AntiMalwareJuly 24, 2026🇷🇺Translated from Russian

Sberbank to Terminate Currency and Multicurrency Visa Cards from September 2026 Despite Prior Extensions to 2030

Sberbank will stop servicing currency and multicurrency Visa cards from 1 September 2026, according to an SMS notification sent to clients. The measure affects even those cards whose expiration dates had previously been extended until 2030.

The bank recommended that customers close the affected cards in advance and transfer any remaining funds to other accounts. Cardholders can complete the closure process through the Sberbank Online mobile application by navigating to the card management section, selecting the relevant card, and initiating the closure procedure. Clients who do not use the app must visit a bank branch in person.

Early closure is intended to help customers retain access to their funds and prevent potential delays after the September 2026 deadline. The move also allows Sberbank to avoid long queues of customers holding suddenly obsolete plastic cards.

The decision forms part of the broader withdrawal of Visa and Mastercard from Russian circulation amid sanctions and import-substitution efforts. In early July, Central Bank Governor Elvira Nabiullina stated that the process is continuing, although the regulator has not yet set a final deadline for abandoning international cards.

In May, Alla Bakina, Director of the National Payment System Department at the Central Bank, indicated that Visa and Mastercard must leave the Russian market. Since the payment systems departed, their cards have lost previous functionality, while the National System of Payment Cards continues to spend resources on their maintenance.

Over the past four to five years, the combined share of Visa and Mastercard in Russia has fallen below 17 percent. Banks are replacing them primarily with Mir cards, and the National System of Payment Cards is using economic incentives to phase out legacy plastic.

Related articles

SecuritylabPolicy & Regulation

Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications

Mixing corporate and personal email accounts creates serious security, compliance, and operational risks for both employees and organizations. When employees forward contracts or client data to personal mailboxes to bypass size limits or convenience, copies proliferate beyond company control in phones, backups, and cloud services. After termination, the employer loses any ability to revoke access or audit the data, while personal accounts often lack multi-factor authentication and strong password practices. Russian legislation including Federal Law No. 152-FZ on personal data, the Labor Code, and Federal Law No. 98-FZ on trade secrets requires proper protection of sensitive information. Using work email for shopping, banking, or password recovery exposes the corporate domain to phishing and leaks, while the reverse creates dependency on private accounts for business continuity. The recommended practice is strict separation with unique passwords, MFA on both accounts, and approved corporate channels for file transfer.

AntiMalwarePolicy & Regulation

Yandex Pay App Permanently Removed from App Store Across All Regions Due to Sanctions

The Yandex Pay application has been fully removed from the App Store in every region worldwide. Existing installations continue to operate normally, and the company has confirmed that all client funds remain secure. However, users can no longer download the app or receive updates, prompting Apple device owners to avoid deleting the application. Yandex recommends disabling automatic app updates through iOS settings to prevent any potential loss of functionality. If the app is accidentally removed, the service remains accessible through the web version at pay.yandex.ru, which can be added to the home screen via Safari. The removal occurs amid broader sanctions and information-related restrictions affecting Russian technology services.

AntiMalwarePolicy & Regulation

NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition

The National System of Payment Cards (NSPK) has issued a warning that holders of Russian-issued Visa and Mastercard cards may encounter difficulties when making online purchases. The issues stem from NSPK's ongoing transition to Russian security certificates required for authenticating internet resources and establishing secure connections. NSPK recommends that users proactively replace their existing cards with Mir-branded alternatives to avoid payment failures at critical moments. The move aligns with broader efforts toward import substitution and ensuring stable access to payment services amid international sanctions imposed on Russia since 2022. Mir cards will remain fully functional for both in-store and online transactions without any changes. Foreign browsers may display security warnings when encountering the new Russian certificates, though NSPK stresses that these alerts do not indicate compromised resources or data leaks. The transition is described as standard practice among Russian organizations and will not affect payment security, data protection, or overall service operations.

AntiMalwarePolicy & Regulation

Astra Cloud Launches Attested Secure Cloud to Accelerate FSTEC Compliance for Russian Government Systems

Astra Cloud, part of the Astra Group, has introduced a new "Protected Attested Cloud" service designed for hosting state information systems, personal data systems, medical platforms, and other sensitive environments. The infrastructure has received official attestation under FSTEC Russia Order No. 117 for protection class K1 and Order No. 21 for protection level UZ-1. Customers can leverage the pre-certified platform to speed up their own system attestation procedures by three to five times, although each organization's information system must still undergo separate certification. The service includes certified security tools such as firewalls, antivirus solutions, intrusion detection and prevention systems, trusted boot mechanisms, and SIEM, with all connections required through certified cryptographic channels. The cloud is hosted in a Tier IV data center built on domestic hardware and targets organizations that must meet FSTEC requirements without building their own protected infrastructure. From March 2026, Order No. 117 replaces Order No. 17 and extends obligations to subordinate institutions and companies interacting with the state segment, including 24-hour remediation of critical vulnerabilities.