Russia is preparing a major reform of the mobile communications market aimed at eliminating 'grey' schemes used by cybercriminals. The Ministry of Digital Development, Communications and Mass Media (Ministry of Digital Development) is considering a project that will radically change the rules of the game for Internet of Things (IoT) SIM cards. As part of the third package of regulatory acts to combat cyber fraud, the ministry plans to isolate M2M (Machine-to-Machine) interfaces into a separate, isolated category with a complete ban on voice functions.

Legal vacuum and the problem of 'grey' dealers

According to industry publications, the initiative is driven by the fact that the machine-to-machine interaction segment de facto operates in a legal vacuum. According to industry associations, technological SIM cards account for about 20% of the total volume of active numbers in the country — more than 60 million units out of a total base of over 300 million.

The main problem lies in the absence of mandatory lists of services for IoT profile tariffication. This allows criminals to use machine-to-machine exchange channels to deploy illegal voice traffic gateways (GSM-gateways) and conduct automated spam calls.

As experts note, the main factor compromising verification systems is grey dealer schemes. Wholesale batches of 'voice' SIM cards are registered under shell legal entities under the guise of contracts for the Internet of Things. This practice allows bypassing the requirements of federal legislation on mandatory individual registration of corporate subscribers on the Government Services Portal.

Technical isolation: internet only, no calls

The proposed set of amendments, which will supplement the 'Anti-Fraud 2.0' law, includes three key barriers to the illegal use of SIM cards:

  • Traffic isolation: Technical restrictions at the level of operator switching platforms (MSC), excluding the processing of calls and SMS on M2M numbers. For such cards, only packet data exchange (GPRS/LTE/5G) will remain available.
  • Ban on remote eSIM activation: Introduction of a regulatory ban on registering built-in electronic card profiles from IP addresses located outside the jurisdiction of the Russian Federation. This should prevent anonymous connections from abroad.
  • Equipment control: Mandatory monitoring of the correspondence of the IMEI identifier to the device type. If an M2M card is detected in a consumer smartphone instead of an industrial terminal, the operator will be obliged to immediately block the service.

Impact on business and infrastructure

The press service of the Ministry of Digital Development confirmed the fact of interdepartmental consultations, however, the final architecture of the amendments will be presented only after the completion of coordination procedures. Representatives of the 'Big Four' operators (MTS, MegaFon, Beeline, T2) are currently refraining from official comments.

However, independent experts warn of possible difficulties. The introduction of strict additional identification procedures will require a large-scale inventory of existing 'smart home' systems and banking equipment. This may temporarily increase operating costs for the legal sector of the economy and complicate logistics procedures for large retailers and digital service providers.

Nevertheless, according to Federal Law 'On Communications' No. 126-FZ, operators bear direct legal responsibility for the accuracy of subscriber information. In the context of the integration of verification systems, the standardization of IoT traffic becomes an inevitable stage of market modernization.