Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk
Russia's websites lost their trusted certificates, and the fix Moscow is offering asks users to install a state root that can vouch for any site on the internet.
On June 13, 2026, Japanese certificate authority GlobalSign revoked thousands of Russian websites' TLS certificates in response to US and EU sanctions. This caused seven major Russian banks to switch to a state root certificate, which mainstream browsers do not trust, making their systems more vulnerable to hacking. Ukraine's Foreign Intelligence Service warns that Russian banks, email, and internal systems become easier targets after the certificate withdrawals.
About 90% of the Russian market still depends on foreign-issued certificates, and the sanctions could make it harder for users to access affected sites. Russian companies now rely on state-issued trust root certificates that users must install manually, but security experts warn that these could be abused for HTTPS traffic interception and man-in-the-middle attacks.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.