Russia's Federal Security Service (FSB) has placed the country's internet under the control of its Second Service, the unit responsible for fighting terrorism and political opposition, according to an investigation by The Bell reported by Novaya Gazeta Europe. The shift came after the data-collection system introduced by the so-called Yarovaya law failed to work as intended for nearly a decade, and it has since led to more blocks, heavier fines and an attempt to shrink the telecom market.

The Yarovaya law, proposed in April 2016 by lawmaker Irina Yarovaya and senator Viktor Ozerov, required telecom operators and internet companies to store metadata, call records, messages, files and other traffic. The FSB was to receive round-the-clock remote access to that data through the SORM surveillance system. The original requirements proved almost impossible to implement, and between 2016 and 2018 the government repeatedly reduced the storage periods. By the time the law took effect in 2018, operators were required to keep SMS messages for six months and internet traffic for one month.

Control over the system initially remained with technical departments of the FSB. The Second Service, which focuses on terrorism and opposition activity, took no part in discussions of either the Yarovaya law or the later sovereign internet law. For several years, the agency largely tolerated incomplete implementation of SORM. Operators were reluctant to spend tens of billions of rubles on equipment, and fines of up to 200,000 rubles were low enough that many companies found it cheaper to pay them. In exchange, operators informally handed the security services information about specific subscribers or IP addresses.

The turning point came in January 2022, when Russian schools, courts, banks, companies and government agencies began receiving mass emails with bomb threats. The number of such messages rose almost tenfold in a year and exceeded 20,000. The Second Service held meetings with Yandex, VK, Kaspersky Lab, Positive Technologies and other companies, demanding the ability to instantly identify the real senders of the emails. Specialists told security officials that this was technically impossible.

Pressure increased in 2022 and 2023, when authorities adopted more than ten legal acts tightening SORM requirements. Owners of autonomous networks and hosting providers were obliged to install surveillance equipment, and regulators were allowed to suspend licenses and impose turnover fines for non-compliance. Starting in November 2022, the FSB's 12th Centre began sending Roskomnadzor information about operators lacking SORM. By August 2023, 33 companies had received warnings, but none of the large operators were among them.

In late 2023, the FSB publicly acknowledged the failure. Alexander Samoilov, an employee of the 12th Centre, said operators were formally signing contracts, changing legal entities and obtaining new licenses to avoid installing the equipment. The situation changed dramatically after the terrorist attack at Crocus City Hall in March 2024. The leadership of the Second Service explained the attack by saying that Telegram did not cooperate with Russian authorities and that SORM did not make it possible to track the preparation of such assaults.

After the attack, FSB officers from the central apparatus traveled to the regions to check whether local offices could connect to each operator's SORM system from their own consoles. The inspections showed that the real system differed significantly from what the law prescribed. According to sources cited by The Bell, the FSB's scientific and technical service received a reprimand, and the Second Service became the main curator of the internet.

The number of punishments then rose sharply. In the two years after the Crocus attack, Moscow courts imposed at least 140 fines on operators and internet companies for SORM violations, compared with only 50 in the previous four years. At the same time, authorities began forcibly adding online services to the registry of information dissemination organizers, whose members must install SORM. Since the beginning of 2024, 124 new resources have been added to the registry.

A regional inspection in the Belgorod region in March 2025 illustrated the scale of the problem. Within a week, the local FSB office sent Roskomnadzor reports on 55 companies whose SORM was missing or defective. The list included Rostelecom and MTS. According to documents reviewed by The Bell, the FSB found that MTS did not even have documents confirming the presence of SORM in the region. The inspection may have led to a meeting between President Vladimir Putin and the head of the Second Service, during which the latter proposed restoring order on the internet.

By autumn 2025, the Second Service had become involved in a reform of the communications market. The operator Er-Telecom proposed tightening requirements, introducing FSB and Roskomnadzor inspections and effectively reducing the number of market participants. Representatives of the Second Service began attending the relevant meetings. According to sources cited by The Bell, security officials wanted to leave in place only a few large operators, which would absorb small companies and install full SORM equipment. One source described the principle as: «We will clear the market for you, and you buy SORM».

The new approach soon translated into visible restrictions. In February 2026, state media published FSB materials accusing Telegram of being used in the preparation of hundreds of attacks. In the spring, the authorities blocked Telegram and WhatsApp. The Second Service also pushed for fines related to searches for extremist material, recognition of VPN use as an aggravating circumstance, and a tougher fight against services used to bypass blocks.

The investigation also points to a new licensing project backed by the Ministry of Digital Development between April and June 2026. Under the proposal, an operator seeking a general license would need charter capital of more than one billion rubles, a fee of 50 million rubles and a minimum period of operation. The measure, if adopted, would make it significantly harder for small operators to survive, effectively consolidating the market in the hands of a few large players able to meet SORM requirements.