AntiMalwareAugust 11, 2026🇷🇺Translated from Russian

NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition

The National System of Payment Cards (NSPK) has advised holders of Russian-issued Visa and Mastercard cards that they may face complications when attempting online payments. The organization recommends replacing existing cards with Mir alternatives in advance to prevent transactions from stalling at inconvenient times.

The problems arise from NSPK's switch to Russian security certificates. These certificates are used to verify the authenticity of online resources and to establish encrypted connections. The company states that this step will guarantee uninterrupted access to its services and reflects standard practice among Russian entities following the departure of international payment systems in 2022.

Mir cards will continue to function normally for payments both in physical stores and on the internet. In contrast, cards issued under the Visa and Mastercard brands, which exited the Russian market due to sanctions, may experience intermittent issues during online checkout processes.

An additional side effect involves certain foreign web browsers that may fail to recognize the new Russian certificates and display warnings about insecure connections. NSPK emphasizes that such messages result from browser-specific configurations and do not imply that the website has been compromised or that user data has been exposed.

The transition is not expected to impact the security of payments, the protection of personal information, or the reliability of payment services overall.

Related articles

AntiMalwarePolicy & Regulation

Astra Cloud Launches Attested Secure Cloud to Accelerate FSTEC Compliance for Russian Government Systems

Astra Cloud, part of the Astra Group, has introduced a new "Protected Attested Cloud" service designed for hosting state information systems, personal data systems, medical platforms, and other sensitive environments. The infrastructure has received official attestation under FSTEC Russia Order No. 117 for protection class K1 and Order No. 21 for protection level UZ-1. Customers can leverage the pre-certified platform to speed up their own system attestation procedures by three to five times, although each organization's information system must still undergo separate certification. The service includes certified security tools such as firewalls, antivirus solutions, intrusion detection and prevention systems, trusted boot mechanisms, and SIEM, with all connections required through certified cryptographic channels. The cloud is hosted in a Tier IV data center built on domestic hardware and targets organizations that must meet FSTEC requirements without building their own protected infrastructure. From March 2026, Order No. 117 replaces Order No. 17 and extends obligations to subordinate institutions and companies interacting with the state segment, including 24-hour remediation of critical vulnerabilities.

AntiMalwarePolicy & Regulation

Russia's Ministry of Digital Development to Bind M2M SIM Cards to Devices and Restrict Unauthorized Calls Starting 2027

The Russian Ministry of Digital Development has proposed new regulations requiring companies and individual entrepreneurs to register M2M SIM cards and associated equipment in the ESIA system. The rules, scheduled for launch on September 1, 2027, aim to combat fraud by preventing the misuse of these cards for anonymous calls and mass messaging. Each M2M SIM card will be strictly tied to a specific device, with changes to identifiers allowed only once per month except in cases of loss or damage. Operators will gain access to a unified platform for managing SIM cards, including activation, deactivation, status checks, location tracking via base stations, and service suspension for discrepancies. All relevant data such as owner INN, operator details, equipment type, identifier, and installation address must be submitted through Gosuslugi or operator platforms. Voice calls will be limited to one minute, white lists for contacts can be updated monthly, and mass SMS or auto-dialing will be banned except for authorized senders.

AntiMalwarePolicy & Regulation

Russia Simplifies State Support Access for National AI Model Developers

Russian authorities have decided to shorten and clarify the path to government support for developers of large AI models. Following the entry into force of the law on artificial intelligence development, obtaining the status of a national or sovereign model will become easier, with decisions verified through a single set of test tasks. The reference test is planned to be published in open access and updated regularly, allowing developers to know in advance the exact criteria the state will use to evaluate their neural networks. Companies such as MWS AI and T-Bank will be able to apply for the new statuses and associated support measures. Expertise will be entrusted to several organizations that have passed state verification, with the main criterion being Russian company control over the entire model lifecycle rather than the origin of every line of code. The use of foreign components under open licenses will be permitted if the developer can independently modify, develop, and maintain the solution. Bureaucratic procedures will be reduced, missing documents can be submitted after the application, and computing infrastructure must be located in Russia but can be rented. The first areas of mandatory application of domestic models will be education and public services, with key provisions of the law taking effect on September 1, 2026, and requirements for sovereign models on March 1, 2027.

HabrPolicy & Regulation

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The EU Council has extended Regulation (EU) 2021/1232, known as Chat Control 1.0, allowing voluntary scanning of unencrypted messages by providers such as Discord and Gmail until 2028. The measure targets detection of child sexual abuse material but has drawn criticism for its impact on encryption and privacy. A proposed Chat Control 2.0 version under COM(2022) 209 would mandate scanning of encrypted communications, which critics argue undermines end-to-end encryption. The extension passed after a July 2026 European Parliament vote failed to reach the required majority due to absent lawmakers. Investigations revealed lobbying ties between Commissioner Ilva Johansson's office and organizations including Thorn and WeProtect Global Alliance. The European Data Protection Supervisor found that targeted advertising supporting the regulation violated EU data rules.