PART I: COURTS, SECURITY SERVICES, POLITICAL PRISONERS, WOMEN, INDIGENOUS PEOPLES AND THE EXPANSION OF DOMESTIC REPRESSION
From Selective Repression to a Broad National-Security System
The most important development inside Russia during 2025 and 2026 was not one isolated crackdown. It was the continued integration of criminal law, national-security legislation, censorship, political policing and judicial prosecution into a broader system for suppressing organized dissent.
Human Rights Watch reported that Russian authorities intensified repression during 2025, targeting journalists, anti-war activists, civil-society organizations, lawyers, Indigenous activists and people accused of cooperating with foreign organizations. By the end of 2025, Memorial's political-prisoner project had recorded 1,217 political prisoners, including 108 women, compared with 805 at the end of 2024.Human Rights Watch
By July 2026, Human Rights Watch reported that Memorial's count had risen to 1,715 political prisoners, while another 2,777 people were categorized as other victims of political repression. One year earlier those figures had been 997 and 1,044 respectively.Human Rights Watch
This represents a sharp expansion in the number of people formally identified by rights monitors as being subjected to politically motivated prosecution.
Courts as an Instrument of Political Enforcement
Russian courts continued imposing lengthy prison terms for anti-war speech, independent journalism, political organizing and association with prohibited organizations.
By September 2025, at least 1,299 people had faced criminal prosecution for opposing the war, while 373 remained imprisoned on related charges. At least 692 had been prosecuted under laws concerning alleged "false information" about the armed forces or "discrediting" the military.Human Rights Watch
Journalists also received severe sentences.
Four journalists accused of involvement with Alexei Navalny's Anti-Corruption Foundation received prison terms of five and a half years in April 2025. Journalist Olga Komleva received a 12-year sentence in July following closed proceedings.Human Rights Watch
The legal categories used against critics increasingly include:
Extremism, terrorism, discrediting the military, spreading allegedly false information, confidential cooperation with foreigners, participation in undesirable organizations, foreign-agent violations and cooperation with organizations outlawed by Russian courts.
In April 2026, Russia's Supreme Court designated what authorities called the "International Public Movement Memorial" as extremist, extending the risk of prosecution to organizations and individuals associated with one of Russia's best-known human-rights movements.Human Rights Watch
The Death Penalty in 2026
Russia presents a fundamentally different death-penalty situation from Iran, China or Afghanistan.
The death penalty remains legally present in Russian law, but Russia is considered abolitionist in practice because it has maintained a long-standing moratorium and has not carried out executions for decades. Amnesty International continues to classify Russia as a country that retains capital punishment in law but has not executed anyone for at least ten years.Amnesty International
Therefore:
There is no meaningful 2026 Russian death-row population comparable to countries actively conducting judicial executions.
Political prisoners may receive extremely long sentences, including decades in penal colonies, but these are not equivalent to death sentences.
Periodic political calls in Russia to restore capital punishment have not, as of September 29, 2026, resulted in the resumption of executions.
Detention, Torture and Prison Conditions
Amnesty International reported that torture and other ill-treatment remained endemic and were carried out with near-total impunity, while arbitrary detention, fabricated charges and unfair trials remained major characteristics of the Russian justice and law-enforcement system.Amnesty International
Human-rights groups have documented abuse across police stations, pretrial detention centers and penal institutions.
The overall enforcement sequence can therefore involve:
Digital surveillance, investigation, search, arrest, interrogation, national-security charge, closed or restricted trial, imprisonment, designation as extremist or terrorist and restrictions extending to associates and family members.
Indigenous Peoples and Ethnic-Minority Activists
One of the most important developments of late 2025 and 2026 was increased pressure on Indigenous-rights organizations.
In December 2025, Russian authorities detained Indigenous activist Daria Egereva, a representative of the Selkup people and co-chair of the International Indigenous Peoples' Forum on Climate Change. Searches were simultaneously conducted at the homes of at least 17 other Indigenous activists and human-rights defenders.Amnesty International
A communication by UN experts in April 2026 raised concerns that Egereva's prosecution could constitute intimidation or retaliation linked to engagement with United Nations mechanisms. The communication described a broader pattern in which Indigenous and minority-rights organizations were labeled extremist or terrorist despite the absence of evidence of violent activity.UN Human Rights Commission Reports
The political significance is substantial.
Minority-rights advocacy increasingly intersects with national-security law.
Organizations representing Indigenous peoples can therefore find themselves treated not as civic associations but as potential security threats.
Chechnya and Collective Punishment
Chechnya remained one of the most severe internal human-rights environments in the Russian Federation.
Human Rights Watch documented retaliation against relatives of government opponents and coercive mobilization. In one 2025 case, after a teenager attacked police officers and was killed, his body was displayed publicly, while authorities reportedly expelled relatives of the alleged attacker and opposition figures and confiscated property.Human Rights Watch
The Kremlin declined to comment on aspects of the episode.
Such cases illustrate the degree to which regional security structures can combine political loyalty, family pressure and coercive enforcement.
Women's Rights and Reproductive Control
Women's rights became increasingly connected to demographic policy.
Human Rights Watch reported in February 2026 that Russian authorities had intensified restrictions on abortion access through pressure on clinics, administrative measures and mandatory counseling designed to discourage termination of pregnancy.Human Rights Watch
More than 200 clinics had lost licenses to provide abortion services since 2023, while church officials claimed that 852 private clinics, approximately 30 percent of the total, had stopped performing abortions by January 2026.Human Rights Watch
By 2025, more than 20 regions had adopted restrictions against what authorities describe as "incitement to abortion."Human Rights Watch
Russia also announced plans for a registry tracking pregnancies and pregnancy outcomes, raising privacy concerns among rights monitors.Human Rights Watch
Domestic violence, meanwhile, remained inadequately addressed through comprehensive federal legislation. Amnesty reported that despite substantial public support for stronger protections, lawmakers again failed to enact major reform.Amnesty International
The Wider Pattern
The domestic system is therefore no longer best understood as a collection of isolated prosecutions.
It increasingly resembles an integrated enforcement architecture involving:
FSB investigations, Interior Ministry policing, prosecutors, courts, prison authorities, Roskomnadzor, financial monitoring, telecommunications controls and legal designations such as extremist, terrorist, foreign agent and undesirable organization.
The growth from 997 documented political prisoners in July 2025 to 1,715 by July 2026 provides one of the clearest quantitative indicators of that transformation.Human Rights Watch
PART II: RUSSIA'S DIGITAL CONTROL SYSTEM, TSPU, DPI, TELEGRAM RESTRICTIONS, MOBILE BLACKOUTS AND THE SOVEREIGN INTERNET

Russia's Internet-Control Model Is Technically Different From China's
Russia's censorship infrastructure has evolved rapidly since the adoption of the Sovereign Internet law.
Its core architecture increasingly depends on centrally controlled filtering hardware installed inside telecommunications providers.
The most important system is known as TSPU, Technical Measures to Counter Threats.
Internet service providers are required to deploy this equipment, while censorship policy can be centrally coordinated through Roskomnadzor.
OONI measurements have shown that independent media sites were blocked across numerous Russian networks using highly similar TLS-interference patterns, consistent with centralized control through TSPU infrastructure.labs.ooni.io
How TSPU Works
The technical model combines decentralized physical deployment with centralized policy.
Hardware sits within ISP networks, but blocking rules can be distributed centrally.
Observed censorship techniques include:
SNI inspection, TLS interruption, TCP reset injection, connection timeouts, IP blocking, domain blocking, traffic throttling and interference with circumvention systems.labs.ooni.io
During a TLS connection, the initial ClientHello may expose the requested domain through Server Name Indication.
OONI measurements inside Russia have repeatedly shown successful IP connections followed immediately by TLS failure once the requested hostname is exposed.
In some measurements, a TCP RST packet was injected immediately after the ClientHello.labs.ooni.io
That behavior is characteristic of Deep Packet Inspection based censorship.
The Architecture Is Becoming More Centralized
Academic research into TSPU describes the system as a form of infrastructural coercion in which telecom operators are forced to install filtering systems and accommodate centralized state control.AoIR Selected Papers
This changes the state's capabilities fundamentally.
The government does not need to negotiate separately with every ISP every time it wants to block a service.
The control layer is increasingly embedded in the network itself.
VPN Suppression
Russia has progressively restricted VPN services and information explaining how to bypass censorship.
A state operating DPI equipment can target VPNs through several mechanisms:
Known endpoint blocking, TLS fingerprinting, protocol signatures, SNI inspection, traffic-flow characteristics and active interference with connections.
Not every failure means the government decrypted the communication.
A censor only needs to identify enough characteristics of the connection to disrupt it.
Telegram, WhatsApp and the 2026 Escalation
In 2026 Russia's communications restrictions intensified significantly.
Reuters reported that repeated restrictions affected Telegram, WhatsApp and mobile internet access, while the government promoted the state-backed messaging platform MAX.Reuters
The disruptions affected millions of businesses and self-employed workers because messaging applications had become essential commercial infrastructure.
Reuters estimated that approximately 2.9 million small companies and 14.1 million self-employed Russians relied on messaging platforms for business communication.Reuters
This transformed censorship from a political-information issue into a nationwide commercial infrastructure problem.
Moscow's 2026 Mobile Internet Blackouts
One of the most consequential developments occurred in March 2026.
The Kremlin publicly acknowledged mobile internet disruptions in Moscow and other cities, stating that they were being implemented for security reasons.Reuters
The Financial Times reported that the Moscow disruptions reduced mobile traffic by approximately 20 percent and caused estimated economic losses of 1 billion to 2 billion rubles per day, approximately $12.5 million to $25 million.Financial Times
Officials introduced or expanded a whitelist model that allowed selected approved services to remain available when general mobile connectivity was restricted.Financial Times
This is a major shift.
Traditional censorship blocks selected destinations.
A whitelist system reverses that assumption:
Access is denied by default, approved services are selectively restored.
Humanizing Digital Blackouts
Mobile internet is now part of ordinary civilian infrastructure.
Disruptions affect:
Electronic payment terminals, taxi platforms, delivery services, banking authentication, logistics, navigation, medical communications, cloud applications, school systems, emergency communication and small-business customer contact.
The economic cost is therefore not limited to technology companies.
Restaurants, transport operators, online retailers, real-estate firms and independent workers can all lose revenue because customers cannot communicate or make payments.Reuters
Healthcare can also be affected where appointment systems, digital prescriptions, imaging transfer, laboratory interfaces or emergency communications depend on mobile connectivity.
However, there is currently insufficient public medical evidence to state that Russian internet restrictions caused a specific number of patient deaths in 2025 or 2026.
That causal claim would require individual medical documentation.
Russia's Physical Internet Connectivity
Russia has one of the largest terrestrial telecommunications systems in the world.
Its international traffic passes through multiple terrestrial and submarine routes connecting it to Europe, the Caucasus, Central Asia and East Asia.
Major Russian backbone operators historically include:
Rostelecom, TransTeleCom, ER-Telecom and other large carrier networks.
Unlike a small landlocked state, Russia does not depend on one border gateway.
Its network geography is distributed across numerous western, southern and eastern interconnection points.
Public BGP data and cable maps can identify routes and network operators.
They do not provide reliable evidence showing the exact FSB interception rack or TSPU appliance at every border crossing.
Any report claiming a precise room, cabinet or border station as an intelligence interception point requires additional physical or documentary evidence.
SORM and Lawful Interception
Russia's communications surveillance architecture predates TSPU.
The SORM family of systems provides lawful-interception capabilities that telecommunications operators are required to support.
At a high level, SORM permits authorized state bodies to obtain communications and subscriber information through telecom infrastructure.
TSPU and SORM should not be confused.
SORM concerns interception and surveillance; TSPU primarily concerns traffic control, filtering and network management.
The combination, however, produces a powerful architecture in which the state can both observe communications and influence whether communications remain available.
PART III: ECONOMIC DAMAGE, WESTERN AND ASIAN TECHNOLOGY, SANCTIONS EVASION, HARDWARE FORENSICS AND CRYPTO-FINANCE

Russia's Digital Economy Continued Growing Despite Censorship
One of the most important findings is that Russia's e-commerce economy remained very large even while internet restrictions intensified.
According to the Russian Association of Internet Trade Companies, AKIT, total Russian e-commerce reached 11.5 trillion rubles in 2025, an increase of 28 percent year over year.
Domestic platforms accounted for 96.2 percent of the market, while cross-border purchases represented 3.8 percent. Online commerce reached 18.8 percent of total Russian retail sales.АКИТ
For the first half of 2026, AKIT reported online-commerce turnover of 7.2 trillion rubles, an increase of 18.7 percent compared with the previous year. Domestic online sellers represented 6.9 trillion rubles, while cross-border transactions totaled approximately 245.8 billion rubles. Online commerce accounted for 22.2 percent of all retail sales.АКИТ
These figures demonstrate the extraordinary economic exposure created by mobile blackouts and platform restrictions.
Quarterly Losses: What Is Actually Known
There is no audited national dataset assigning an exact censorship-related loss to every quarter of 2025 and 2026.
Therefore, invented figures such as "Q1 censorship losses = X billion rubles" should not be presented as verified statistics.
What can be documented is narrower but significant.
During the March 2026 Moscow mobile internet disruption, estimated losses reached 1 billion to 2 billion rubles per day.Financial Times
If such disruption continued for seven consecutive days at that rate, arithmetic exposure would be 7 billion to 14 billion rubles.
For 30 days, the modeled exposure would be 30 billion to 60 billion rubles.
Those are modeled scenarios, not audited economic accounts.
Western and Asian Components Inside Russian Systems
Russia possesses substantial domestic telecommunications and surveillance engineering capacity.
It is therefore inaccurate to claim that it cannot manufacture advanced censorship technology itself.
However, Russian technology systems have historically depended on global hardware supply chains involving processors, network-interface cards, routers, storage systems, FPGA components, optical equipment and server platforms.
After sanctions expanded, Russia increased import substitution and parallel-import mechanisms. Academic research into TSPU specifically notes the importance of sanctions-driven import substitution in Russia's censorship infrastructure.AoIR Selected Papers
A serious supply-chain investigation should therefore separate three categories:
Russian-developed censorship software and integration, foreign-origin commodity hardware, components obtained through sanctions-evasion or parallel-import networks.
Hardware Serial-Number Forensics
The strongest method for identifying foreign technology in Russian state infrastructure is serial-level tracing.
Investigators should preserve:
Manufacturer, model, serial number, MAC address, OUI, firmware version, board revision, manufacturing date, importer label, distributor label and asset-management tag.
These identifiers can then be compared with:
Invoices, warranty registrations, customs declarations, distributor records, freight documents, export-control filings, bills of lading and maintenance contracts.
This distinction is essential.
Finding an Intel processor, Western NIC or Asian router inside Russia does not prove the manufacturer knowingly sold it to a sanctioned or security end user.
The evidentiary question is:
Who sold it, through which intermediary, under which end-user declaration and where did the equipment ultimately go?
Customs Data Is Becoming Harder to Obtain
On September 28, 2026, President Putin signed additional restrictions on disclosure of Russian energy-sector and customs information, including export routes, buyers, sellers, prices and destinations. Reuters reported that the restrictions were intended to make Western sanctions enforcement more difficult.Reuters
This creates an important investigative problem.
The same information that sanctions investigators need to reconstruct trade routes is increasingly being classified, withheld or removed from ordinary disclosure.
Investigators therefore become more dependent on:
Mirror customs data, foreign port records, shipping databases, corporate filings, insurance documents, third-country import statistics and manufacturer records.
Seizure of Western Corporate Assets
Russia's confrontation with Europe increasingly affects commercial property directly.
Reuters reported on September 29, 2026 that Russian authorities placed the Russian assets of Nestlé, Metro AG and Auchan under temporary state management.
Since the beginning of the war, Russia had taken control of 135 foreign-affiliated firms, mainly European companies.Reuters
Russian officials characterized these measures as responses to European sanctions and support for Ukraine.
For European corporations, this creates a new category of geopolitical risk:
Investment can become leverage in state-to-state confrontation.
Sanctions-Evasion Financial Architecture
A major recent investigation found that Russian-linked entities used front companies, forged documents, third-country banking systems and shadow foreign-exchange mechanisms to circumvent sanctions.
The Financial Times reported in September 2026 that a Kremlin-backed fintech network associated with A7 moved approximately $6.9 billion over nine months, using networks linked to Kyrgyzstan and the UAE and routing transactions through major international banks.Financial Times
The case illustrates the vulnerability of sanctions systems that rely heavily on documentation supplied by intermediaries.
A shell company can conceal:
Actual seller, actual buyer, beneficial owner, final destination and ultimate end user.
Garantex, Grinex and the Russian Crypto Network
The clearest crypto-forensic case involves Garantex.
The U.S. Treasury reported that Garantex had processed more than $100 million in transactions associated with known illicit actors, including ransomware groups and darknet markets.U.S. Department of the Treasury
In March 2025, U.S., German and Finnish authorities disrupted Garantex infrastructure and froze more than $26 million in cryptocurrency.U.S. Department of the Treasury
Treasury later reported that Garantex transferred customers and assets into a successor platform, Grinex, after enforcement actions.
Grinex subsequently facilitated billions of dollars in cryptocurrency transactions.U.S. Department of the Treasury
Treasury also linked the system to A7A5, a ruble-backed digital asset issued by Kyrgyzstan-based Old Vector and designed for users of Russian cross-border settlement company A7.U.S. Department of the Treasury
This is one of the most important recent examples of cryptocurrency being integrated directly into a sanctions-evasion ecosystem.
Ransomware and USDT
Treasury stated that Garantex received millions of dollars connected to Russia-linked ransomware families including:
Conti, Black Basta, LockBit, NetWalker, Phoenix Cryptolocker and Ryuk.U.S. Department of the Treasury
One sanctioned money launderer exchanged more than $2 million in Bitcoin for Tether through Garantex.U.S. Department of the Treasury
This demonstrates that USDT and other stablecoins can appear in Russian illicit-finance networks.
But a careful report must distinguish:
Russian state assets, sanctioned Russian financial entities, criminal ransomware actors and ordinary Russian cryptocurrency users.
They are not the same category.
China, Russia and Iran: Security Convergence
China, Russia and Iran maintain important but distinct military, technological, diplomatic and sanctions-related relationships.
It is reasonable to examine them as an area of strategic security convergence, but not as a single centralized operational command without specific evidence.
Russia and China continued military cooperation and naval exercises. China has remained an important source of industrial and dual-use goods, while U.S. and European authorities have repeatedly investigated supply chains involving Chinese companies and components reaching sanctioned Russian users.
Iran has supplied Russia with military technology during the Ukraine war, while Russia and Iran have expanded security relationships.
The principal Western concern is therefore not a slogan about a "triangle," but a concrete network of:
Dual-use procurement, sanctions circumvention, military technology transfer, banking alternatives, digital assets, intelligence cooperation and diplomatic protection.
Each transaction requires its own evidence.
PART IV: TRANSNATIONAL OPERATIONS, SABOTAGE, ASSASSINATION NETWORKS, EUROPEAN SECURITY AND U.S. COUNTERINTELLIGENCE

Russia's Security Footprint Does Not End at Its Borders
The most serious risk posed by Russian state activity to Europe and the United States is documented through intelligence operations, cyber campaigns, sabotage allegations, transnational repression and covert financial networks.
This must be distinguished from the millions of ordinary Russian migrants, students, tourists, refugees and businesspeople who have no relationship with Russian intelligence.
Nationality is not evidence of intelligence activity.
The relevant indicators are:
Tasking, payment, clandestine communication, intelligence-service contact, operational surveillance, false documentation, covert financing and other corroborated conduct.
September 2026: An Alleged Russian Intelligence Murder Network
One of the most serious recent U.S. cases emerged on September 15, 2026.
The U.S. Department of Justice unsealed charges against five individuals allegedly working for Russian intelligence services.
Prosecutors alleged that the network financed or attempted to finance surveillance and targeted killings in the United States and elsewhere and commissioned acts of terrorism against civilian and military infrastructure in European states supporting Ukraine.Department of Justice
These remain allegations until established through judicial proceedings.
Their importance lies in the operational model described by prosecutors:
Foreign intelligence handlers, intermediaries, surveillance, recruited local participants, payments and planned violence.
This is the type of evidence that should define a counterintelligence investigation.
It is far stronger than generalized claims that students, refugees or tourists are secretly intelligence operatives.
Rising European Concerns Over Sabotage
European officials warned in September 2026 of increased Russian-linked hybrid activity involving sabotage, cyberattacks, drones, arson and other disruptive actions.
Reuters reported that European ministers saw growing hybrid pressure but did not assess that Russia was preparing an imminent conventional attack on NATO.Reuters
This distinction is crucial.
Hybrid operations seek to create uncertainty, economic cost, political pressure and public fear without crossing automatically into open conventional war.
Targets can include:
Railways, warehouses, military logistics, communications networks, energy systems, airports, data centers and organizations supporting Ukraine.
Cyber Operations and Critical Infrastructure
Russian intelligence services and affiliated cyber groups have long been associated by Western governments with cyber espionage, ransomware ecosystems and disruptive operations.
The risk to Europe and North America increases when cyber operations converge with criminal infrastructure.
Cryptocurrency exchanges such as Garantex illustrate this convergence because the same financial platforms can serve cybercriminals, ransomware groups and sanctions-evasion networks.U.S. Department of the Treasury
This does not mean every criminal hacker acts for the Russian government.
But intelligence agencies can benefit from an ecosystem in which criminal actors, sanctions evaders, cryptocurrency exchanges and state-linked structures operate in overlapping environments.
The Information Environment
Foreign influence can also target information systems rather than physical infrastructure.
Potential mechanisms include:
Covert financing, cyber intrusion, false personas, manipulated social-media networks, selective amplification, influence through intermediaries and undisclosed relationships with media or political actors.
A publicly funded U.S. media organization, including Voice of America, should therefore maintain transparent safeguards against undisclosed foreign influence.
However, the open sources reviewed for this Russia-focused report do not establish that Russian intelligence currently controls or directs VOA Persian editorial policy.
That claim should not be presented as fact without direct evidence.
The more defensible investigative question is:
What procedures exist to identify conflicts of interest, foreign-state relationships, undisclosed financial ties and coordinated influence inside public institutions?
Medical, Translation and Service-Provider Data
The same counterintelligence logic applies to outsourced commercial services.
Sensitive information can pass through:
Medical interpreters, call centers, cloud vendors, remote IT support, transcription services, customer-service systems and identity-verification companies.
A patient or customer might be a government employee, police officer, military officer, intelligence employee, journalist, refugee, dissident, scientist or government contractor.
Data might reveal:
Identity, location, phone number, medical condition, medication, family relationships, workplace information, biometric images and voice recordings.
But a potential vulnerability is not proof of foreign compromise.
An investigation should determine:
Who owns the vendor, where servers are located, which subcontractors have access, what data are stored, whether sessions are recorded, what jurisdictions apply and whether foreign governments can legally compel disclosure.
Institutional Penetration and the Wrong Way to Investigate It
The possibility that intelligence services attempt to place or recruit sources within governments, companies or universities is well established in counterintelligence practice.
But describing refugees, students, tourists or immigrants collectively as covert agents would be both inaccurate and counterproductive.
A serious investigation should follow evidence:
Bank transfers, handler communications, recruitment activity, false declarations, intelligence tasking, covert meetings, classified-information requests and operational surveillance.
That method protects institutions without treating whole communities as suspects.
Economic Pressure Against Europe
The Kremlin's September 2026 seizure of additional European corporate assets demonstrates another form of pressure.
European companies are not simply exposed to commercial risk.
They can become instruments in geopolitical disputes.
Russia's control of foreign-owned businesses, restrictions on customs transparency and creation of alternative payment systems all reduce the effectiveness of traditional Western economic pressure.Reuters
The Limits of Western Sanctions
The evidence does not support the conclusion that sanctions have entirely failed.
They have increased transaction costs, forced Russia to create alternative supply networks and triggered repeated enforcement actions.
But the A7, Garantex, Grinex and A7A5 cases show that enforcement remains incomplete.U.S. Department of the Treasury
Weak points include:
Third-country banks, shell companies, forged documentation, free-trade zones, cryptocurrency exchanges, opaque beneficial ownership, parallel imports and inconsistent enforcement among partner states.
These are the points where European and American enforcement systems remain vulnerable.
Final Assessment
Russia in 2025 and 2026 presents a distinctive form of technologically enabled authoritarian control.
Domestically, political imprisonment expanded sharply, human-rights organizations were outlawed, national-security legislation reached deeper into civic life, reproductive autonomy came under growing pressure and Indigenous activists were increasingly treated as security threats.Human Rights Watch
Digitally, Russia moved further toward a sovereign-network architecture.
TSPU equipment provides centralized censorship capabilities; TLS and SNI filtering can terminate encrypted connections before useful communication begins; VPN access is increasingly constrained; mobile internet blackouts and whitelist systems demonstrate that the state can move from selective censorship toward partial network isolation.labs.ooni.io
Economically, the stakes are enormous.
Russian e-commerce reached 11.5 trillion rubles in 2025 and 7.2 trillion rubles during the first half of 2026, meaning internet interference now affects an economy measured in trillions of rubles rather than a marginal digital sector.АКИТ
Internationally, the most significant risks are increasingly concrete rather than theoretical:
Russian intelligence operations, alleged assassination networks, European sabotage allegations, cybercrime-finance infrastructure, sanctions evasion, covert procurement and alternative digital-settlement systems.
The appropriate investigative response is therefore not generalized suspicion.
It is evidence collection.
Follow the court files, follow the TSPU infrastructure, follow the hardware serial numbers, follow the customs records, follow the shell companies, follow the cryptocurrency clusters, follow the intelligence tasking and preserve every link in the chain.
Sources and Reference Material
Human Rights Watch, World Report 2026: Russia
Human Rights Watch, Memorial Rights Group Declared Extremist, April 2026
Human Rights Watch, Russia: Attacks on Abortion Undermine Women's Rights, February 19, 2026
Amnesty International, Russia Human Rights Report
Amnesty International, Indigenous Leader Daria Egereva Detained
United Nations Human Rights Special Procedures, RUS 3/2026
OONI, Censorship Chronicles: Systematic Suppression of Independent Media in Russia
OONI, Russia Blocked OONI Explorer
Association of Internet Trade Companies, AKIT, Russian E-Commerce 2025
AKIT, Russian E-Commerce, First Half 2026
Reuters, Russia's Internet Crackdown Hobbles Small Businesses, May 8, 2026
Reuters, Kremlin Says Moscow Mobile Internet Outages Are for Security, March 10, 2026
U.S. Department of the Treasury, Garantex, Grinex, A7 and A7A5 Network, August 14, 2025
Reuters, Russian State Management of European Corporate Assets, September 29, 2026
Reuters, Russia Tightens Secrecy Around Energy and Customs Information, September 28, 2026
Financial Times, Russia's $6.9 Billion Sanctions-Evasion Network, September 2026
Research, investigation, compilation and preparation by the Editorial Team