In early August 2026, the websites of several major Russian banks switched to TLS certificates from the Ministry of Digital Development's National Certification Authority. The changes affected Sberbank, VTB, Alfa-Bank, Rosselkhozbank, Promsvyazbank, Uralsib, and Bank Saint Petersburg.
In Google Chrome, Safari, Firefox, and some other browsers, such websites may not open or may display a warning about an insecure connection. Banks suggest installing the Russian root certificate or using a browser where it has already been added.
Important: a browser warning alone does not mean that the bank has been hacked and customer data has already leaked. But installing an additional root certificate does indeed change the device's security model.
Why a website needs a TLS certificate
A TLS certificate has two main functions:
- confirms that the user has connected to the real website rather than a fake;
- encrypts transmitted data — passwords, messages, card details, and documents.
A browser trusts only certificates issued by certificate authorities on its trusted list. Certificates from the Ministry of Digital Development are not included by default in the trust stores of most foreign browsers, which is why the warning appears.
What is the risk of data leakage
It is necessary to distinguish between a certificate for a specific bank website and a root certificate, which the user installs on the device themselves.
A regular bank certificate protects the connection only to its website. A root certificate gives the issuing certificate authority broader powers: the browser begins to trust websites whose authenticity is confirmed by that authority.
In theory, if a certificate authority issues a certificate for someone else’s domain and the user’s traffic can be routed through intermediary equipment, the browser may mistake a spoofed site for the real one. This scheme is called a “man-in-the-middle” attack. At risk may be:
- logins and passwords;
- correspondence and email;
- bank details;
- uploaded documents;
- data from personal accounts.
Installing a certificate alone does not mean that all internet traffic will be automatically decrypted. Interception would additionally require a replacement certificate and the ability to redirect the user's connection. However, the potential for such a scenario does arise.
How to use a Russian bank more safely
- Use the bank's official mobile app. Download it only from the official app store or the bank's website. Do not install APK files sent via Telegram, email, or SMS.
- Do not install certificates from links in messages. If a certificate is unavoidable, open the instructions yourself through the bank's official website or the certificate page on Gosuslugi.
- Set aside a separate browser exclusively for the Russian bank. Do not use it for email, European online banking, Bulgarian government services, or other important accounts.
- Do not ignore browser warnings. Do not click “Continue anyway” unless you have checked the website address and the reason for the error.
- Enter the bank's address manually or use a saved bookmark. A fake page may completely copy the appearance of the real online bank.
- Enable transaction confirmation and notifications. Even if someone else learns your password, additional verification will make it harder to access the account.
- Use different passwords. Your bank password should not match the password for your email, social media, or other services.
If access to a Russian bank from Bulgaria regularly causes problems, it makes sense to use a separate European account for local payments and receiving income. Up-to-date information is available in the article on which banks in Bulgaria allow a foreigner to open an account.
What to do if the certificate is already installed
If you no longer need Russian banking services, you can remove a certificate you installed yourself from the device's trusted certificate store. The location of the settings depends on the operating system:
- Windows: press Win + R, enter
certmgr.mscand check the Trusted Root Certification Authorities section; - macOS: open the Keychain Access app and the certificates section;
- Android: open the security settings and the user certificates section;
- iPhone and iPad: check the “VPN & Device Management” and “Certificate Trust Settings” sections.
Do not randomly remove unfamiliar system certificates. Remove only the certificate that you installed yourself. If you are unsure, it is better to consult a specialist.
What to do if you suspect data interception
- Stop transactions on the suspicious device.
- From another, known-safe device, change your email and online banking passwords.
- End active sessions in your account settings.
- Contact the bank using the number listed on the card or official website.
- If necessary, temporarily block your cards and set transfer limits.
- Check recent transactions and save screenshots of unfamiliar charges.
Brief conclusion
Banks switching to certificates from the Ministry of Digital Development does not mean an automatic data leak. The main risk arises when a user adds a new root certificate to the trusted list on their primary device.
The most cautious option is to use the official banking app or a separate browser solely to access the Russian bank. It is better to open email, European banks, Bulgarian government services, and work accounts in another environment.
Frequently asked questions
Can a root certificate steal a password by itself?
No. A certificate by itself does not copy passwords or files. But it can create a technical possibility for undetectable substitution of a secure connection if additional conditions are present.
Will a VPN protect against such interception?
A VPN protects the connection to the VPN server, but it does not override the browser's trust in an installed root certificate. Therefore, a VPN cannot be considered complete protection in this situation.
Can you use the bank's website without installing a certificate?
If a regular browser blocks the website, it is safer to use the bank's official app. Do not disable certificate verification or install files from unofficial sources.
