AntiMalware•October 6, 2026•🇷🇺Translated from Russian

Russia Plans Additional Security Checks for Gosuslugi Portal Access

Prime Minister Mikhail Mishustin has instructed the Ministry of Digital Development to explore additional security measures for accessing the Gosuslugi portal and recovering accounts. The portal already serves 120 million users, making reliable protection of their accounts a priority.

The directive was announced during the “Digital Solutions” forum. Specific details on the nature of the new checks and their rollout timeline have not yet been disclosed. The ministry is still required to formulate and propose a workable mechanism before any concrete changes can be introduced.

At the same time, the Ministry of Digital Development is preparing a third package of measures aimed at combating cyber fraud. One of the key proposals involves creating a unified platform within Gosuslugi for managing consents to personal data processing. Through this platform, users would be able to see which organizations are using their data, including information obtained offline, revoke previously granted consents, and report suspected violations to supervisory authorities.

Ministry of Internal Affairs officials have cautioned that fraudsters are already capitalizing on discussions around account security. They are sending messages that threaten account blocking or data leaks and prompt recipients to call a listed phone number immediately. Such calls may result in the account being taken over rather than protected.

Related articles

Securitylab•Policy & Regulation

Entering Cybersecurity Without a Specialized Degree: Sector Rules and Practical Entry Points

The article examines whether a specialized higher education diploma is necessary to start a career in information security. It breaks down three main industry segments—state security structures, regulated government organizations, and private business—and explains the differing formal and practical requirements in each. In government-related roles, candidates must meet strict regulatory standards for education and approved programs. Private companies instead focus on demonstrable technical skills in networks, Windows Server, Linux, and security tools. The piece also covers typical junior engineer expectations, real-world career paths from unrelated backgrounds, and four key ways to prove competence without a diploma. It concludes with advice on building home labs, troubleshooting skills, and accessing open training resources like the CyberED course.

AntiMalware•Policy & Regulation

MTS, MegaFon and Beeline Must Temporarily Suspend Radio Equipment at FSO Request Under Extended Frequency Licenses

Russian telecom operators MTS, MegaFon and VimpelCom (Beeline) have received extensions for their radio frequency allocations until 31 December 2027, but the licenses now include a binding requirement to pause operations of radio-electronic equipment upon demand from the Federal Security Service (FSO). The State Commission for Radio Frequencies (GKRCH) added this condition during its 31 August meeting, directly linking compliance with FSO instructions to the continued use of spectrum originally allocated in 2006. The measure applies during security operations, high-priority state activities and special FSO events, potentially causing temporary loss of mobile connectivity for subscribers in affected areas. Although FSO powers to request such suspensions have existed since 2011, the new decision embeds the obligation explicitly into the frequency license terms. At the same time, the operators retain earlier commitments to expand network coverage to all settlements with at least 2,000 residents by 31 March 2027. The dual requirements illustrate how spectrum policy now balances nationwide connectivity goals with operational readiness for temporary shutdowns ordered by security authorities.

AntiMalware•Policy & Regulation

Russia Discusses Extra Fees for International Traffic Over 50 GB in 5G Networks

The Russian Ministry of Digital Development is again in talks with mobile operators about introducing charges for international data traffic exceeding 50 GB per month, but only within 5G networks. The measure would potentially apply to VPN services and other foreign resources, adding to users' mobile bills. No final decision has been reached and the exact fee amount remains unspecified. Sources indicate a possible launch in October, though timelines are subject to change. Technical challenges arise because current 5G deployments rely on LTE infrastructure, requiring new traffic separation, network handover tracking, and billing system adjustments. Average monthly mobile data usage stood at 24 GB in 2025, making the 50 GB international 5G threshold a narrow scenario. Headlines claiming VPNs will become paid services overstate the current discussions, which focus solely on international traffic classification.

Habr•Policy & Regulation

Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices

A Russian developer building a contract-processing service discovered that his website was silently sending visitor data to foreign companies despite keeping all contract data on Russian servers. The site used Vercel for hosting, Google Fonts across 33 pages, and Cloudflare's cdnjs for PDF and Word libraries, exposing IP addresses, browsers, and browsing history. Under Russia's 152-FZ, such transfers require a separate notification to Roskomnadzor, and the United States and EU are not on the list of countries with adequate protection. The developer migrated fonts and libraries to his own Russian server, moved hosting domestically, and updated his privacy policy after a single console command revealed the external domains. The case highlights how common web practices like loading Google Fonts or using CDNs can trigger strict data localization and notification rules, with fines reaching millions of rubles for violations.