background image blur
background image
  • Blog
    >
  • News
    >
  • Russia Is Running What May Be Its Biggest VPN Blocking Campaign in History

Russia Is Running What May Be Its Biggest VPN Blocking Campaign in History

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 6 August, 2026
A Russian woman outside tries to use her phone

Key Takeaways

  • Russian authorities appear to have launched one of the largest VPN blocking campaigns in the country's history, affecting more than 20 popular services, according to reporting by Meduza.
  • The attack is targeting IP addresses and entire subnets belonging to major hosting providers, rather than individual VPN servers — a broader and potentially more effective method than previous crackdowns.
  • Leonid Volkov of the Anti-Corruption Foundation called it "the biggest in history" on Telegram, with cyberlawyer Sarkis Darbinyan suggesting Russian apps' location tracking has allowed Roskomnadzor to compile a large database of IP addresses for the attack.
  • The campaign coincides with reported plans by Russia's Digital Development Ministry to tighten control over corporate VPN IP addresses and introduce continuous monitoring to remove "disguised" circumvention tools from approved lists.

Russia appears to be carrying out one of its largest-ever attacks on VPN services, according to reporting by Meduza. Amnezia, one of Russia's most popular VPN providers, reported on August 4 that Russian authorities had launched a new mass blocking campaign that had been underway for at least several days. 

SecurityLab reported that multiple VPN services experienced outages and connection problems on the same day, with restrictions hitting IP addresses and entire subnets belonging to major hosting providers.

VPN Legend, GaMMa VPN, LTVPN, ABS, FoxyBot, and Paper VPN have all reported disruptions. The Telegram channel Eksploit calculated that more than 20 popular VPN services have been affected. Leonid Volkov, one of the leaders of Alexei Navalny's Anti-Corruption Foundation, called it "the biggest attack in history" on his Telegram channel. 

Cyberlawyer Sarkis Darbinyan and Amnezia representatives both suggested the same mechanism is behind it: Russian apps — including banking and marketplace apps — track users' IP addresses, giving Roskomnadzor the data needed to compile a large database of VPN IP addresses and carry out a coordinated mass block.

This isn't an isolated incident. Amnezia was targeted in a large-scale attack earlier this summer that lasted a month and a half, hitting not only the service's servers but its payment infrastructure through DDoS attacks. Amnezia is confident Roskomnadzor was behind that campaign too.

The Mechanism — and Why It’s More Effective This Time

Previous VPN blocking efforts in Russia typically targeted individual servers or domains. This campaign appears to be operating differently: by hitting IP addresses and entire subnets belonging to major hosting providers, authorities can take down many services simultaneously without needing to identify each one individually. It's a blunter instrument, but a broader one.

The tracking mechanism described by Volkov and Darbinyan adds another layer. Russian apps — the banking apps, marketplace apps, and other services that Russians use daily — collect location and IP data from users. That data flows to Roskomnadzor, building a map of which IP addresses are associated with VPN traffic. When the map is complete enough, a mass block becomes operationally feasible in a way that previous piecemeal approaches were not.

A day before the attack was reported, Russian business outlet RBC reported that the Digital Development Ministry wants tighter control over corporate VPN IP addresses currently on a special exempt-from-blocking list. "Disguised" circumvention tools have apparently been making their way onto that list. The ministry wants to work with hosting providers on continuous monitoring to remove suspicious addresses. Whether this week's blocking campaign is connected to those discussions isn't yet clear. The timing is notable.

What This Means for People Who Need VPNs in Russia

The people most affected by this campaign aren't privacy enthusiasts or tech professionals who can find workarounds. They're ordinary Russians who use VPNs to access news from independent outlets that have been blocked, communicate with family abroad, or simply use services that Russia has restricted. We've written before about how Russia's internet censorship operates as a layered system — blacklists, sovereign infrastructure, wartime speech laws, and now an active campaign against the circumvention tools that let people navigate all of it.

We've also written about how Russia's app store restrictions produced a 70% surge in mobile malware, as users blocked from legitimate services turned to unvetted APK downloads. Mass VPN blocking creates the same dynamic: when legitimate, reputable VPN providers are blocked, users don't stop wanting to access the open internet. 

They turn to whatever works — which increasingly means less secure, less transparent tools that may themselves be surveillance vectors.

The broader implications extend beyond Russia's borders. Leonid Volkov's framing — that this is the biggest attack in history — reflects a qualitative shift, not just a quantitative one. When a state becomes sophisticated enough to use data from its own civilian apps to map and block circumvention infrastructure at scale, the architecture of internet control gets meaningfully harder to escape. 

That's a template other governments are watching. The Cockroach Effect we covered last week — decentralized, peer-to-peer tools that can't be blocked through centralized infrastructure attacks — exists precisely because this kind of campaign is where the trajectory of state censorship leads.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"