A new milestone in cybersecurity: Law No. 210-FZ changes the rules of the game

The Russian financial sector is preparing for major changes in its security system. As of March 1, 2027, a new Federal Law No. 210-FZ, adopted on June 26, 2026, will come into force. According to the document, banks will be required to refuse clients money transfers if signs of malicious software are detected on the devices used (smartphones, tablets, PCs). This decision is a response to the growing threat of cyber fraud, where criminals use viruses to hijack control over banking applications.

How the blocking system will work: mechanism and limitations

The new rule applies to all major types of operations: transfers from bank cards, transactions with electronic money, and payments via the Fast Payment System (FPS). If the bank's antifraud system detects malicious code on the client's device, the transaction will be declined. It is important to note that the law does not imply a total account block or freezing of funds. It concerns exclusively the blocking of a specific transaction initiated from an infected device. At the same time, banks will not gain full access to the smartphone's file system; the exact scanning parameters and the volume of collected data will be regulated by separate technical standards.

Alternatives for the client: what to do in case of transfer refusal

The law provides for consumer protection in the event of a transaction refusal. The bank must not only decline the payment but also clearly explain the reason to the client — the presence of malicious software. As an alternative, the client must be offered other ways to conduct the transfer. For example, the user can use a clean device (another phone or computer) or visit a bank branch to conduct the operation through secure terminals or with the help of staff. This ensures the availability of financial services while minimizing the risk of fund loss.

Fighting money theft: why this became necessary

The main goal of the innovation is to combat money theft using malicious software. Modern trojans are capable not only of intercepting logins and passwords but also of gaining access to banking applications in real-time, replacing user actions. Criminals can manage payments directly from the victim's device, making the theft process invisible. Now, the presence of malicious software will become a critical risk factor that banks must consider when conducting any operation, which will significantly complicate the work of cybercriminals.