Most coverage of VPN blocking describes a cat-and-mouse game about traffic: the censor learns to recognise what a VPN connection looks like, the provider disguises it, and round it goes. What is reported in Russia this month is a different mechanism, and the difference matters more than the headline does.
What is reported, and how firmly
On 5 August 2026, Euronews reported that Roskomnadzor, the Russian communications regulator, is targeting encrypted connections ahead of the September elections, in an action described as the largest of recent years. The exact scale is not known, and the report says so plainly. We are not in a position to test anything from inside Russia, so what follows is what is documented, marked as such.
The reported method is the part worth understanding. Rather than identifying VPN traffic by its signature, the restrictions are said to have targeted the infrastructure directly: the IP addresses of the hosting providers where VPN services sit were added to a blacklist. Several dozen autonomous systems, the large blocks that networks are organised into, were identified, and all the prefixes attached to them were blocked.
For scale, Roskomnadzor confirmed in February 2026 that it had blocked 469 VPN services. Separately, a budget of 2.27 billion roubles, roughly 29 million dollars, was allocated to developing an AI-assisted filtering system intended to automate the detection and blocking of prohibited content and encrypted connections.

Why this defeats obfuscation
This is the point that gets lost. Obfuscated servers work by making VPN traffic look like ordinary HTTPS, so that a firewall inspecting the traffic cannot tell what it is. That is a good answer to signature-based blocking, and it remains a good answer to it.
It is not an answer to address-based blocking. If the destination range itself is unreachable, it no longer matters what the traffic looks like, because there is nothing at the other end to reach. Disguising a letter does not help when the entire postal district has been closed.
That is why a provider can advertise obfuscation honestly and still be unreachable in a country doing this. The two mechanisms are stacked, not alternatives, and a claim that one product defeats all blocking should be read with that in mind.
What actually tends to survive, and the honest caveat
Address-range blocking has a cost for the censor: hosting ranges carry more than VPNs, so blocking a whole prefix takes down unrelated services sitting in the same block. That cost is the practical limit on how far this method goes, and it is why blocks of this kind are often partial and shifting rather than total.
What follows from that is unglamorous. Infrastructure that is not concentrated in a few well-known hosting ranges is harder to sweep up in one action, which is an argument for self-hosted or less concentrated endpoints rather than for any particular commercial brand. We are not going to tell you a specific service currently works in Russia, because we cannot verify it from here and a claim like that goes stale within days.
Before anything else, the legal question
Using a VPN is legal in most countries, and Russia is a case where the picture is more restrictive and moves. Our country-by-country look at VPN legality sets out what is documented rather than what is assumed. Anyone travelling to or living in a country that restricts these tools should check the current position rather than rely on an article, including this one.
The short version
The story is not that Russia found a cleverer way to spot VPN traffic. It is that it stopped trying to spot it, and went after the addresses instead. That is a blunter instrument with real collateral damage, and it is also the one that current consumer defences are least able to answer.
Reporting on the current wave: Euronews, 5 August 2026.
Stay connected anywhere with NordVPN
Obfuscated servers for restrictive networks · 60+ countries · 30-day money-back



