Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030
Sberbank will stop servicing currency and multicurrency Visa cards from 1 September 2026, according to an SMS notification sent to clients. The measure affects even those cards whose expiration dates had previously been extended until 2030.
The bank recommended that customers close the affected cards in advance and transfer any remaining funds to other accounts. Cardholders can complete the closure process through the Sberbank Online mobile application by navigating to the card management section, selecting the relevant card, and initiating the closure procedure. Clients who do not use the app must visit a bank branch in person.
Early closure is intended to help customers retain access to their funds and prevent potential delays after the September 2026 deadline. The move also allows Sberbank to avoid long queues of customers holding suddenly obsolete plastic cards.
The decision forms part of the broader withdrawal of Visa and Mastercard from Russian circulation amid sanctions and import-substitution efforts. In early July, Central Bank Governor Elvira Nabiullina stated that the process is continuing, although the regulator has not yet set a final deadline for abandoning international cards.
In May, Alla Bakina, Director of the National Payment System Department at the Central Bank, indicated that Visa and Mastercard must leave the Russian market. Since the payment systems departed, their cards have lost previous functionality, while the National System of Payment Cards continues to spend resources on their maintenance.
Over the past four to five years, the combined share of Visa and Mastercard in Russia has fallen below 17 percent. Banks are replacing them primarily with Mir cards, and the National System of Payment Cards is using economic incentives to phase out legacy plastic.
Related articles
.RU and .РФ Registries Stop Disclosing Legal Entity Domain Owners in WHOIS
The domain registries for .RU and .РФ have ceased displaying detailed information about administrators that are legal entities. Previously the WHOIS service revealed the full name of the organization along with its INN tax identification number, but the records now show only the generic term Organization. The change was first noticed on 22 July by Habr user @ifap, who observed that domains previously linked to government bodies such as the Federal Protective Service no longer reveal the actual administrator. Support staff at the Coordination Center attributed the disappearance of data to unspecified technical issues and described the outage as temporary, without providing any timeline or details on the root cause. Observers note that the reduced transparency turns routine owner identification into a lengthy investigation, especially for less prominent domains. One unconfirmed theory suggests the registry is being reconfigured to meet new authentication requirements for domain administrators. It remains unclear whether the previous level of disclosure will be restored or whether the current limited view will become permanent.
Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments
The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.
Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations
The Supreme Court of the Russian Federation has officially recognized the hacker groups Silent Crow and Cyberpartisans BY as extremist organizations and banned their activities in Russia. The closed-door ruling, issued at the request of the General Prosecutor's Office, accuses both groups of conducting joint cyberattacks against Russian and Belarusian critical information infrastructure with the aim of destabilizing the political situation and achieving an unconstitutional change of government. Cyberpartisans BY are described as part of the Belarusian association Supratsiv, which allegedly seeks a violent overthrow of the constitutional order, and are linked to the banned Polk named after Kastus Kalinouski as well as Ukrainian military information-psychological operations units. Silent Crow, previously known as CyberWar and Cyber LegionsUA, is portrayed as a pro-Ukrainian collective of politically motivated hacktivists whose primary objective is to damage Russian state bodies, companies, and critical infrastructure. Both groups are held responsible for attacks on Aeroflot IT systems, Rostelecom databases, Rosreestr servers, and the Belarusian Railway infrastructure. Participation in or support for these organizations now carries legal liability under Russian law.
How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences
The July 2025 Aeroflot cyber incident, claimed by Silent Crow and Belarusian Cyber-Partisans, demonstrated how technical vulnerabilities quickly translate into canceled flights, regulatory investigations, stock market reactions, and direct executive accountability. The article examines the persistent communication gap between CISOs, who focus on metrics like EDR coverage and mean time to detect, and CEOs, who prioritize costs, operational disruptions, revenue loss, and personal liability. Research from EY and Splunk highlights differing perceptions of threats and success measures, while real-world cases such as Marks & Spencer, Jaguar Land Rover, Clorox, Change Healthcare, SolarWinds, and Uber show how contractor weaknesses, missing MFA, and delayed disclosures lead to hundreds of millions in damages and legal actions. Regulatory developments, including SEC charges against CISOs and Russia's 420-FZ with turnover-based fines, further force cybersecurity discussions into the boardroom. The piece provides a practical translation table showing how technical warnings should be reframed using concrete business scenarios and financial impacts. It concludes that both CISOs and CEOs must initiate conversations around unacceptable events, downtime costs, and risk reduction versus post-incident consequences.