Russia Moves From Blocking VPN Apps to Blocking Their Hosting
A new Russia VPN block hit on 4 August 2026, and its target was not the apps. Roskomnadzor took down IP addresses and whole subnets belonging to large hosting providers, so more than twenty VPN services lost their servers at once. Days earlier the Ministry of Digital Development had circulated a plan to audit the one place where VPN infrastructure could still sit quietly: the white list of addresses that stay reachable when everything else is throttled.
Taken together these are two halves of the same shift. The state is moving from chasing individual services to clearing out the ground they stand on.
The 4 August Russia VPN block: hosting infrastructure in the crosshairs
Operators and specialist channels counted more than twenty affected services during the day. There is no official list: Roskomnadzor published no statement about the wave, and the regulator has never confirmed which subnets it filters. What the reporting does establish is the level at which the block was applied. It was not a protocol signature and not an application ban, it was addresses and entire subnets of major hosting providers.
That distinction matters more than the number of services. A provider whose protocol is detected can change its protocol. A provider whose hosting subnet is filtered has to move house, and every service renting from the same subnet moves with it, whether or not it was the target. Through the evening some operators brought individual locations in Europe and the United States back online, which is the usual pattern: rent new address space, restore, wait for the next sweep.
The Ministry of Digital Development proposal: auditing the white list
The white list exists so that banks, marketplaces, state services and corporate systems keep working while other traffic is restricted. Any address on it is, by design, an address that does not get filtered. That made it attractive shelter, and the Ministry of Digital Development now proposes to audit it continuously. Nothing here is law yet: this is a proposal under discussion with the market, and the mechanics reported by RBC, citing four market participants, look like this.
| Step | What is proposed |
|---|---|
| Monitoring | Addresses on the white list are watched for signs of VPN infrastructure |
| Query | On detection the hosting provider gets a request and has 24 hours to answer |
| Answer | Either confirm the address serves a legitimate corporate need, or it leaves the white list |
| Weak client checks | Where the client was verified only by phone number or card, the address can be blocked within 30 minutes |
| Strong client checks | Where the client passed document or biometric verification, a warning comes first |
| Repeat offences | The provider can be labelled untrustworthy, and restrictions extend from single servers to its whole IP subnets |
Read the last row again, because it is the part that changes the economics. Today a hosting provider that ignores a takedown risks losing one customer's server. Under this scheme it risks its entire address space, including the customers who never ran anything of the kind.
Why infrastructure pressure works differently
Blocking a service is a contest the service can win repeatedly. New domains, new protocol obfuscation, new client versions: the cycle is well practised, and Russia has been running it for years, with roughly four hundred circumvention services restricted by the middle of January 2026 according to Kommersant.
Pressure on hosting changes who has to act. The provider is a company with a legal address, contracts and a revenue stream, and it can be made to choose between one customer and its whole subnet. That is why the same logic already appears in legislation: amendments discussed under the Antifraud 2.0 bill would forbid hosting providers from supplying capacity to owners of systems that provide access to blocked material.
What this means in practice
For people inside Russia the visible effect is instability rather than a wall. Services return, then break again, and each sweep costs their operators money and address space. The services most exposed are small ones renting in shared subnets, because they are collateral in a filter aimed at somebody else.
There is also a lesson that travels well beyond one country. When a state stops filtering traffic and starts filtering the companies that host it, the question for any privacy tool is no longer which protocol it speaks but whose infrastructure it stands on, how many other tenants share that address space and how quickly it can move. Diversity of hosting is becoming part of the threat model, not an operations detail.