Security & AI news

Internet censorship · By FireAI Security & Research Team · Published

Russia plans to double spending on its internet blocking system and proposes a registry of VPN hosting customers

Russia’s 2027 draft budget gives its blocking system 19.87 billion roubles, and a new draft law targets VPNs on Russian hosting and expands login data retention.

A globe with map pins and the TorAi mascot, next to the words “Russia doubles its blocking budget.”

Russia’s draft federal budget for 2027 allocates 19.87 billion roubles to the system Roskomnadzor uses to block websites and VPN services, almost twice the 9.87 billion roubles previously planned for that year, The Moscow Times reported on 1 October 2026 [1]. In the same week the Digital Development Ministry published a third anti-fraud package that would bar people who run censorship-circumvention services from Russian hosting providers, Meduza reported on 5 October [2]. Together, the two documents describe more money for blocking and new legal pressure on the infrastructure used to get around it.

Background

Russia filters internet traffic with equipment installed on operators’ networks, known as TSPU (technical means of countering threats). According to The Moscow Times, Roskomnadzor manages that equipment through an automated internet security system, ASBI, run by the Main Radio Frequency Centre, a body subordinate to Roskomnadzor; the TSPU are used to filter traffic and to block and slow down sites and services [1]. Circumvention tools, such as VPNs, proxies and Tor, carry a user’s traffic past that filtering.

What the reports describe

The 2027 figure of 19.87 billion roubles is followed by 19.84 billion in 2028 and 19.87 billion in 2029, about 60 billion roubles over three years. Roskomnadzor has previously been given the task of blocking 92 per cent of VPNs by 2030 and of raising ASBI’s capacity 2.5 times, to 954 Tbit/s. In 2025 the number of TSPU on operators’ networks reached 1,406, and Roskomnadzor blocked 258 VPN services, the outlet reported [1]. Roskomnadzor’s overall funding for 2027 would rise to 31.8 billion roubles [1].

The draft anti-fraud package reviewed by Meduza would create a registry of Russian hosting providers’ customers who use rented computing resources to run proxy or VPN services that circumvent censorship. Anyone found circumventing blocks would be barred from signing new contracts with any hosting provider in the country for a full year [2]. Hosting providers would also have to cease supplying computing resources at the request of agencies conducting criminal intelligence operations, “where necessary to counter cyberattacks”; Meduza writes that it is unclear whether the security service would use this power against VPNs as well [2].

Companies, which may currently use VPNs “for technical purposes necessary to its operations”, would have to notify Roskomnadzor that they do so, under rules to be agreed with the FSB. Websites and apps, Russian and foreign, would have to retain records of users’ registrations, logins and account closures for three years and provide them to authorised agencies. Telecom operators would store information “on network addresses and ports” used when a customer signs a contract over the internet, for three years [2].

Implications for Mac users

For a person in Russia, the reports point to two pressures at once: a better-funded blocking system, and draft rules that would make it harder to run a VPN server on Russian hosting and would keep more records of who logs in where. A VPN whose servers are blocked or removed stops working, and a VPN account is itself a login that the proposed retention rules would cover for services operating in Russia. The anti-fraud package is a draft, and none of the figures above says how well the blocking performs in practice. Readers outside Russia are not directly affected, but the measures concern anyone who builds or relies on circumvention tools used there.

Recommendations

  1. Keep more than one circumvention method available, since a single VPN provider can be blocked or lose its hosting.
  2. Prefer tools that fail closed, so that an app is blocked rather than sent over the direct connection when the tunnel drops.
  3. Remember that a login to any service identifies the account holder, whatever route the traffic takes.
  4. Follow the anti-fraud package as it moves from draft to law, because its details are still to be set by the government.

Relevance to TorAi

TorAi 0.1.1 sends selected Mac apps, or all traffic except the local network, over Tor, with one circuit per app, and is built to fail closed: if Tor is not ready, routed apps are blocked. TorAi does not yet offer bridges, which networks that block Tor relays usually require; bridges are on its roadmap. It does not make a user anonymous after logging in to an account, and it cannot prevent a service from keeping the login records the draft law describes. TorAi is not affiliated with or endorsed by The Tor Project.

Limitations

The budget figures come from The Moscow Times’ reading of the draft federal budget, first noted by the outlet Verstka, not from the budget document itself [1]. The anti-fraud provisions come from Meduza’s review of the ministry’s draft; the text may change before it is adopted, and the government has yet to set several procedures [2]. Neither source discusses Tor specifically, and neither measures how many people in Russia use circumvention tools.

To route chosen Mac apps over Tor, download TorAi and try every feature free for 17 days. TorAi is made by HisnLabs and is not affiliated with or endorsed by The Tor Project.

Sources

  1. The Moscow Times (Russian service), 1 October 2026: Власти удвоят расходы бюджета на блокировки интернета и борьбу с VPN
  2. Meduza, 5 October 2026: Russia says it’s fighting scammers. Its latest proposals would push VPN services off Russian servers, tie eSIMs to devices, and expand telecom data retention