Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing
Russian banks and financial organizations are required to freeze operations on the domestic accounts of Telegram founder Pavel Durov after his inclusion in the Rosfinmonitoring list of terrorists and extremists. The measures focus mainly on his personal finances and assets located in Russia, according to attorney Dmitry Roshchin.
At the same time, Telegram is not automatically designated as a prohibited or extremist resource. Under Russian law the messaging service and its founder remain separate legal subjects, as clarified by Izvestia.
The situation with money transfers to Durov is more nuanced. The mere act of sending funds does not equate to financing terrorism. Establishing criminal liability would require evidence that the money was intended specifically for terrorist activity, Roshchin emphasized.
Rosfinmonitoring added the entrepreneur to the list on 30 July. Earlier the FSB charged him with aiding terrorist activity and placed him on an international wanted list. The agency claims Telegram administration failed to delete channels, chats and bots allegedly used by Ukrainian special services to prepare sabotage, terrorist acts, mass killings and cyberattacks in Russia. Durov has not yet been found guilty; only a court can make that determination.
Related articles
Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps
The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.
Google's Android Developer Verification Rollout: Implications for Russian Devices and MDM-Managed Phones
Google is introducing mandatory Android Developer Verification on certified devices starting in select countries in September 2026, requiring developers to register and sign apps with verified identities. The policy aims to curb fraudulent and malicious applications by linking package names to registered developer signatures checked via the new Android Developer Verifier system component. Devices without Google services, including many Russian and Chinese firmware builds as well as AOSP variants, remain completely unaffected since the verification mechanism relies on Google Play services. Russia is explicitly excluded from the initial rollout and subsequent waves due to sanctions, allowing continued distribution of in-house and third-party applications. Corporate MDM deployments are also exempt because administrators are considered to have already vetted the apps for safety. Google plans to offer both full registration requiring D-U-N-S numbers for organizations and a limited option for hobbyists capped at 20 devices. The company has already registered SafeMobile as a verified developer, ensuring seamless installation of its client on supported devices.
Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue
A large software development company transformed its approach to information security awareness by replacing formal policy sign-offs and portal documents with an interactive Welcome Training program. The 45-minute in-person sessions target developers, analysts, testers, product managers, and designers, focusing on real-world context, attack mechanics, and personal relevance rather than prohibitions. Training covers global and local threat landscapes, password policies, corporate email usage, sensitive data storage with VeraCrypt, secure credential sharing via pbin, file verification with VirusTotal, and social engineering defense. It also highlights existing corporate tools including Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM systems to emphasize layered protection. The format has increased engagement, improved retention of guidelines, fostered conscious compliance, and noticeably reduced incidents stemming from human error. The company stresses that technology alone fails without employee understanding of why rules matter.
Russian Ministry Clarifies No Plans to Disable Apple iPhones Despite New Device Registry
The Russian Ministry of Digital Development has officially stated that no government body or telecom operator has the authority to remotely disable iPhones or other devices from specific manufacturers. The clarification was issued in response to an inquiry from deputy Vladimir Plyakin regarding rumors of potential restrictions if Apple fails to comply with Russian legislation. Current laws do not permit turning user devices into non-functional bricks through any centralized mechanism. However, amendments to the law On Communications will introduce a national registry of user equipment identifiers starting March 1, 2027. The ministry is still developing the regulatory framework for this database, including what data will be collected and which agencies will have access. Officials emphasized that the existence of the registry does not imply any capability for mass device deactivation at this stage.