August's VPN Crackdown in Russia Relied on Data Already Collected by Domestic Apps
Russia saw one of its largest-ever waves of VPN blocking in early August, which VPN providers say drew for the first time on data gathered by Russian apps such as Yandex, VK, Max and HeadHunter. Experts say the blocking has become increasingly automated and scalable.
In early August, Russia experienced one of its most sweeping waves of VPN blocking to date, which Anti-Corruption Foundation (FBK) figure Leonid Volkov called the biggest such attack in history. Meduza spoke with representatives of four VPN services — Liberty VPN, Amnezia VPN, Paper VPN and BlancVPN — about how this wave differed from previous ones and whether Russia's censorship agency, Roskomnadzor, appears to be following any clear logic.
Liberty VPN said its service was only lightly affected, having encountered a similar pattern roughly two months earlier and having since built an automated defense system. According to the company, the key difference this time was that, apparently for the first time, the attackers drew on data collected through popular Russian apps and services — Yandex, VK, the messenger Max, and job site HeadHunter. That accumulated trove — IP addresses, links to social media accounts, and subnets registered to specific companies — was fed into Russia's TSPU internet traffic filtering system, allowing blocking to happen at much greater scale and speed than before.
Other providers confirmed that even small and self-hosted VPN services were affected. Amnezia VPN, however, said it was not hit by this wave at all, despite media reports claiming otherwise.
How VPN users are identified
Liberty VPN explained that Roskomnadzor can detect VPN use by analyzing a visiting IP address and response time — if the delay suggests a user isn't physically located where their router claims to be, it's flagged as a VPN. The company also said that, according to a source, one Russian service was tasked roughly six months ago with automatically transmitting user data — including device model, full name and passport details — to Russia's Federal Security Service (FSB).
Providers agreed there is essentially no reliable way to fully evade this data collection. Partial mitigations include split tunneling, which routes Russian domains outside the VPN tunnel, and two-hop VPN architecture, where entry and exit server addresses differ.
Asked about reports from the business outlet RBC that Russia's Digital Development Ministry wants tighter control over IP addresses approved for corporate VPN "whitelists," Liberty VPN said circumventing such whitelists is becoming markedly more costly and complex, though market demand for the necessary IP addresses will persist regardless.

