Russia Russia SORM surveillance VPN ban

Russia's Retreat From a Phone-Only Login Mandate Doesn't Touch the SORM Machine Behind It

Moscow dropped the Antifraud 3.0 rule forcing foreign sites to ID Russians by phone after experts flagged it as a backdoor into the FSB's SORM system.

Antifraud 3.0's Dropped Rule, By the Numbers People of Internet Research · Russia 3 years Proposed data retention How long foreign platforms would h… 3 Requirements stripped from draft Phone-only login, number verificat… 69 pages SORM technical order length Scope of Order No. 1174, which exp… 439+ VPN services blocked Roskomnadzor's VPN blocklist by mi… peopleofinternet.com
Antifraud 3.0's Dropped Rule, By the N… People of Internet Research · Russia 3 years Proposed data retention 3 Requirements stripped from dr… 69 pages SORM technical order length 439+ VPN services blocked peopleofinternet.com

Key Takeaways

A Narrow Retreat

On August 24, 2026, Russian outlets including Vedomosti and Kabelshchik reported that the Digital Development Ministry had quietly stripped three provisions from the draft third anti-fraud package known as Antifraud 3.0: a rule forcing foreign websites and apps to authenticate Russian users solely by phone number, a mandate to verify those numbers as genuinely Russian, and a requirement to store three years of registration and login records for handover to law enforcement on request. The ministry's own stated reason is that a Russia-only login system was "technically and organizationally difficult" for global platforms to build — not that the underlying goal changed.

What the Rule Would Have Done

The draft, first reported by Meduza on July 30, 2026, would have replaced the existing menu of authentication options in Russia's information law with a single mandatory channel for any foreign-run site or app serving Russian users: a Russian mobile number, full stop. Paired with it was the three-year data-retention clause. Telecom analysts quoted by Kommersant were blunt that a globally oriented service has little reason to build region-specific plumbing to satisfy one country's regulator, and that the more likely outcome for services unwilling to comply was simply losing access to the Russian market rather than adapting to it.

The SORM Problem

The provision collapsed for a reason more specific than bureaucratic friction: experts told Meduza that compliance would have meant, in practice, connecting to SORM, the System for Operative-Investigative Activities that already gives Russia's security services standing access to telecom and internet traffic. That link isn't incidental. Two months earlier, on May 22, 2026, the ministry registered Order No. 1174 — a 69-page technical standard, filed with the Justice Ministry's official registry — expanding what counts as searchable SORM data to include passport numbers, tax IDs, bank details, device identifiers, and geolocation, and extending the installation obligation beyond telecoms to hosting providers, data centers, cloud operators, banks, and universities. A phone-only login mandate for foreign sites would have been the missing piece pulling international platforms into that same pipe.

Steelmanning the Fraud Case

It's worth taking the ministry's stated rationale seriously before dismissing it. Russia has real, well-documented telephone and account-takeover fraud, and the first two Antifraud packages — covering international call-blocking and stricter SIM issuance — target a genuine consumer-protection problem shared by many jurisdictions grappling with SMS scams and SIM-swap fraud. Phone-based identity verification is not inherently sinister; India, the EU, and the US all lean on carrier-linked identity signals in various anti-fraud contexts. A government arguing it needs a reliable way to trace fraudulent accounts back to a real person is not making an unreasonable claim on its face.

Why That Case Falls Apart Here

The distinguishing fact is who receives the data and why. Standard anti-fraud verification is designed to be queried by fraud investigators, typically walled off from national-security services. What the dropped Antifraud 3.0 clause proposed was different: a single mandatory channel, tied to a national phone number, feeding into a legal architecture — SORM — whose defining purpose is standing, warrantless access for the FSB and other security services, not case-by-case fraud referrals. Combined with the three-year retention window, the rule would not have targeted fraud rings specifically; it would have handed Moscow a durable, foreign-platform-inclusive identity map of any Russian user of any global service, fraud suspect or not. That's the pattern proportionate-regulation advocates should watch for: a legitimate policy label attached to an enforcement mechanism built for something else.

The Retreat Doesn't Change the Trajectory

None of this should read as a genuine policy reversal. The ministry hasn't disavowed the goal, only this implementation path, and Vice-Premier Dmitry Grigorenko has said the broader Antifraud 3.0 package — now minus the foreign-login clause — is still headed to the State Duma this autumn. Meanwhile the infrastructure this provision would have plugged into keeps expanding on its own: Roskomnadzor had restricted access to 439 VPN services by mid-January 2026, up 70% from October 2025, part of a steady campaign to close off the circumvention tools Russians increasingly rely on as direct access to foreign platforms narrows. Dropping one unworkable phone-login rule is a tactical concession to technical reality, not a retreat from the ambition to fold foreign platforms into Russia's surveillance perimeter. The next draft, or the one after it, will likely try again with a mechanism global platforms can actually be pressured into adopting.

Sources & Citations

  1. Meduza: Russia drafts rules requiring foreign websites to authorize Russian users by phone number
  2. Meduza: Russia's digital ministry expands SORM data-sharing requirements
  3. Ministry of Justice registration record: Order No. 1174 (SORM technical requirements)
  4. Vedomosti: Third antifraud package drops foreign-site phone registration
  5. The Record: Russia upgrades rules for its digital spy system
  6. www1.ru: Roskomnadzor restricts access to 439 VPN services