Summary
- What happened. In early August 2026, mobile carriers started blocking mass and automated calls from companies that hadn’t signed a paid labeling agreement. The law requiring this took effect back on September 1, 2025 (the rule sat unenforced for almost a year before this).
- Mechanics. A legal entity or sole proprietor has to buy a “label” from the carrier (the caller ID text you see on your screen). It costs about 30 kopecks (about $0.004) per call attempt, and the money gets charged even if the subscriber never picks up.
- Costs. Estimates put the burden on business at up to 20 billion rubles (about $266 million) a year. In the first few months, the cost per call rose 5 to 20 times, and 18 call centers closed in Perm, Novosibirsk, Tomsk, and Vladimir. Large players can absorb the costs; smaller ones are leaving the market or cutting staff.
- The gap. The law doesn’t define “mass and automated calls,” each carrier interprets the rule its own way, and the rates are a trade secret.
- Next steps. The third Antifraud package proposes letting virtual PBX systems operate only from Russian IP addresses, while a telecom association proposes a registry of trusted PBX systems authorized through Gosuslugi (Russia’s national state services and digital identity portal).
What’s happening
On August 3, 2026, the newspaper Kommersant reported that mobile carriers from the “big four” had started cutting off calls from legal entities without labeling agreements. MegaFon explained the move as a licensing requirement and said mass calls without a carrier agreement are illegal. It also gave a figure: since the start of 2026, the number of calls flagged as mass calls arriving from fixed-line carriers grew by 155%. T2 Mobile (formerly the Russian branch of Tele2) said 99.9% of its clients that make mass calls had signed labeling agreements. MTS declined to comment.
The rule carriers are citing comes from Federal Law No. 41-FZ of April 1, 2025. A new clause 9.1 in Article 46 of the Communications Law requires carriers to send the recipient’s device information about the calling legal entity or sole proprietor. The government set the procedure and format in Resolution No. 1300.
For a year the law only half-worked: labeling existed, but there were no penalties for skipping it. Now the law works in full.
Mechanics: what happens to a call
Let’s break it down step by step, in plain terms.
Step one: the contract. A company or sole proprietor signs a display agreement with a carrier. This gives consent to pass on to other carriers the company name, trade name, call category based on its main line of business, the text to display on screen, and the list of numbers it will call from. The category comes from a list based on OKVED (Russia’s classifier of economic activities), and the label can run up to 32 characters.
Step two: passing the label along. When the company calls, its carrier passes the label further down the chain, to the carrier you use. To handle this, the Big Four carriers built a shared API-based data exchange system: requests to add, change, or delete data move between carriers automatically.
Step three: classification. The receiving carrier decides what kind of call this is. It looks for the label and, at the same time, evaluates whether the call might be a mass or automated one. There are a lot of criteria: Beeline, according to industry reports, mentions up to 600 classification parameters.
Step four: the decision. If there’s a label, the call goes through and you see the company name on screen, as if the number were already in your contacts. If there’s no label and the call gets flagged as a mass call, it never reaches you. On top of that, subscribers now have the right to opt out of mass calls in advance: if you’ve used that option, such calls don’t get routed to you at all.

The key detail about money: the caller pays for the call, and the fee applies to the call attempt itself, even if no one answers. For a campaign dialing a million numbers, that fundamentally changes the economics.
Business has another complaint about carriers. Yaroslav Dubovikov, executive director of the Association of Telecom Companies, claims that instead of dropping an unlabeled call, mobile carriers route it to voicemail with an answer status, which lets them call termination fees. The connection formally went through, which means both the subscriber and the fixed-line carrier get charged for it. This claim remains the industry association’s position; we found no confirmation from the regulator.
This scheme isn’t aimed at fraudster calls
A different mechanism blocks caller ID spoofing that impersonates the “Central Bank” or “police”: the Antifraud call verification system, which has been running since December 2022. The principle is simple: when a call comes in, the carrier automatically asks the system whether the number’s actual owner initiated the call. No confirmation means the call doesn’t go through.
The results from this mechanism are substantial. In 2024, the system checked about 158 billion calls and blocked nearly 606 million caller-ID-spoofed . A year earlier, there had been more spoofed calls: over 756.7 million. You can also see the trend within a single year. MegaFon blocked 36 million spoofed calls in January 2024, and by December that was already down to 6 million. The system covers 1,162 carriers, controlling 99.6% of Russia’s numbering capacity.
So the precise answer to “will labeling put an end to the fake Central Bank scheme” is this: labeling isn’t what handles that scheme, and it’s already been mostly shut down by other means. Labeling solves a different problem: showing the name of a legitimate business so you know who’s calling.
But you still can’t trust a call just because it’s labeled. A label only confirms that someone signed a contract and provided a name; it doesn’t confirm good intentions on the other end. Once fraudsters lost number spoofing, they didn’t disappear, they switched tools: they now call from ordinary numbers and impersonate someone by voice, or they move to messaging apps, where there’s no verification at all. Technology is powerless against this, because the scheme doesn’t work through a fake number, it works through social engineering.
The practical rule hasn’t changed: if someone asks for an SMS code, rushes you into a decision, or threatens you with a criminal case, hang up and call back yourself using the number from the organization’s official website.
This is not (only) about security
The official rationale behind all these measures is simple and noble: protect people from fraudsters posing as banks and government agencies. That’s a real problem, and the measures do have some genuine effect. But the design also has properties that don’t follow from the goal of “cutting off fraudsters.”
The right to call became a paid service. Before September 2025, being able to dial a number was simply a property of the phone network. Now, for a legal entity, it’s a product you have to buy from the very carrier that decides whether to let your call through. The rates aren’t published and are treated as a trade secret. The difference between carriers is noticeable: according to a service comparison, a call to Beeline can cost 24 kopecks (about $0.003), while a call to MegaFon costs 46 kopecks (about $0.006) — almost twice as expensive.
The key term is undefined. The law sets no criteria for what counts as a “mass” or “automated” call. Each carrier decides for itself, and, as industry reports note, a support call to a client can end up falling under that definition. When the rule is vague and the decision is automated, the line gets drawn not by the law but by a commercial company’s filter settings.
The carrier became the arbiter. It’s the carrier that decides, by its own criteria, whether your call is legitimate, and it’s also the carrier that sells the service that makes a call legitimate. Convenient, isn’t it? The stricter the filter, the more you need the paid label.
A registry of who calls whom now exists. The Antifraud system mentioned above originally solved a narrow problem: checking whether a number was spoofed. Starting March 1, 2026, it’s being expanded into a state information system (GIS) for exchanging data between carriers, banks, government agencies, and platforms, created under the same Law 41-FZ. The scope has changed: from verifying a number to exchanging information among every participant. According to an industry encyclopedia, Roskomnadzor (Russia’s federal internet censoring and telecom regulatory agency) has started blocking calls from carriers that haven’t joined the system and taking those that refuse to court. The same source mentions plans to use it for monitoring calls made through messaging apps.
Businesses pay for the connection themselves, and the sums under discussion are serious. The system’s participants include not just telecom carriers but banks, marketplaces, classified-ad sites, hosting providers, and Russian social networks and messaging apps, plus, on the government side, the Prosecutor General’s Office, the Investigative Committee, and the Central Bank. Technically, the connection runs through SMEV-4, the state inter-agency data-exchange bus. According to estimates from the Internet Research Institute, the first phase connects around 2,500 large organizations at a cost of 10–25 billion rubles (about $133 million – $332.5 million), and expanding coverage to more than 20,000 participants would cost at least 180 billion rubles (about $2.4 billion). The Ministry of Digital Development considers this estimate inflated, but officials haven’t published their own figures. Even if the researchers’ number isn’t exactly right, the sums involved are substantial.
The costs will ultimately fall on the consumer. By design, this resembles a parafiscal (or quasi-fiscal) charge: the state imposes the obligation, but the money goes not to the budget but to a designated recipient. The closest familiar example is Chestny Znak (“Honest Mark”), the mandatory track-and-trace system, where businesses also pay a commercial operator for every code because the law requires it. The Platon road-toll system, whose payments go to a private concessionaire, and carriers’ contributions to the universal service reserve fund follow the same logic. In the end, the buyer pays for these schemes, because businesses build the cost into their prices. Call labeling will work the same way.
The results are asymmetric. Legitimate businesses start paying extra for a new service. Fraudsters don’t disappear; they simply move to wherever no labeling is required. Looking back at the first half of 2025, MegaFon had already reported that 60% of fraud complaints involved messaging apps. T2 put the figure at 57%. Regulatory logic responds to this by extending control to messaging apps, too, and the circle closes.
What comes next is stricter. The third Antifraud package proposes allowing access to virtual PBX (cloud PBX / SIP infrastructure) systems only from Russian IP addresses, and requiring hosting providers to place such PBX systems only on Russian addresses too. The Big Data Association proposed an alternative: a registry of trusted virtual PBX systems, where owners register their IPs after authorizing through Gosuslugi, and carriers accept voice traffic only from addresses on that list. The authors of the third Antifraud package also want to require websites and apps to store records of registrations, logins, and account deletions for three years and hand them over on request from law enforcement (that’s a topic for a separate piece soon). The Ministry of Digital Development stresses that this version of the bill isn’t final and will go through public consultation, though there’s no guarantee that public comments will actually be taken into account. The expected effective date is March 1, 2028.
The positions of different actors
Supporters of tighter controls emphasize the outcome: fraudsters are calling less often. State Duma Speaker Vyacheslav Volodin reported in May 2026, citing carrier data, that the number of fraudulent calls fell 33–74% in the first quarter, depending on the carrier. Volodin attributed this to new laws passed last year that were officially aimed at fraud. The 33–74% spread comes from carriers counting things differently. MTS reported a 74% drop for January–March; Vimpelcom reported 33%. MegaFon cited an entirely different metric: for MegaFon, the number of blocked fraudulent calls rose 18%. That doesn’t contradict a decline elsewhere; it’s simply a different measurement. It reflects how well the filters worked, not how many fraudsters there were. These figures can’t be compared directly with one another.
Skeptics point out that such methods have limited effectiveness. Andrey Yablonskikh, president of the International Academy of Digital Communications, argues that against fraudsters using social engineering, “neither labeling, nor card limits, nor bans will work.” A technical label filters out number spoofing. But it does nothing about a fraudster who still gets through and talks the victim into handing over money.
As for the market, telecom carriers come out ahead thanks to the new revenue stream, while companies that need to call their customers are bracing for losses.
International context
Verifying which company is calling a customer wasn’t invented in Russia. In the US, for example, the STIR/SHAKEN standard is in effect: carriers cryptographically sign the call with a digital certificate, and the receiving side checks that the number isn’t spoofed. But businesses there don’t pay for the call-approval service itself.
The Russian model adds three layers to identification that the original approach doesn’t have: a fee for the right to make a call, blocking based on undefined criteria, and integration into a state data-exchange system. The closest analogy here isn’t American anti-spam efforts; it’s the logic of the registry of “socially significant” services we’ve written about before: access only for those on the list who’ve confirmed they’re “compliant.”
For developers
A separate note for anyone building products that involve calls, notifications, or telephony.
Any call automation is now within regulatory scope
If your product can place calls on its own (say, you send appointment reminders, order confirmations, run voice-based two-factor authentication, or call debtors), it potentially falls under the definition of mass or automated calls. As a reminder, the law has no clear definition of “mass” or “automated”; it’s entirely up to the carrier. The practical takeaway: build in the ability to disable the voice channel and switch to text without rewriting half your system.
The economics have changed
A charge of 30–50 kopecks (about $0.004–$0.007) per call attempt, deducted regardless of whether anyone answers, disrupts the unit economics of any product relying on voice notifications as a low-cost channel. If your model is “we’ll get through on the third try,” you now pay for all three attempts.
Carrier integration is now a mandatory part of the stack
The “big four” built a shared API for exchanging labeling data between carriers and clients. If you provide telephony or a CRM with outbound calling, you’ll need to add labeling support. For cloud PBX providers, this has become a separate paid add-on.
Prepare for a law restricting virtual PBX systems
If the Russian-IP-only rule passes as written, a self-hosted Asterisk or FreeSWITCH instance on a foreign VPS will stop being able to send voice traffic to Russian carriers. The alternative, a registry of trusted PBX systems through Gosuslugi, is technically gentler, but it means your communications infrastructure has to be declared to the state and added to a list. The expected date is March 2028, and the document is still under discussion.
One more item in the same package goes beyond telephony and deserves a separate piece, but it’s worth flagging here: websites and apps would be required to store records of registrations, logins, and account deletions for three years. If this passes, “right to deletion” in your product becomes legally contradictory: a user deletes their profile, but you’re obligated to keep a record that they existed. When designing your data schema now, separate user data from the event log, so you don’t end up having to choose between the two requirements later.
Steps you can do ahead of time
For now, here are just a few brief practical tips:
- Keep your voice channel replaceable.
- Document users’ consent to be called — it’s your only defense if a carrier decides your calls count as mass calls.
- Don’t make critical flows (account login, access recovery) depend solely on a voice call.
- Follow the discussion of the third Antifraud package: the public consultation process is, at least formally, a channel for influencing it.
Changes for NGOs and activists
This angle gets discussed the least, and it may be the most significant one. Labeling is built so that calling “as an organization” now means exposing your identity, both to the carrier and on the other person’s screen.
Making a call now requires paperwork. For calls to get through, you need a legal entity or sole proprietor status, a contract with a carrier, and submission of your name, OKVED activity category, and the list of numbers you call from to the system. An unregistered initiative group, a project with no legal entity, or an organization that lost its registration simply doesn’t fit into this scheme. Their calls stay unlabeled, and if such calls get flagged as “mass” calls (and again, no one knows exactly what that will mean), they won’t get through at all.
Caller anonymity is effectively eliminated. You used to be able to call from an ordinary number and the recipient just saw the digits. Now the choice is: either a label with your organization’s name, or the risk that the call gets classified as mass and cut off. The system has no middle ground for “I’m calling on legitimate business, but I’d rather not announce who I am.”
A label on someone else’s screen can put the recipient at risk. This follows directly from the mechanics rather than being a documented case, but the risk is real. Labeling shows the organization’s name as if the number were already saved in contacts. For a crisis line, legal aid service, or support hotline, that means the label is visible not only to the intended recipient but to anyone nearby, or anyone who picks up their phone. For someone being called about domestic violence, stalking, or legal help, for instance, this is an added risk.
Organizations are forced to leave yet another digital trace. Call data now flows into the GIS Antifraud system, where carriers, banks, and government agencies interact. For anyone whose contacts are sensitive (journalists’ sources, human rights lawyers’ clients, whistleblowers), this means the fact of a communication gets recorded in a state system. The content of the call doesn’t reach that system, but the metadata about who called whom is often enough on its own, for example, to open a criminal case. Yes, the state already monitors phone communications regardless, but this adds one more collection point for call data.
Foreign infrastructure is now in question. If the rule restricting virtual PBX systems to Russian IPs passes, organizations that operate from abroad and call into Russia through their own telephony will lose that channel.
What should organizations do about this
These aren’t tips on how to get around the law: you can’t get around it, and trying to call outside the labeling system creates extra legal risk and still runs into the carrier’s filter. Instead, here’s how to operate within the new rules without putting people at risk.
Think carefully about what goes in your 32 characters. The law requires you to submit either your legal name or a trade name, so the label doesn’t have to word-for-word match the name in your founding documents. If your activity could put the person you’re calling at risk, choose a neutral label that tells an outside observer looking at the screen nothing. That’s a legitimate choice within the requirement.
Tell people in advance what an incoming call will look like. Say this during first contact and put it on your website: “we’ll call you, and your screen will show this exact label.” That way, the person can decide for themselves whether and when it’s safe to answer. Or suggest they save your number under a neutral name instead. If a number is already saved in someone’s contacts, the subscriber sees that saved name, not the organization’s label. The label arrives over the network as a call attribute for a number the subscriber’s phone doesn’t recognize, and the local address book in the dialer takes priority on both Android and iOS. That said, this recommendation obviously needs verification; we can’t vouch for every phone manufacturer’s behavior.
Flip the contact model. The most reliable protection is to not call people yourself and instead have them call you. Arrange a time and give them a number to dial themselves.
Don’t make voice calls the backbone of all critical communication. Identity verification, sensitive information, and emergency contact are all better handled through end-to-end encrypted messaging apps. A voice call leaves an extra trace, and now it also exposes the sender by default.
Document consent. If people gave you their number themselves and agreed to be called, record that. If there’s ever a dispute over whether your calling campaign counted as “mass,” proof of consent is the only thing you can really rely on, since there’s no defined criterion for “mass.”
If you don’t have a legal entity, plan your communication without relying on calls. Unregistered initiative groups and projects simply don’t fit into the labeling scheme. The honest conclusion: organizational phone calls are effectively closed off to them, and it’s not worth building your operations around them.