Unified Biometric System;

Foreigners would be able to buy SIM cards online in some cases

Foreigners can currently buy a SIM card only in person at an operator’s office. Since January 1, 2025, they have been subject to a blanket ban on signing contracts remotely. The Digital Development Ministry proposes some exceptions, but it is not yet clear how this provision would work.

The exceptions would be set out in a separate document: the rules governing the provision of communications services, approved by a Russian government decree.

Federal Law “On Communications”

Article 45.1. Special rules for providing mobile telephone services to foreign citizens or stateless persons

2. Mobile telephone service contracts may not be concluded with a foreign citizen or stateless person over the Internet, except in circumstances specified in the rules governing the provision of communications services.

At Meduza, we are committed to transparency about our use of artificial intelligence in the newsroom. The story you’re reading was written by one of our living, breathing journalists and translated from Russian using an AI model configured to follow our strict editorial standards. This translation process is the result of extensive testing and refinements to ensure our English-language coverage is timely and accurate. A Meduza editor reviews every draft before publication.

If you find any errors in this translation, please contact us at [email protected].

To read Meduza’s exclusive content in English, please subscribe to our newsletter.

Denis Dmitriev

Cover photo: Lam Yik / Bloomberg / Getty Images