Is there any connection between drones and “allowlists”? We proved there was none.
The State Duma elections were held on September 18–20, 2026, under connectivity restrictions which had been announced well in advance. Back on June 15, 2026, Ella Pamfilova, head of the Central Election Commission (CEC), proposed that Russians choose between “the internet or saved human lives.” It remained unclear exactly which lives she referred to.
By the election day, the restrictions had long since become background noise. According to data from the measurement company Vigo, over 60% of mobile sessions in the country ran under restrictions in the first half of 2026. In the Belgorod, Bryansk, and Kursk regions, about 90% of connections in July worked only through so-called “allowlists” (registries of websites approved by the state). The exact contents of these “lists” have been unknown.
The government’s rationale for internet shutdowns
Drones were not even mentioned in the legislation. The usual justification for restrictions was fraud or “digital sovereignty”. Vladimir Putin, for instance, spoke about the latter back in December. Yet the Ministry of Digital Development (Mintsifry) kept talking about drones. In March 2026, for example, the ministry denied reports of restrictions for residential ISPs, arguing that wired internet is not needed for drone attacks. In the summer of 2026, officials cited the fight against drones to explain the new IMEI registry (a database that tied mobile devices to their subscribers by hardware ID).
Drones were not the only reason given for restrictions. For instance, on August 13, 2025, Roskomnadzor (Russia’s communications regulator) explained the ban on WhatsApp and Telegram calls as a fight against scammers and terrorists. At the same time, the Russian Central Bank pointed out that the share of fraud committed through messaging apps had actually fallen in 2024 from 22.5% to 15.7%.
In some cases, restrictions were not explained at all, in particular, the restriction on roaming for foreign SIM cards, or the new authorization rules.
Drones and shutdowns: where the geography does not match
Attacks are distributed unevenly. From early 2025 through February 2026, according to calculations by Novaya Gazeta Europe, drone strikes were recorded in 57 regions, but half of all incidents occurred in just five regions: the Belgorod, Kursk, Bryansk, and Rostov regions, and Krasnodar Krai.
Shutdowns, however, are distributed differently. For example, according to data from Novaya Gazeta Europe, 33 regions that had shutdowns throughout all of 2025 did not experience a single attack. And by March 2026, every one of the 83 regions of Russia’s internationally recognized territory had seen at least one shutdown.
Attacks and “allowlists” diverge in timing too. Novaya Gazeta Europe, together with the project Na Svyazi (“Connected”), calculated that 85% of 2025 shutdowns fell on days when no drone strikes were reported in that region. In the five most-attacked regions, the internet was shut down on more than 70% of days starting from July 2025, including days when no drones came at all.
Is there any connection between drones and “allowlists”?
We compared the timing of drone alerts against signs of shutdowns in each region. The data came from a third-party international measurement project, Internet Outage Detection and Analysis (IODA), covering the period from May 19 to August 24, 2026. This tool comes with a caveat: it can only tell whether a region’s networks respond from the outside, not what’s actually happening on a subscriber’s connection. Under the “allowlist” regime a region can look connected even when nothing loads for the people living there.
Out of 506 alerts tied to a specific region, we ended up with 38 “region and time of day” pairs to compare against a control day a week earlier. A deviation was observed in only two pairs, both involving annexed Crimea. In the rest, there were if anything fewer outages after the alert than before it. Vigo’s measurement for July of the same year found that about 90% of connections in the border areas ran only through the list.
The exact time is known for only a third of the 568 alerts collected. For the rest, we only know the part of the day (morning or evening). The pilot data collection ran for just 15 days, and with an effect size this small, statistical significance at the 0.05 level is not reachable in under 20 days of data collection.
The editorial team does not yet have its own measurement tool as of publication: an in-house client for direct measurements is still being finished and rolled out, and none of the figures in this piece come from it. The team will publish that data later, in a separate update.
Even officials oppose the “allowlists”
The official position has not changed. At the height of the Moscow shutdown, presidential press secretary Dmitry Peskov stated that the restrictions “will last as long as necessary to ensure citizens’ safety.” How long that is, nobody knows.
Some governors did not like the blockings. During a call-in show on March 19, 2026, Belgorod governor Vyacheslav Gladkov said that the lack of alerts was costing lives, and that he was “absolutely in agreement with all the residents’ outrage.” Gladkov left his post soon after, and the reasons included objections to the blockings. Nizhny Novgorod governor Gleb Nikitin questioned the very design of the blocking system: “Allowlists mean the LTE or 4G signal is present. And there is a real question of whether that lets people guide the very weapons we are fighting against.”
The head of the Bank of Russia, Elvira Nabiullina, has spoken out against the “lists” too. On March 20, 2026, she stated that “being on this ‘allowlist’ gives a serious competitive advantage to the banks that made it in.” That same day, five deputies from the Communist Party (KPRF) demanded that the Ministry of Digital Development and the Federal Antimonopoly Service (FAS) disclosed how the list was compiled. No substantive public response from the FAS could be found, and none was ever officially reported.
Nabiullina was asking for every licensed bank to be added to the list, not for the whole regime to be scrapped. On April 22, 2026, Dmitry Gusev, first deputy chair of the Duma’s oversight committee, proposed adding hundreds of thousands of entrepreneurs to it as well. Operators, as CNews reported, were asking for a single, unified set of rules.
Developers of censorship circumvention tools are already rethinking their threat model, and a separate section with recommendations for them follows below. Developer Sergey Durgalyan writes in an article on Habr dated April 9, 2026: “The situation with mobile operators is even worse — MTS, MegaFon, Yota, Tele2, and Beeline all use allowlists. That means only traffic to approved IP addresses gets through, and everything else is cut.” He describes his answer to this: a multi-layered, fault-tolerant architecture where, if one method fails, the next one takes over. Another developer, who publishes on Habr under the handle zarazaexe, sums up the logic of allowlist filtering more bluntly: “Everything is forbidden; only the chosen few are allowed.” The technical consequence, he says, was the need to disguise traffic as a browser and host servers on addresses that were already on the approved list.
Do drones actually depend on cellular networks?
One of the main arguments made by the authorities and their propagandists is that drones depend on cellular networks, so those networks need to be jammed somehow. Some independent experts make this argument too, as does the Ukrainian side.
Industry experts disagree. Gleb Babintsev, director general of the Aeronext association, argues that “a drone can fly thousands of kilometers completely on its own, no problem.” Kirill Mikhailov, a military researcher at the Conflict Intelligence Team, points out that there is no known case of drones being controlled en masse via mobile internet, aside from Operation Spiderweb. Neither side has published data on what share of attacks actually depend on cellular networks.
Even Oryol region governor Andrei Klychkov argues against the drone-and-cellular-network claim. In early September 2026: “Drones used to be guided by mobile internet; now they are forced to fly higher, on an entirely different trajectory.” None of this can be verified — no aircraft, no dates, no altitudes. Not once, in the entire time this policy has been in place, has any official named a specific case where a shutdown stopped an actual strike.
There is no research showing that shutdowns actually improve safety.
Recommendations for developers of circumvention tools
These recommendations are for developers of transports and clients used to bypass blocking. The reasoning is simple: the past year’s measures target circumvention tools, not drones, so these regime changes read first and foremost as a shift in the threat model for this particular audience.
Design for allowlist filtering, not for blocklist filtering. This is a change in the architecture of the problem, not just a tightening of the old one. Under blocklist filtering, whoever disguises their traffic as unknown wins; under an allowlist, anything unknown gets dropped by default, and only the destination address matters.
Treat both address-based workarounds as closed. Hosting on allowlisted IP ranges was shut down in January 2026, and the roaming tunnel followed in July. Any architecture that depends on someone else’s allowlist or on a foreign SIM card inherits the full risk of being cut off.
Prepare for control to shift from traffic to devices. The IMEI registry moves the decision point from the content of a connection to the identity of the device and subscriber. Resistance to traffic analysis offers no protection against this class of measures, and the timeline is already known: 2027 and 2028.
Build in backup channels outside mobile internet. The rise in SMS traffic at operators shows where load actually shifts during shutdowns. Wi-Fi, mesh networks, and device-to-device exchange between nearby devices keep working even where cellular data is switched off entirely.
Recommendations for those measuring shutdowns
These recommendations are for research groups and outlets building their own measurements from alerts, complaints, or instrumental data, rather than just repeating someone else’s statistics. Our own calculations for this piece ran into two problems: no positive control, and a short observation window. The next two points address exactly that.
Build a positive control into your telemetry from day one. The minimal setup: simultaneously query an allowlisted service, a non-allowlisted service, and an external endpoint, from the same SIM card at the same moment. Without this, silence in the telemetry is indistinguishable from normal operation, and your own data will end up suffering the same fate as other people’s external measurements.
Do not fill gaps with zeros. A silent client and confirmed unavailability are two different facts. The direction of the effect varies between operators even within the same region, so keep the data broken down by operator instead of averaging it across the whole region.
Capture telemetry on September 18–20. This restriction was announced in advance, which is a rare case: the timing is known before it happens, so measurements from before, during, and after are comparable within the same network and the same SIM card. Windows like this give you something retrospective analysis of someone else’s data never can.
Plan for a collection window of at least 20 days. Below that threshold, statistical significance at the 0.05 level is unreachable regardless of effect size. The limiting factor is the number of daily shifts, so polling more often or adding more clients will not help.