Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
privacy-surveillance-policyoperational-disruptiongovernment-diplomatic-threat

Moscow Internet Blackouts and State-Approved Web Access

Updated 2d agoFirst seen Mar 18, 20265 sources

Russian authorities are restricting internet access in Moscow during ongoing mobile network disruptions by allowing connectivity only to a government-approved whitelist of domestic websites and services. Reporting indicates the system keeps selected Russian platforms—such as government sites, telecom services, marketplaces, and transport or delivery apps—available while broader internet access is blocked, reportedly using deep packet inspection (DPI) and infrastructure controls that require traffic to stay within Russia and prevent users from masking IP addresses. Officials have framed the outages and restrictions as protective measures against Ukrainian drone attacks, while similar controls are reportedly being prepared or used in other Russian cities including St. Petersburg.

The disruptions are also producing visible social and economic effects in Moscow, where residents and businesses are struggling with failed QR-code payments, degraded app-based services, and loss of normal mobile connectivity. One account describes a broader regression to offline workarounds, including increased demand for walkie-talkies, pagers, and paper maps, as GPS-dependent and internet-based services become unreliable. A separate report on Kazakhstan's proposed social media monitoring regime concerns a different country and policy process and does not describe the same Moscow outage and whitelist event.

Share:
Moscow Internet Blackouts and State-Approved Web Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 20, 20262mo ago

Russia proposes sovereign AI rules requiring domestic training data

Russia's Ministry for Digital Development reportedly proposed sovereign AI rules to be implemented by 2027 that would require chatbots to be developed and trained in Russia using only Russian datasets rather than broader internet sources. Business groups and firms including Yandex and Gigachat reportedly argued that domestic compute capacity and local training data are currently insufficient and that several years would be needed to build the necessary infrastructure.

Russia demands a sovereign AI - Pivot to AI
Apr 6, 20263mo ago

DDoS attack on Rostelecom disrupts internet access across Russia

A large-scale DDoS attack hit state-run telecom provider Rostelecom on Monday evening, causing temporary internet disruptions in roughly 30 Russian cities and affecting services including Steam, Gosuslugi, Rutube, and banking platforms. Rostelecom said the attack was quickly contained, though emergency filtering measures contributed to degraded access and some government sites remained affected into the next day.

Cyberattack on telecom giant Rostelecom disrupts internet services across Russia | The Record from Recorded Future News
Apr 4, 20263mo ago

Internet controls reportedly expand from Moscow to other large Russian cities

By early April, reports described mobile internet shutdowns and tighter controls on Telegram, WhatsApp, and VPN access not only in central Moscow but also in other major Russian cities. The expansion suggested the Kremlin's whitelist-style, state-controlled internet model was being rolled out more broadly across the country.

As� es la 'c�rcel digital' de Putin: sin 3G en la calle ni chat en casa y con una app esp�a obligatoria en el m�vil | Internacional
Mar 18, 20264mo ago

St. Petersburg expected to face similar internet restrictions

Reports indicated that similar connectivity disruptions were expected in St. Petersburg as Russian authorities expanded or prepared comparable controls beyond Moscow. This suggested the measures could spread to other major cities.

Residents shift to analog tools amid degraded connectivity

With digital services impaired, Moscow residents reportedly increased their use of analog alternatives such as walkie-talkies, pagers, and paper maps. The disruptions also created pressure to move from Telegram and WhatsApp to the state-backed MAX app developed by VK.

Economic and civic disruption from outages becomes evident

As the restrictions continued, businesses and public institutions in Moscow experienced significant disruption, including problems with payments, navigation, logistics, retail operations, and even government functions. Analysts estimated that five days of internet restrictions could cost Moscow businesses up to 5 billion rubles.

Whitelist-based internet controls are reportedly deployed in Moscow

Russian authorities were reported to be introducing a mobile internet "whitelist" system in Moscow that permits access only to government-approved websites and services, apparently using deep packet inspection to block most other traffic. The move was described as part of a broader push toward a more isolated sovereign Runet.

Mar 7, 20264mo ago

Moscow begins sustained mobile internet disruptions

A prolonged disruption of internet and mobile connectivity in Moscow began, with Russian authorities publicly presenting the restrictions as a response to Ukrainian drone threats. The outages affected everyday digital services across the city.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
9 linked
TelegramWhatsappSteamFacebookWechatIphoneChatgptGmailCopilot
Organizations
8 linked
YandexMeta PlatformsAppleTelegramVKWildberries & RussRussian FieldGigachat
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.