Russia Russia SORM surveillance VPN ban

Russia's Antifraud 3.0 Turns Hosting Companies Into VPN Enforcers and Pushes Surveillance Down the Stack

Mintsifry's Sept. 30 draft would make Russian hosts check clients against a Roskomnadzor VPN registry and cut off listed owners for up to a year.

Russia's VPN Crackdown in Numbers People of Internet Research · Russia 469 VPN services blocked Confirmed blocked by February 2026… 439 Services restricted by January Up ~70% from October 2025. 6M+ Top-5 VPN users, Q3 2025 Up from 247,000. 1 year Proposed hosting ban Maximum bar for registry-listed VP… peopleofinternet.com
Russia's VPN Crackdown in Numbers People of Internet Research · Russia 469 VPN services blocked 439 Services restricted by Ja… 6M+ Top-5 VPN users, Q3 2025 1 year Proposed hosting ban peopleofinternet.com

Key Takeaways

On September 30, 2026, Russia's Ministry of Digital Development (Mintsifry) opened its 'Antifraud 3.0' package for public discussion. According to The Moscow Times' Russian service, citing Kommersant, the draft would require hosting providers to identify clients and the purpose of each physical or virtual server. They would check clients against a Roskomnadzor registry of VPN and proxy owners. They could not supply listed owners with servers for up to one year. They would also have to terminate service when law enforcement or critical-infrastructure organizations ask.

The case for the regulator

The strongest argument for the package is the fraud problem it is named after. Phone scams and account takeovers cost real people real money, and fraudsters do rent servers to hide infrastructure. Any state could reasonably ask hosts to know their customers and to respond to takedown requests during an active cyberattack. Know-your-customer duties for hosting are not exotic. Several democracies debate similar obligations for abuse handling.

But this draft does not stop at fraud. Its VPN section is tied to a different legal hook: Article 15.8 of the information law.

What Article 15.8 actually targets

Federal Law No. 276-FZ of July 29, 2017, catalogued by WIPO Lex, added Article 15.8 to the information law. It obliges operators of circumvention tools to connect to a federal blocking system and enforce the blocklist, or face being blocked themselves. As Dechert noted at the time, the law did not restrict VPNs per se. It aimed at VPNs that provide access to prohibited resources.

The Moscow Times report says the registry covers services that violate Article 15.8. So the new regime would not be about fraud detection. It would extend a censorship-enforcement rule from the VPN operator to the company that rents the operator its machines. A VPN operator that refuses to filter is already blockable. The draft adds a second choke point: it denies the operator a domestic server.

From intermediary to controller

Meduza, reporting on an earlier version of the idea, described the shift as moving hosts from 'technical intermediary' to 'controller'. A technical intermediary reacts to complaints. A controller must proactively prevent service. That distinction matters for liability. Once a host must judge what a customer's server is 'for', it faces penalties for guessing wrong. The rational response is over-compliance: refuse anything that looks like a tunnel, a proxy, a corporate gateway or a privacy tool.

The collateral damage is predictable. Russian businesses use VPNs to link offices and protect remote staff. Roskomnadzor has already told operators of private networks to stop using foreign encryption protocols and invited businesses to appeal with protocol, IP and purpose data. A hosting rule that requires purpose-of-server declarations pushes that same disclosure into every rental contract.

Why this belongs in a surveillance story

The draft arrives after a year of escalation. Expert.ru reported that 439 VPN services had been restricted by mid-January 2026, and that blocking expanded in December 2025 to the SOCKS5, VLESS and L2TP protocols. Lantern's research corpus recorded 469 blocked services by February 2026 and a shift from blocking individual services to blocking whole protocol categories.

That shift explains the hosting move. Once protocols are fingerprinted at the network level, the remaining circumvention tools hide inside ordinary-looking traffic from ordinary servers. The state's next lever is the supply side: where those servers live and who knows what is running on them. A client-identity and purpose log held by every host is also a surveillance asset. Together with SORM interception equipment installed at operators and the traffic filtering used for blocking, it narrows the places a Russian internet user can be anonymous. The draft's 'terminate on request' clause, available to law enforcement without a stated judicial step in the reporting we reviewed, removes a further check.

Does it work?

The evidence says blocking raises the cost of circumvention but drives demand rather than ending it. Expert.ru cites figures showing the user base of the top-five VPN services grew from 247,000 to over 6 million in Q3 2025. Lantern cites an estimate that VPN users are no less than 40% of the population. A registry-and-hosting rule will be evaded by moving to foreign hosts, which the draft cannot reach, while domestic legitimate users lose options. The mechanism for detecting VPN use and the criteria for listing clients were, according to coverage of an earlier version, left unspecified.

A proportionate alternative

A pro-innovation approach would separate the fraud problem from the access-control problem. Targeted obligations are defensible: act on court-ordered or well-documented fraud complaints, preserve narrow records, and notify affected customers with a path to appeal. They should be scoped to fraud, bound by judicial oversight, and not keyed to a censorship registry. Mixing the two means every fraud-prevention duty inherits the over-breadth of the blocklist.

The draft is still in public discussion on the federal portal for draft legal acts. Industry comments, particularly from hosts asked to become enforcers without clear criteria, will show whether the VPN section survives. Outside Russia, the lesson is general: when intermediary liability shifts from reacting to complaints to policing customers' intent, the intermediaries stop serving the open internet and start protecting themselves.

Sources & Citations

  1. WIPO Lex: Federal Law 276-FZ (2017)
  2. Federal Portal of Draft Regulatory Legal Acts (regulation.gov.ru)
  3. The Moscow Times (RU): hosting VPN penalties
  4. Meduza: Kommersant on hosting ban
  5. Expert.ru: 439 VPN services restricted
  6. Lantern: 469 VPN services blocked
  7. Dechert: Russia VPN measures (2017)