Protection Layer

The Roof Has Windows

Everyone knows the Russian state shelters its ransomware crews. What gets less attention is that it also watches them: formally, comprehensively, and without a court order. Once you see the surveillance, tolerance stops being a plausible story.

By Reno 31 Jul 2026 15 min read Open Research
The roof has windows · illustration

On the morning of 14 January 2022, the Russian state showed the world how much it knows about its own ransomware operators. FSB officers hit twenty-five addresses across five regions in a single coordinated sweep and detained fourteen members of REvil, the crew behind some of the worst ransomware attacks ever mounted against the West. There was no manhunt and no attribution puzzle. Washington asked, and Moscow drove straight to the doors. Finding them was never the hard part. Confirmed reporting

That morning is usually told as a story about diplomacy, a gesture to Washington that was later quietly unwound (we return to how it ended below). We read it as a story about visibility. The state saw REvil the whole time, the way it sees the rest of the ecosystem it shelters, because it has spent three decades building the machinery to see. This June, that machinery got its newest user manual.

Order No. 1174 of the Ministry of Digital Development runs to sixty-nine pages. Stripped of the legal language, it tells every owner of a network with its own address block, a class that includes the commercial hosting providers ransomware infrastructure runs on, how to make its data searchable by the security services on demand: passport data, full names, tax numbers, banking details, IP addresses, domains, logins, location coordinates, roughly two dozen categories in all. There is no warrant procedure in those sixty-nine pages. There is a technical specification. The security service does not request access to Russian networks. It queries them. Confirmed reporting

Official Internet Portal of Legal Information · Register Entry (translated)
InstrumentOrder of the Ministry of Digital Development, Communications and Mass Media No. 1174 Signed16 December 2025 RegisteredMinistry of Justice, 22 May 2026, registration No. 86587 Published23 May 2026, publication No. 0001202605230002 In force3 June 2026 ScopeOwners of technological communication networks holding an ASN, for use by state bodies conducting operative-investigative activity
Source: publication.pravo.gov.ru, official register entry. Public record, reproduced for analysis.

Read quickly, that looks like a 2026 expansion of state surveillance. Read carefully, it is something more damning. When Meduza put the order next to its legal predicates in an analysis published 8 June 2026, it found that the FSB gains no new categories of data at all: the same types were already mandated under a ministry order from 29 October 2018 (No. 573) and a government decree from September 2023. What Order 1174 actually does is solve an engineering problem. Organizations covered by the older mandates did not know how, technically, to deliver what the law already required. The 2026 order gives them the technical instructions. Meduza's English edition put the significance plainly: this is not about telecoms anymore, it is about building "a parallel SORM inside every major company in the country." Confirmed reporting

The windows into Russian networks were not installed in 2026. They were installed years ago. This year the state standardized the glass.

This matters for the argument this site exists to make. Our framework holds that the ransomware ecosystem rests on three dependencies: the money, the metal, and the krysha, the roof of active state protection. A common softer framing, one we have used ourselves in earlier work, describes that protection as "tacit tolerance": Moscow simply declines to look. The record assembled below says otherwise. The Russian state operates one of the most complete domestic visibility regimes on earth, technical and financial, and it is pointed at exactly the infrastructure and cash-out channels its ransomware crews depend on. A state that sees everything and moves against nothing has not failed to notice. It has decided.

Fig. 1 · The visibility edges this article walks · excerpt from the Observatory ecosystem map
THE STATE FSB Rosfinmonitoring Central Bank (CBR) Tax Service (FNS) Bulletproof Hosting the metal Ruble Banking System the money, onshore Crypto Exchanges the unregulated seam Ransomware Crews the protected SORM · Order 1174 115-FZ · ZSK · Art. 86 feeds Transparent Blockchain tracing, not regulation hosts on cashes out through KRYSHA · ACTIVE PROTECTION
Structural excerpt, relationships as of Jul 2026: every layer the crews depend on carries a state visibility edge, except the crypto-exchange seam, which carries tracing but no regulation. Explore the full map →

The wire

Start with the technical layer, because it is the oldest and least ambiguous.

SORM, the System for Operative Investigative Activities, has obligated Russian telecommunications providers to build interception capability for the security services since 1995. It has grown in three overlapping generations: SORM-1 (1995) for telephone networks, SORM-2 (1998) for internet traffic, with ISPs required to install the monitoring equipment at their own expense while being denied access to the boxes themselves, and SORM-3 (a 2014 ministry order taking effect in 2015) extending collection and retention across all media, with selectors including IP addresses, IMSI and IMEI identifiers, and deep packet inspection. Confirmed reporting

The legal check on this system is largely ornamental. Russian law does require judicial authorization to intercept the content of communications. But the European Court of Human Rights, ruling unanimously in the Grand Chamber case Roman Zakharov v. Russia on 4 December 2015, found the framework lacking "adequate and effective guarantees against arbitrariness": the security services enjoy direct technical access to communications, and the law imposes no obligation to show the authorization to the network operator, who has no right to demand it. The 2016 Yarovaya amendments went further, requiring operators to retain content and metadata and to disclose "all other information necessary" to the authorities on request, without a court order. Confirmed reporting

Then, in the same December week that Order 1174 was signed, the State Duma passed a further amendment to the law on the FSB: from 1 April 2026, the service may obtain, free of charge and on the order of its own director, copies of databases or parts of databases held by any organization in Russia, no court involved. Any customer list, any billing system, any know-your-customer identity file a company keeps on its clients is now formally available to the FSB on internal signature. Confirmed reporting

Apply this to the ecosystem we track. Russian-hosted bulletproof hosting has always been described, correctly, as a jurisdiction problem: Western legal process does not reach it. The point that completes the picture is that the FSB's process does reach it, formally and comprehensively. A provider like the ones our Observatory tracks on the Bulletproof Hosting node holds an ASN. It is therefore inside the class Order 1174 addresses. The command-and-control servers, the leak-site backends, the staging infrastructure that Western agencies spend months attributing from the outside, all of it sits on networks the FSB is legally wired into from the inside. When ransomware infrastructure on Russian commercial hosting goes untouched for years, the explanation cannot be that nobody could see it.

The ledger

The technical wire would matter less if the money could still hide. It cannot, or at least not from Moscow.

Russia's financial surveillance stack has three interlocking layers. The first is Rosfinmonitoring, the financial intelligence unit, fed by mandatory reporting under Federal Law 115-FZ since 2001: transactions over statutory thresholds reported automatically, suspicious transactions reported within one business day, tens of millions of reports a year across both streams per the FATF's 2019 evaluation. Since 2020 the agency has also been building a dedicated cryptocurrency tracing system, Prozrachny Blokchein, "Transparent Blockchain," developed with the Lebedev Physical Institute, covering more than twenty crypto assets, with its bank pilot completed at the end of 2025 by the agency's own announcement. Confirmed reporting

This is not a paper capability. A deputy director of the agency, Evgeny Gileta, told the parliamentary paper Parlamentskaya Gazeta on 23 April 2026 that the system was used in 120 financial investigations in 2025 and contributed to opening more than 40 criminal money-laundering cases. Confirmed reporting His colleague Olga Tisen, the agency's head of legal, said publicly in May 2025 that crypto anonymity is a "myth," and that every exchange with so much as one representative office in Russia, Binance included, shares wallet-owner data with Russian law enforcement. Credible reporting

The second layer is the Central Bank. Since 1 July 2022 it has operated the Know Your Client platform, a state-run risk score that sorts every legal entity and individual entrepreneur in the country into green, yellow, or red tiers, with roughly 0.7 percent flagged red. And when the state decides a category of financial behavior should stop, the system demonstrates its reach immediately. A Central Bank order signed 5 November 2025 doubled the suspicious-transaction criteria used against "dropper" cash-out accounts, effective 1 January 2026. Monthly account and card blocks jumped from roughly 330,000 in 2025 to a reported two to three million in the first weeks of January. Amendments to 115-FZ signed 15 December 2025 add the power to freeze a listed suspect's assets without warning them first, with blocks running up to a year in extremism-linked cases as provisions phase in through 2026 and 2027. Confirmed reporting Whatever else this is, it is not a state that lacks the means to shut down mule networks. It shut down millions of them in a month, when the victims were Russian.

Fig. 2 · Monthly account and card blocks, Russian banks (anti-dropper criteria expansion, effective 1 Jan 2026)
~330K
2025monthly average
Vedomosti
2–3M
Jan 2026first weeks
Vedomosti
Reported monthly blocks before and after CBR Order OD-2506 expanded suspicious-transaction criteria from six to twelve. Source: Vedomosti, 19 Jan 2026. Shown to convey demonstrated enforcement capacity at scale.

The third layer is the tax service. Since 1 July 2014, banks automatically notify the FNS of every account an individual opens or closes; the service's Nalog-3 system exists, by its own description, to assemble comprehensive taxpayer dossiers. Crypto has been folded in steadily: the 2020 digital-assets law classified it as property and made legal protection of crypto claims conditional on declaration, the November 2024 mining law taxed extraction and barred miners from simplified regimes, and pending legislation would require residents to notify the FNS of foreign-hosted wallets from 1 July 2026, a bill still moving through the Duma. Confirmed reporting

And the tax service has already demonstrated what these powers mean for cybercriminals specifically. After a Perm-based carding group was convicted in April 2024 of trafficking stolen American bank-card data, an interregional FNS inspectorate separately assessed personal income tax arrears on their undeclared crypto income from 2019 to 2021: roughly 62 million rubles against one member, 89 million against another, and over 258 million claimed against the group's biggest earner in his bankruptcy. Credible reporting Sit with what that case means. The Russian state measured, to the ruble, income earned by defrauding American cardholders, and then billed for its share. The proceeds of foreign-facing cybercrime are not invisible to Moscow. They are, on the record, taxable.

One seam in the ledger deserves its own sentence. When the Eurasian Group's follow-up evaluation of Russia (adopted 2023, published 2024) re-rated the country on the FATF's virtual-asset standard, it moved Russia from compliant to partially compliant: the one conspicuous regulatory hole sits precisely at the crypto-exchange layer, the layer where ransom payments become rubles. Confirmed reporting The banking system is wired for total visibility. The off-ramp the ransomware economy uses is the one part left unregulated. We return to that choice below.

The demonstration

Capability arguments can always be waved off as theoretical. These five cases are why this one cannot.

REvil, January 2022. The raid this piece opened with deserves its numbers: fourteen detentions across twenty-five addresses in one morning, over 426 million rubles seized alongside 600,000 dollars, half a million euros, and twenty luxury cars, with the FSB stating openly that it was acting on a US request. Confirmed reporting Then the geopolitical moment passed, and the case record shows what enforcement looks like when Moscow is merely keeping up appearances. On 25 October 2024, nearly three years later, a military court in St. Petersburg sentenced four defendants to between four and a half and six years, not for ransomware operations against Western critical infrastructure, but for "illegal circulation of means of payment" and, for two of them, malware distribution. On 23 June 2025 the remaining four were convicted and released in the courtroom, their pretrial detention, credited under Russian law at one and a half days per day held, having already covered their five-year terms. No defendant was ever charged with the extortion campaign that prompted the US request. No one was extradited. Confirmed reporting

Mikhail Matveev. The LockBit and Babuk affiliate known as Wazawaka was indicted in two US districts (returned December 2022, unsealed 16 May 2023 alongside OFAC sanctions and a ten-million-dollar reward). His response was to give interviews, print merchandise of his own wanted poster, and observe that Western sanctions were "a plus for my security." Confirmed reporting He was right about the logic. Russian authorities reportedly arrested him in Kaliningrad in late November 2024 on a domestic malware charge, and researchers tracking the case report he was released on bail; the case reportedly concerns activity that touched Russian or CIS interests, not the American indictments, and as of this writing we can find no public verdict. Credible reporting Half a decade of loud, foreign-facing ransomware activity under a name the FBI put a bounty on drew no Russian action at all. A domestic irritant drew an arrest within weeks of surfacing.

The Yahoo case. The oldest proof, and the most literal. Alexsey Belan was publicly indicted in the United States in 2012 and again in 2013, placed on the FBI's Cyber Most Wanted list, arrested in Europe on a US request in June 2013, and escaped to Russia. What happened next is the krysha compressed into a single Justice Department sentence: instead of acting on the Interpol Red Notice and detaining Belan, FSB officers Dmitry Dokuchaev and Igor Sushchin used him, directing his 2014 breach of Yahoo that compromised half a billion accounts, per the March 2017 US indictment of the officers themselves. Confirmed reporting The state did not merely see a wanted criminal on its soil. It hired him. The coda shows what the system actually punishes: Dokuchaev and his superior in the FSB's Information Security Center, Sergei Mikhailov, were arrested in December 2016 and convicted of treason in 2019, for passing information to the Americans. Confirmed reporting Employing criminals was the job. Talking to the adversary was the crime.

Evil Corp. Covered at length in our Evil Corp series and The Protected, so briefly here: Maksim Yakubets and Igor Turashev were indicted by the United States on 5 December 2019 over the Dridex operation, with Treasury stating in the same action that Yakubets was working for the FSB as of 2017. Neither man has ever been arrested, anywhere. And in October 2024 the US, UK, and Australia sanctioned the man who performed the protection: Eduard Benderskiy, former FSB Spetsnaz officer and Yakubets's father-in-law, designated for "ensuring they were not pursued by Russian internal authorities." Confirmed reporting Protection here is not an inference. It is a documented function with a name attached.

Garantex. The exchange that laundered ransom payments for Conti, LockBit, Ryuk, and others operated from Federation Tower in Moscow City, one of the most heavily surveilled commercial addresses in Russia, under every reporting obligation described in the previous section. OFAC sanctioned it on 5 April 2022. It then processed more than sixty billion dollars over the following three years, per Elliptic, until a US-European operation seized its domains on 6 March 2025. Within months its operators stood up a successor, Grinex, moving value through the ruble-backed token A7A5, and Treasury re-designated the whole structure on 14 August 2025. Confirmed reporting Across those three post-sanctions years, with Rosfinmonitoring publicly boasting that crypto anonymity is a myth for anyone with a Russian office, Russian financial supervision, which blocked millions of domestic mule accounts in a single month, took no public action against the most notorious cash-out platform in the country. The full reconstruction is in After Garantex.

The pattern across all five is not complicated. Enforcement happens when it serves a diplomatic purpose, and is then quietly minimized; or when an actor crosses the domestic line; or never, when the actor is useful and properly connected, and in the Yahoo case the connection was an employment relationship. In no case was the constraint an inability to find anyone. The state's problem has never been sight.

The objections

The strongest honest counterarguments to this thesis deserve stating, because the thesis survives them.

First: SORM is decaying. Carnegie's Gavin Wilde has documented that Western sanctions cut Russian telecoms off from servicing the Nokia and Ericsson equipment much of the intercept stack rides on; in his phrase, the sector is "on a shot clock," though what that decay has cost the FSB in actual casework is not measurable from open sources. Confirmed reporting Second: encryption. SORM's provider-side architecture yields metadata, not content, against end-to-end encrypted platforms, and the state's own campaigns against Telegram and for data localization are indirect evidence that officials feel the gap. Analyst inference Third: the system is sloppier than it looks. Soldatov and Borogan, the most credible chroniclers of the Russian security services, have documented uneven filtering, mistaken blocks, and thin prosecution rates; the Zakharov judgment itself found that Russian law prohibits logging intercepts, which is as consistent with disorder as with secrecy. Confirmed reporting Fourth: the picture is fragmented across rival agencies, the FSB and the MVD's Department K, with documented turf conflict and mutual distrust. Confirmed reporting

All four points are real. None of them rescues the tolerance theory, for one shared reason: the proof cases already control for them. A decayed, encrypted-blind, sloppy, fragmented apparatus still produced fourteen coordinated REvil arrests in one morning when instructed to, still located Matveev the moment his work turned domestic, and still, through the financial stack, taxed the crypto income of individual carders to the ruble. The gaps are marginal. The outcomes are categorical. Marginal gaps do not produce categorical outcomes.

The fifth objection is the interesting one: corruption. On this account, visibility is monetized rather than actioned; officers sell protection instead of enforcement, so the state as such never "decides" anything. The best evidence is Grigory Tsaregorodtsev, the FSB counterintelligence officer in Perm who took roughly 160 million rubles, about 1.7 million dollars, from the same carding group the tax service later billed, in exchange for shielding them, and who was sentenced to nine years in April 2024, having been found with, among other assets, one hundred gold bars. Confirmed reporting But look at what that case actually establishes. Protection was for sale because the officer could see the criminals and they knew it; the product being sold was the state's own gaze, averted. And when he was punished, he was punished for freelancing, for selling at retail what the system distributes by policy. Corruption does not contradict the krysha model. It is the krysha model, running at the individual scale, priced. The alternative reading, that protection rackets somehow indicate state blindness, requires the rackets to have had nothing to sell. Analyst inference

What the windows change

If the roof were blind, the policy prescription would be modest: help Moscow see, share indicators, request cooperation. Twenty years of that approach produced the case record above. The roof has windows, and that reframes the leverage.

It shifts the attribution burden. Every Western designation and indictment of a Russia-based actor should be written on the record now available: the target operated on networks the FSB is wired into by law, cashed out through a banking system under total supervisory visibility, and filed, or conspicuously did not file, with a tax service that receives his bank data automatically. "We were not aware" is not available to a state whose surveillance statutes are published on its own legal portal.

It validates targeting the protectors, not just the protected. The Benderskiy designation is the template: name the specific individuals who perform the protection function, and treat protection itself as the sanctionable conduct. Our tracking of the state-organ nodes on the Observatory map is oriented to exactly this: the krysha is not an atmosphere, it is people, and people can be listed.

And it identifies the one deliberately unbuilt window as the pressure point. Russia wired every layer of its financial system for visibility except the crypto-exchange off-ramp, the single layer the ransomware economy cannot function without, and the FATF process has now formally recorded that gap. A state does not construct the most comprehensive financial surveillance apparatus in its history and forget one room. The unregulated seam between Garantex and its successors and the ruble is not an oversight to be remedied with technical assistance. It is policy, and it should be attacked as policy: every exchange that fills the Garantex role should be treated, from designation day one, as an extension of the protection system rather than a compliance failure inside it. Analyst inference

The money, the metal, the krysha. This piece has been about the third, but the finding runs through all three: the state that shelters this ecosystem watches every part of it. The roof was never over the operation. The roof is part of the operation, and it has windows on every floor.

Sourcing & confidence

This dispatch draws on Russia's official legal register, ECtHR jurisprudence, US Treasury and DOJ actions, FATF/EAG evaluations, and Russian official statements as reported by state, independent, and trade press, independently verified against primary sources where available. Confidence labels follow standard analytic practice. One note on Order 1174: the official copy of its 69-page technical annex is published as a scanned image, so the interface and data-type details are sourced from Russian legal and trade press that reviewed the document, checked against the order's register entry.

Confirmed · multiple independent sources, including official register, designation, or indictment language.
Credible · single strong source or consistent reporting, not yet officially confirmed.
Analyst inference · End Krysha's own assessment, drawn from the evidence above.

SORMOrder 1174Rosfinmonitoring115-FZFNSKryshaProtection Layer