Russia’s Ministry of Digital Development has released its proposed Anti-Fraud 3.0 legislative package for public consultation, seeking to curb fraud enabled by anonymous or stolen-identity mobile accounts. The measures would limit physical SIM registration to direct dealers, prohibit preloaded SIM balances, and require subscribers to execute service agreements before adding funds. Telecom operators would also be required to suspend every number registered to a subscriber when the FSB or Interior Ministry identifies one of their numbers as involved in unlawful activity, while data on people who transfer phone numbers or account credentials to fraudsters would be added to the GIS Antifraud system.
The package would require identifiable bulk-SMS senders, ban automated checks of number activity, and require websites and mobile-app operators to retain registration data for three years. Russian hosting providers would face customer-identification, service-purpose verification, and Roskomnadzor registry-screening requirements, including a one-year prohibition on serving registry-listed operators of tools used to access blocked resources. Proposed provisions also restrict online authentication methods and establish a unified consent-management platform through Gosuslugi; if approved as drafted, the amendments would take effect on March 1, 2028.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Russia’s Ministry of Digital Development published its third anti-fraud legislative package for public consultation. The proposed measures would tighten SIM-card sales and activation rules, expand GIS Antifraud reporting and suspension powers, impose hosting-provider controls, restrict online authentication methods, and require retention of specified user and telecom-contract data.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.