AntiMalwareJuly 30, 2026🇷🇺Translated from Russian

Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps

The Russian Ministry of Digital Development (MinTsifry) has put forward a proposal that would force foreign websites and mobile applications to authenticate users inside Russia solely by mobile-phone number. Traditional login methods such as email or social-network accounts could be removed under the new rules.

The requirement appears in the draft third package of anti-fraud measures titled Antifraud 3.0, according to business daily Vedomosti. In addition to phone-based authentication, owners of overseas resources would have to store registration data, login records and account-deletion information for three years and supply these records to Russian law-enforcement bodies on request.

The changes are intended to be introduced into Article 8 of the federal law On Information. The draft is currently undergoing inter-agency coordination; the government aims to submit the full legislative package to the State Duma in autumn 2026.

Industry observers note that international companies may be reluctant to redesign their authentication systems for a single market. They would need to identify Russian users and implement a separate login flow, an effort some services may decide is not worth the cost. As a result, certain platforms could withdraw from Russia, while some users may choose not to register at all if a phone number is mandatory.

A further complication concerns the definition of a foreign resource operating in Russia. Services such as Facebook and Instagram, both owned by Meta, have already been blocked and declared extremist organisations; their legal operation in the country has ceased, making enforcement of the new obligations practically difficult.

Antifraud 3.0 contains additional provisions, including a ban on disclosing the recipient’s personal data in SMS messages and an expansion of the data sets that telecommunications operators must retain for three years and disclose to special services.

Related articles

HabrPolicy & Regulation

Google's Android Developer Verification Rollout: Implications for Russian Devices and MDM-Managed Phones

Google is introducing mandatory Android Developer Verification on certified devices starting in select countries in September 2026, requiring developers to register and sign apps with verified identities. The policy aims to curb fraudulent and malicious applications by linking package names to registered developer signatures checked via the new Android Developer Verifier system component. Devices without Google services, including many Russian and Chinese firmware builds as well as AOSP variants, remain completely unaffected since the verification mechanism relies on Google Play services. Russia is explicitly excluded from the initial rollout and subsequent waves due to sanctions, allowing continued distribution of in-house and third-party applications. Corporate MDM deployments are also exempt because administrators are considered to have already vetted the apps for safety. Google plans to offer both full registration requiring D-U-N-S numbers for organizations and a limited option for hobbyists capped at 20 devices. The company has already registered SafeMobile as a verified developer, ensuring seamless installation of its client on supported devices.

HabrPolicy & Regulation

Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue

A large software development company transformed its approach to information security awareness by replacing formal policy sign-offs and portal documents with an interactive Welcome Training program. The 45-minute in-person sessions target developers, analysts, testers, product managers, and designers, focusing on real-world context, attack mechanics, and personal relevance rather than prohibitions. Training covers global and local threat landscapes, password policies, corporate email usage, sensitive data storage with VeraCrypt, secure credential sharing via pbin, file verification with VirusTotal, and social engineering defense. It also highlights existing corporate tools including Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM systems to emphasize layered protection. The format has increased engagement, improved retention of guidelines, fostered conscious compliance, and noticeably reduced incidents stemming from human error. The company stresses that technology alone fails without employee understanding of why rules matter.

AntiMalwarePolicy & Regulation

Russian Ministry Clarifies No Plans to Disable Apple iPhones Despite New Device Registry

The Russian Ministry of Digital Development has officially stated that no government body or telecom operator has the authority to remotely disable iPhones or other devices from specific manufacturers. The clarification was issued in response to an inquiry from deputy Vladimir Plyakin regarding rumors of potential restrictions if Apple fails to comply with Russian legislation. Current laws do not permit turning user devices into non-functional bricks through any centralized mechanism. However, amendments to the law On Communications will introduce a national registry of user equipment identifiers starting March 1, 2027. The ministry is still developing the regulatory framework for this database, including what data will be collected and which agencies will have access. Officials emphasized that the existence of the registry does not imply any capability for mass device deactivation at this stage.

AntiMalwarePolicy & Regulation

Russia's Top Investigator Proposes AI, VPN and Other Technologies as Aggravating Circumstances in Criminal Code

Alexander Bastrykin, head of Russia's Investigative Committee, has put forward a bill that would treat the use of artificial intelligence, VPN services and other information technologies as an aggravating factor when sentencing offenders. The proposal aims to address the growing role of digital tools in crimes ranging from fraud and data trafficking to terrorism, murder and sexual offences. Current Russian law lacks a universal provision allowing courts to factor in the deployment of such technologies during punishment decisions. Bastrykin argued that embedding specific technologies into dozens of Criminal Code articles would be inefficient because the IT landscape evolves too rapidly for static legal language. Instead, the committee advocates a systemic approach that recognises technology as a distinct aggravating circumstance when it serves as the primary instrument of the crime or significantly amplifies the harm caused. The measure would not criminalise the mere possession or activation of a VPN, smartphone or AI model; it would apply only when these tools materially enable or scale criminal activity. The bill has already been prepared by the Investigative Committee and was outlined in an interview with Interfax.