Russia’s State Duma has passed a law imposing administrative fines on website and mobile application owners that violate the country’s user-authorization rules, including by failing to provide approved domestic login methods for users in Russia. The measure enforces requirements already in force since 2023 and targets operators of online services rather than end users; people are not being fined for signing in with accounts such as Google, Apple ID, or Gmail. Under the rules, services aimed at users in Russia must offer authentication through a Russian mobile number, Gosuslugi (ESIA), the Unified Biometric System (EBS), or another Russian-owned information system, with penalties reported at up to 700,000 rubles for noncompliance.
The legislation also broadens liability in adjacent digital-regulation areas. It introduces penalties for violations involving recommendation technologies, including unlawful collection of user preference data and failure to disclose the use of recommendation algorithms, and it raises sanctions for telecom operators that breach obligations to cooperate with law enforcement during operational-search and security activities. Reports indicate the updated framework includes multimillion-ruble fines and turnover-based penalties for repeat offenses, expanding enforcement pressure across Russia’s online platform and telecom sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The underlying authorization requirements took effect in 2023, requiring websites and applications serving users in Russia to offer login via a Russian mobile number, Gosuslugi (ESIA), the Unified Biometric System, or another Russian-owned information system.
The Russian State Duma passed in the second and third readings a bill introducing administrative fines for website and application owners that violate existing user-authorization requirements on Russian internet resources. The measure also adds penalties tied to recommendation technologies and raises liability for telecom operators that violate cooperation rules with law enforcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.