In short: Russia's May 2025 turnover fine law — up to 3% of annual revenue for repeat data breaches — has given hackers a powerful new extortion lever. Security researchers at УЦСБ (Ural Centre for Security Systems) documented in September 2026 that cybercriminals are increasingly demanding a "quiet ransom": pay us to keep your breach secret, or we'll report it to Roskomnadzor ourselves.
What happened
In September 2026, analysts at УЦСБ, a leading Russian cybersecurity integrator, published findings on a new extortion pattern emerging across the Russian corporate sector. After successfully stealing data — customer databases, internal communications, financial records, or source code — attackers skip the traditional ransom-for-decryption demand. Instead, they offer silence: pay us, and we won't tell the regulator.
SOC Director Konstantin Mushovec of УЦСБ stated: "Hackers are increasingly offering companies a quiet buyout — payment not to inform the regulator about the breach." If companies refuse, attackers proactively file complaints with Roskomnadzor, triggering an official investigation that carries consequences far costlier than the ransom itself.
Learn how modern data theft schemes work and what defences are most effective in our cybersecurity blog.
How the "quiet ransom" scheme works
Traditional ransomware extorts payment for decryption access: pay up or you can't use your own data. The quiet ransom scheme is different: the data is already stolen. The leverage isn't operational disruption — it's legal liability.
Russia's Law No. 420-FZ, effective May 30, 2025, introduced turnover fines for personal data breaches. For repeat violations, companies face fines of 0.1%–3% of annual revenue, with a minimum of 25 million rubles. Breaches involving biometric data carry a maximum fine of 500 million rubles.
For a company with multi-billion ruble annual turnover, a potential fine can easily exceed 100–200 million rubles. Against that backdrop, a demand for a smaller silence fee can seem rational — and that calculation is exactly what extortionists are banking on. Critically, paying offers no guarantees: attackers can sell the same data multiple times or deploy it later in attacks targeting the company's own customers.
Scale of the threat: key statistics
УЦСБ reports that combined attacks — simultaneous encryption, data theft, and DDoS — have become standard practice in 2026. DDoS attacks on Russian companies rose 27% in H1 2026 compared to the same period in 2025, with industrial enterprises the most frequently targeted sector.
According to Kommersant, approximately 120 data breaches were officially recorded in Russia in 2025 — but analysts estimate the true number is far higher, as most incidents are deliberately concealed. This culture of secrecy is precisely what created the quiet ransom opportunity: attackers know companies fear regulatory scrutiny more than the breach itself.
In the financial sector, 76% of stolen data consists of personal information — names, phone numbers, and account details. The average global cost of a data breach in 2025 was approximately $1.16 million, and with Russian turnover fines added, total costs for affected companies can be substantially higher.
What this means for your personal data
The quiet ransom scheme harms end users regardless of how the company responds. Your data ends up in criminal hands either way.
If the company pays quietly — Roskomnadzor may never investigate, and you won't receive a breach notification about data that directly concerns you. If the company refuses — your data may surface on dark web forums or be sold to other criminal groups.
Protecting your own traffic and passwords is within your control right now. Encrypting your network connection prevents data interception in transit, particularly on public Wi-Fi where the risk is highest. This layer of defence is entirely independent of any company's security practices.
How to reduce your personal risk right now
You can't control how companies secure their servers. But you can limit the damage when they fail:
- Unique passwords per service. A different password everywhere means one breached account can't unlock the rest. A password manager (Bitwarden, 1Password) makes this practical.
- Two-factor authentication. Enable 2FA wherever possible: a leaked password alone won't be enough to take over your account.
- Check your exposure. Have I Been Pwned (haveibeenpwned.com) shows whether your email appeared in known breaches.
- Minimise your data footprint. Don't fill in optional fields, and avoid granting biometric consent where it's not genuinely necessary.
- Encrypt your traffic. Especially important on public Wi-Fi in cafes, airports, and shopping centres, where unprotected connections are most easily intercepted.
Sources
- УЦСБ: Hackers Increasingly Extort Firms With Data Breach Disclosures — news.mail.ru, September 6, 2026
- Rising Data Breach Fines Fuel Extortion Wave — Kommersant
- Hackers Increased Pressure on Russian Business Through Threat of Regulatory Disclosure — www1.ru, September 6, 2026
