Russian banks, starting from March 1, 2027, will be obliged to refuse clients' transfers if malicious software is detected on their devices. This follows from Federal Law No. 210-FZ of June 26, 2026. The new rule applies to all popular transfer methods: bank card operations, electronic money transfers, and transfers via the Faster Payments System (SBP).

As Anatoly Aksakov, head of the State Duma Committee on Financial Markets, explained, the law expands the list of signs of suspicious operations that banks and telecom operators must respond to. According to him, if malicious software code is detected on a device, money transfer operators must check and stop the transaction.

Upon detection of malicious software, the bank is obliged to inform the client of the reason for refusal and offer an alternative way to conduct the operation – for example, transfer money from another device or personally visit a bank branch.

To detect malicious programs on clients' devices, banks will need to obtain user consent. Existing client agreements must be re-signed by September 1, 2027.

Read more on the topic: