Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025
Half a year before May 30, 2025, the economics of data leaks in Russia were straightforward: the maximum fine for a legal entity stood at 100,000 rubles, rising to 300,000 rubles for repeat offenses. Implementing effective protection against leaks through DLP systems, audits, dedicated staff, and processes cost tens of millions of rubles annually, making breaches cheaper than prevention.
Federal Law 420-FZ of November 30, 2024, linked fines to the number of affected data subjects and introduced a turnover-based component for repeat violations under CoAP RF Article 13.11. Storage of unnecessary records suddenly carried direct financial risk because each excess entry became a line item in potential penalty calculations.
In the 18 months since the norm took effect, authorities conducted 52 administrative investigations, drew up 40 protocols, and imposed a total of 2.6 million rubles in fines. Not a single turnover fine has been applied. These figures stand against 1.581 billion leaked records in 2025, equating to roughly one-sixth of a thousandth of a kopeck per record.
The volume of fresh data leaks from Russian companies fell noticeably in the first half of 2026, yet activity on shadow marketplaces increased by almost 60 percent. Several non-exclusive explanations exist: operators now sell databases privately rather than publishing them openly to protect reputation; businesses have learned to conceal incidents because disclosure became costlier than silence; and some real reduction occurred as companies began questioning data retention periods instead of simply buying more DLP tools.
The core insight is that investment decisions are driven by expected loss rather than actual penalties paid. When the potential damage figure L in the risk equation p × L increased by two orders of magnitude, budgets were approved regardless of enforcement statistics. This effect has a limited shelf life: without turnover fines materializing in the next two to three years, the modeled probability will approach zero and budgets will follow.
Direct costs include the administrative fine, external forensics starting at 1.5 million rubles per medium incident, subject notification campaigns, and legal defense against individual claims. Indirect costs, often larger, encompass customer churn, increased customer acquisition expenses, service downtime, diverted team time, and higher future insurance and audit premiums. In a modeled service with 3 billion rubles annual revenue and an 800,000-client base, a conservative 2 percent churn already dwarfs all other loss categories combined.
Over-collection now appears on the balance sheet as an unhedged liability. Reducing retention periods from three years to six months directly lowers both risk exposure and infrastructure spend, delivering measurable ROI that most organizations still overlook in favor of additional security tooling.
Related articles
Russia Authorizes Temporary State Takeover of Unprotected Critical Infrastructure
President Vladimir Putin has signed a decree that empowers the Russian government to appoint temporary managers for critical infrastructure facilities whose owners have failed to ensure adequate security. The measure directly targets operators of objects classified as critical infrastructure who have not met protection requirements. Under the new rules, the state can intervene by installing an interim administrator to oversee operations until security standards are satisfied. This approach aims to prevent potential disruptions or threats arising from insufficiently defended assets. The decree provides a legal mechanism for rapid governmental response without permanent nationalization of the facilities. It reflects ongoing efforts to strengthen oversight of sectors deemed essential to national security and stability.
Microsoft Removes Reinstallation Requirement for Enabling Smart App Control in Windows 11
Microsoft has eliminated the primary restriction on Smart App Control, allowing home users to activate or reactivate the Windows 11 security feature without performing a clean installation of the operating system. Previously, toggling the setting effectively required users to reinstall the entire system. Smart App Control leverages Microsoft's cloud-based reputation system and analyzes digital signatures to block suspicious, potentially dangerous, or unsigned files before execution. The toggle is now accessible through Windows Security under App & browser control. The update is being rolled out gradually via Windows 11 updates, though users who have disabled optional diagnostic data may still need a reset or reinstallation. The feature can interfere with developers and enterprise users working with rare or unsigned tools, as there is no option to whitelist individual blocked applications.
Russian State Operators Must Report Cyber Incidents to FSB Within 24 Hours From September 2026
Starting 1 September 2026, operators of state information systems in Russia will be required to notify the National Coordination Center for Computer Incidents within 24 hours of detecting a cyber incident. The mandate is set out in FSB Order 297 and applies to operators of GIS, information systems of state bodies, state unitary enterprises and state institutions. The order places particular emphasis on incidents involving unauthorized data transfers. Organizations will interact with GosSOPKA through the technical infrastructure of NKTsKI, which will issue an incident identifier upon receipt of the report. The new rules formalize what was previously considered good practice and stem directly from Law 568-FZ adopted in December 2025. The requirement removes any possibility of delaying notification to the FSB.
Trusting Russian Root Certificates and Monitoring Domestic CT Logs
The article examines risks associated with installing Russian root certificates issued by the Ministry of Digital Development. It explains how these certificates, when trusted, enable potential MitM attacks through TSPU infrastructure by allowing on-the-fly issuance of fraudulent certificates for foreign domains. Yandex Browser stands out by enforcing Certificate Transparency checks for domestic certificates, unlike other browsers that disable CT validation in the presence of added roots. Three primary domestic CT logs are maintained by Yandex, VK, and the Ministry, with log lists updated annually. A Python script is provided to query these logs directly and verify SCT inclusion for any certificate. The piece also notes limitations of existing web monitors such as ct.tlscc.ru when dealing with newer log endpoints.