New security era in banking: Critical warning for infected devices
Starting March 1, 2027, Russia will block card payments and money transfers from devices where malware is detected.
12punto
As security measures in banking are tightened against cyber fraud and data theft, Russia is preparing for a new practice for financial transactions. In the country, banks will be able to detect malicious software on devices that customers use to perform transactions via mobile applications and internet banking.
The regulation, announced by the Russian Interior Ministry's Department for Combating Illegal Use of Information and Communication Technologies, is planned to come into effect on March 1, 2027. Accordingly, certain financial transactions of users whose devices are found to have viruses, spyware, or similar malware will be automatically rejected.
Under the new practice, card payments, electronic money transfers, and transactions attempted via the Faster Payment System may be blocked for security reasons. The goal is to prevent fraud attempts made through compromised or risky devices.
In Turkey, banks already use similar security layers within the framework of the BRSA's "Regulation on Information Systems of Banks and Electronic Banking Services." Mobile banking applications can stop transactions or request additional verification when they detect security risks such as unauthorized access or root/jailbreak, in addition to malware.
Banks can also restrict mobile banking usage when a suspicious device, unusual location, or risky access is detected. Thus, the personal device security of users is becoming an increasingly decisive factor in the approval of financial transactions.