On September 30, 2026, Russia's Ministry of Digital Development (Mintsifry) opened its 'Antifraud 3.0' package for public discussion. According to The Moscow Times' Russian service, citing Kommersant, the draft would require hosting providers to identify clients and the purpose of each physical or virtual server. They would check clients against a Roskomnadzor registry of VPN and proxy owners. They could not supply listed owners with servers for up to one year. They would also have to terminate service when law enforcement or critical-infrastructure organizations ask.
The case for the regulator
The strongest argument for the package is the fraud problem it is named after. Phone scams and account takeovers cost real people real money, and fraudsters do rent servers to hide infrastructure. Any state could reasonably ask hosts to know their customers and to respond to takedown requests during an active cyberattack. Know-your-customer duties for hosting are not exotic. Several democracies debate similar obligations for abuse handling.
But this draft does not stop at fraud. Its VPN section is tied to a different legal hook: Article 15.8 of the information law.
What Article 15.8 actually targets
Federal Law No. 276-FZ of July 29, 2017, catalogued by WIPO Lex, added Article 15.8 to the information law. It obliges operators of circumvention tools to connect to a federal blocking system and enforce the blocklist, or face being blocked themselves. As Dechert noted at the time, the law did not restrict VPNs per se. It aimed at VPNs that provide access to prohibited resources.
The Moscow Times report says the registry covers services that violate Article 15.8. So the new regime would not be about fraud detection. It would extend a censorship-enforcement rule from the VPN operator to the company that rents the operator its machines. A VPN operator that refuses to filter is already blockable. The draft adds a second choke point: it denies the operator a domestic server.
From intermediary to controller
Meduza, reporting on an earlier version of the idea, described the shift as moving hosts from 'technical intermediary' to 'controller'. A technical intermediary reacts to complaints. A controller must proactively prevent service. That distinction matters for liability. Once a host must judge what a customer's server is 'for', it faces penalties for guessing wrong. The rational response is over-compliance: refuse anything that looks like a tunnel, a proxy, a corporate gateway or a privacy tool.
The collateral damage is predictable. Russian businesses use VPNs to link offices and protect remote staff. Roskomnadzor has already told operators of private networks to stop using foreign encryption protocols and invited businesses to appeal with protocol, IP and purpose data. A hosting rule that requires purpose-of-server declarations pushes that same disclosure into every rental contract.
Why this belongs in a surveillance story
The draft arrives after a year of escalation. Expert.ru reported that 439 VPN services had been restricted by mid-January 2026, and that blocking expanded in December 2025 to the SOCKS5, VLESS and L2TP protocols. Lantern's research corpus recorded 469 blocked services by February 2026 and a shift from blocking individual services to blocking whole protocol categories.
That shift explains the hosting move. Once protocols are fingerprinted at the network level, the remaining circumvention tools hide inside ordinary-looking traffic from ordinary servers. The state's next lever is the supply side: where those servers live and who knows what is running on them. A client-identity and purpose log held by every host is also a surveillance asset. Together with SORM interception equipment installed at operators and the traffic filtering used for blocking, it narrows the places a Russian internet user can be anonymous. The draft's 'terminate on request' clause, available to law enforcement without a stated judicial step in the reporting we reviewed, removes a further check.
Does it work?
The evidence says blocking raises the cost of circumvention but drives demand rather than ending it. Expert.ru cites figures showing the user base of the top-five VPN services grew from 247,000 to over 6 million in Q3 2025. Lantern cites an estimate that VPN users are no less than 40% of the population. A registry-and-hosting rule will be evaded by moving to foreign hosts, which the draft cannot reach, while domestic legitimate users lose options. The mechanism for detecting VPN use and the criteria for listing clients were, according to coverage of an earlier version, left unspecified.
A proportionate alternative
A pro-innovation approach would separate the fraud problem from the access-control problem. Targeted obligations are defensible: act on court-ordered or well-documented fraud complaints, preserve narrow records, and notify affected customers with a path to appeal. They should be scoped to fraud, bound by judicial oversight, and not keyed to a censorship registry. Mixing the two means every fraud-prevention duty inherits the over-breadth of the blocklist.
The draft is still in public discussion on the federal portal for draft legal acts. Industry comments, particularly from hosts asked to become enforcers without clear criteria, will show whether the VPN section survives. Outside Russia, the lesson is general: when intermediary liability shifts from reacting to complaints to policing customers' intent, the intermediaries stop serving the open internet and start protecting themselves.