SecuritylabAugust 12, 2026🇷🇺Translated from Russian

Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications

Mixing work and personal email may seem harmless when a large attachment needs to be sent quickly, but the practice creates lasting security and compliance problems. Corporate mailboxes are managed by the organization, which controls domains, applies filters, maintains backups, and can revoke access upon employee departure. Personal accounts, by contrast, remain fully under individual control even after termination, leaving contracts, client correspondence, and internal documents outside any company oversight.

152-FZ and the Labor Code impose obligations to protect personal data during processing, while 98-FZ governs trade secrets. When work files leave the corporate environment, additional uncontrolled copies appear in mobile caches, tablet downloads, and synchronized cloud storage. Recovering or auditing these copies becomes nearly impossible, complicating incident investigations and regulatory compliance.

Using a corporate address for online purchases, subscriptions, and password recovery also expands the attack surface. The work mailbox receives marketing lists, phishing attempts, and breach notifications, while personal services become dependent on an account the employer can disable at any time. After dismissal, employees lose access to tickets, receipts, and recovery codes tied to the corporate domain.

Security experts recommend clear separation of roles. All client communications, contracts, reports, and internal notifications should stay within the corporate system. Personal registrations, banking alerts, and private correspondence belong exclusively to the individual mailbox. Both accounts must use unique strong passwords and multi-factor authentication to prevent credential reuse from turning a minor leak into a major incident.

If mixing has already occurred, organizations advise locating work messages and attachments in personal accounts, disabling forwarding rules, returning files to approved repositories through official procedures, and notifying security teams when confidential data may be involved. Automatic forwarding between accounts is particularly dangerous because it creates an uncontrolled, persistent channel for sensitive information.

Related articles

AntiMalwarePolicy & Regulation

Yandex Pay App Permanently Removed from App Store Across All Regions Due to Sanctions

The Yandex Pay application has been fully removed from the App Store in every region worldwide. Existing installations continue to operate normally, and the company has confirmed that all client funds remain secure. However, users can no longer download the app or receive updates, prompting Apple device owners to avoid deleting the application. Yandex recommends disabling automatic app updates through iOS settings to prevent any potential loss of functionality. If the app is accidentally removed, the service remains accessible through the web version at pay.yandex.ru, which can be added to the home screen via Safari. The removal occurs amid broader sanctions and information-related restrictions affecting Russian technology services.

AntiMalwarePolicy & Regulation

NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition

The National System of Payment Cards (NSPK) has issued a warning that holders of Russian-issued Visa and Mastercard cards may encounter difficulties when making online purchases. The issues stem from NSPK's ongoing transition to Russian security certificates required for authenticating internet resources and establishing secure connections. NSPK recommends that users proactively replace their existing cards with Mir-branded alternatives to avoid payment failures at critical moments. The move aligns with broader efforts toward import substitution and ensuring stable access to payment services amid international sanctions imposed on Russia since 2022. Mir cards will remain fully functional for both in-store and online transactions without any changes. Foreign browsers may display security warnings when encountering the new Russian certificates, though NSPK stresses that these alerts do not indicate compromised resources or data leaks. The transition is described as standard practice among Russian organizations and will not affect payment security, data protection, or overall service operations.

AntiMalwarePolicy & Regulation

Astra Cloud Launches Attested Secure Cloud to Accelerate FSTEC Compliance for Russian Government Systems

Astra Cloud, part of the Astra Group, has introduced a new "Protected Attested Cloud" service designed for hosting state information systems, personal data systems, medical platforms, and other sensitive environments. The infrastructure has received official attestation under FSTEC Russia Order No. 117 for protection class K1 and Order No. 21 for protection level UZ-1. Customers can leverage the pre-certified platform to speed up their own system attestation procedures by three to five times, although each organization's information system must still undergo separate certification. The service includes certified security tools such as firewalls, antivirus solutions, intrusion detection and prevention systems, trusted boot mechanisms, and SIEM, with all connections required through certified cryptographic channels. The cloud is hosted in a Tier IV data center built on domestic hardware and targets organizations that must meet FSTEC requirements without building their own protected infrastructure. From March 2026, Order No. 117 replaces Order No. 17 and extends obligations to subordinate institutions and companies interacting with the state segment, including 24-hour remediation of critical vulnerabilities.

AntiMalwarePolicy & Regulation

Russia's Ministry of Digital Development to Bind M2M SIM Cards to Devices and Restrict Unauthorized Calls Starting 2027

The Russian Ministry of Digital Development has proposed new regulations requiring companies and individual entrepreneurs to register M2M SIM cards and associated equipment in the ESIA system. The rules, scheduled for launch on September 1, 2027, aim to combat fraud by preventing the misuse of these cards for anonymous calls and mass messaging. Each M2M SIM card will be strictly tied to a specific device, with changes to identifiers allowed only once per month except in cases of loss or damage. Operators will gain access to a unified platform for managing SIM cards, including activation, deactivation, status checks, location tracking via base stations, and service suspension for discrepancies. All relevant data such as owner INN, operator details, equipment type, identifier, and installation address must be submitted through Gosuslugi or operator platforms. Voice calls will be limited to one minute, white lists for contacts can be updated monthly, and mass SMS or auto-dialing will be banned except for authorized senders.