Human Rights Watch reported on September 24, 2026 that Russia has moved from blocking individual VPNs to attacking the infrastructure that supports them. The tools now include bulk IP and subnet blocking, DDoS attacks, phishing aimed at VPN staff, app-store removals and payment restrictions. The escalation matters well beyond Russia. It shows what happens when a censorship regime treats circumvention as the problem to be solved rather than the symptom of the content rules it enforces.
The strongest case for the state's position
Every government has a legitimate interest in enforcing its own laws online. If a court or regulator has lawfully ordered illegal content blocked, a tool whose purpose is to defeat that block undermines the rule of law. That is the logic behind Federal Law 276-FZ of 2017, which prohibits owners of VPN services and internet anonymizers from providing access to websites banned in Russia. Regulators in many democracies also worry that anonymity tools shield fraud and abuse.
That argument has real force where the underlying blocklist is narrow, judicially supervised and aimed at clearly illegal material. Russia's is none of these.
What has changed
According to HRW's report, authorities had blocked at least 469 VPN services by February 2026. The new element is the target: the infrastructure behind the services rather than individual apps.
- Amnezia VPN, June 2026. The service's developers said it was hit by bulk IP blocking and a large DDoS attack, and that its staff were targeted by phishing. Amnezia's own account describes "a massive, planned attack" combining DDoS with IP blockages. Meduza reported that the developers said swapping servers became impossible, and that Roskomnadzor did not comment on the allegations. HRW says recovery took about 1.5 months. Attribution to the regulator rests on the developers' claim, not on independent forensics.
- August 4, 2026. Exploit reported disruptions at 20 VPN providers, according to Eurasia Review's summary of HRW's findings. Bulk IP and subnet blocks take longer and cost more to reverse than blocking one app.
- April 2026. HRW says more than 20 large internet companies were told to detect VPN use and cut services to those users. RKS Global found at least 30 large apps collected data that was later used in infrastructure blocks.
- App stores and payments. Apple removed 468 "utility" apps, including VPNs, in 2025 at Russian request. In March 2026 it removed five named VPN tools on Roskomnadzor's demand. Mobile carriers were also barred from processing Apple billing. Google was fined about 22.8 million rubles in February 2026 for failing to remove VPN apps.
Why the necessity test fails
International human rights law does not forbid every limit on expression. It requires that limits be provided by law, serve a legitimate aim, and be necessary and proportionate. The UN Special Rapporteur's 2015 report on encryption, anonymity and the human rights framework (A/HRC/29/32) applies that three-part test to anonymity tools. HRW cites the same reasoning against blanket bans on anonymity.
Russia's campaign fails this test in three ways.
- It is indiscriminate. Bulk IP and subnet blocking cannot tell a user reading blocked news from one protecting their banking privacy. Collateral damage is built into the method.
- It targets people, not content. DDoS attacks and phishing against developers are not enforcement of a blocklist. They are operations against the people who maintain a privacy tool.
- It leaves no lawful alternative. With roughly 57 million users, about 40% of the population by HRW's estimate, VPN use is mainstream. A measure that reaches that many people in ordinary daily use is not a targeted response to a defined harm.
The privacy cost of whack-a-mole
HRW makes a point that is easy to miss: the harm goes beyond lost access. When large providers are knocked offline, users move to whatever still works. Those alternatives are often less audited, less transparent and worse on privacy. The state gets to claim it has cut circumvention while pushing people onto tools that are easier to exploit.
The proposal for a state-run "GovVPN" option, noted in Amnezia's June digest, shows where this can lead. Degrade trustworthy tools, then offer a monitored substitute.
What platforms and funders should do
The pressure on private intermediaries is the part other jurisdictions should watch. A store operator that complies with a takedown demand in one country sets a precedent that authoritarian regulators elsewhere will cite. HRW urges companies to resist store takedowns and funders to back circumvention tools.
Those recommendations are sound, with one caveat. Companies face real legal and safety risks for local staff and cannot simply ignore orders. Transparency is the least they can offer. That means publishing each takedown request, the legal basis cited, and the number of users affected. Apple's transparency reporting is a start, but a per-app account would do more for the people affected.
For democratic governments, the takeaway is to avoid reaching for the same instruments. Proportionate regulation targets specific illegal conduct through specific, reviewable orders. Regimes that go after the infrastructure of privacy itself tend to end up with less security and less trust, and citizens who still find a way around.
Bottom line
Russia's escalation is evidence that a censorship regime that has to attack developers, payment rails and IP address space to enforce a blocklist has already lost the argument that the list is proportionate. Supporting open, auditable circumvention tools is the pro-speech, pro-innovation response.