19 min read

Why Russian Banks Block Transfers: 12 Signs | OneSix

Since 2026 Russian banks screen transfers against twelve official signs. What triggers a hold, why newcomers get flagged more often, and what to do about it.

Why Russian Banks Block Transfers: 12 Signs | OneSix
Why Russian Banks Block Transfers: 12 Signs | OneSix

Why Russian Banks Block Transfers: The 12 Official Signs

Since 1 January 2026, Russian banks screen every transfer against twelve official signs instead of the previous six, set out in Bank of Russia order OD-2506. Match even one and the bank must suspend the operation for two days and notify you immediately. The filters are not aimed only at fraud: changing your phone number the day before, sending an unusually large amount, or logging in from a new device is enough. If you have recently arrived in Russia, you will hit these filters more often than locals — and the reasons are worth understanding before it happens.

Written by Alexander Lebedev, analyst at OneSix. OneSix is mentioned alongside other settlement methods, with the limitations of each stated.

Two different mechanisms, routinely confused

Discussions of "blocked accounts in Russia" mix two separate procedures. They require different responses, so the distinction matters.

Anti-fraud (161-FZ)Financial monitoring (115-FZ)
What is stoppedA single operationAn operation or account access
PurposeProtecting you from fraudAnti-money-laundering control
DurationTwo daysUntil documents are provided; no fixed term
What you must doConfirm the transferDocument the source of funds
Who decidesAutomated screeningThe bank's compliance team

This article covers the first mechanism. It is automatic, requires no suspicion of you personally, and in 2026 it is what most ordinary payers run into.

Where the twelve signs come from

The list is set by Bank of Russia order 05.11.2025 No. OD-2506, issued under part 3.3 of article 8 of the National Payment System law. It has applied since 1 January 2026 and replaced order OD-1027, which had six signs (order text on the Bank of Russia site, in Russian).

Signs about the recipient

The clearest group: the bank is looking at who you are paying, not at you.

  1. The recipient appears in the Bank of Russia database of cases and attempts of transfers made without the client's voluntary consent. Banks check it before every operation.
  2. The recipient appears in the state information system for countering technology-enabled offences, created under law 41-FZ. This sign applies from 1 March 2026.
  3. The recipient is on your bank's internal list of details previously seen in fraud schemes.
  4. Criminal proceedings have been opened against the recipient in connection with transfers made without a client's voluntary consent, documented accordingly.

You cannot check a recipient in advance — the database is available to banks only.

Signs about your behaviour

Here the bank compares the operation against what you normally do. This is the group that catches honest people, and newcomers in particular.

  1. An atypical operation. The order lists six parameters: the time and days of the operation, the location, the device and how it is used, the amount, the frequency, and the recipient. A sharp deviation from your usual profile is grounds for a pause.
  2. A large SBP top-up before paying a new recipient. Triggered when more than 200,000 RUB arrives in your account over SBP from your own account at another bank less than 24 hours before you send money to someone you have not paid in the past six months. It targets the classic scheme where a victim is talked into consolidating all their savings and forwarding them.
  3. Cash deposited after a cross-border transfer. Depositing cash at an ATM with a tokenised card within 24 hours of sending more than 100,000 RUB abroad to individuals.

Signs about your device and connection

The least intuitive group: the bank analyses the circumstances in which you press "send", not the money itself.

  1. A phone number changed within 48 hours of the transfer, either in the bank's app or on the Gosuslugi state services portal.
  2. Atypical session parameters — an unfamiliar connection provider, a different operating system, a different app, or tools that conceal session data. This is the clause that catches transfers made over a VPN.
  3. Indications of malware on the device used for the transfer, including information supplied by mobile operators and messenger owners.
  4. Atypical phone activity. Calls in the six hours before a transfer that do not match your usual frequency or duration, or a spike in messages from new numbers, including messages appearing to come from banks or state services. This one answers the scheme where a victim is kept on the phone while being talked through a payment.
  5. Technical risk markers — an unusual card response time at an ATM, which can indicate skimming, risk-level signals from the payment system, and a match between your device parameters and devices recorded in the database.

Why newcomers to Russia get flagged more often

Nothing in the order targets foreigners. The problem is structural: several signs measure deviation from a client's usual pattern, and a newly opened account has no usual pattern to deviate from. Everything is a first.

The typical arrival stacks triggers on top of each other. A Russian SIM registered days ago, then linked to the bank app — that is the 48-hour clause. A phone bought locally or brought from abroad, unfamiliar to the bank — atypical device parameters. A VPN left running out of habit — concealed session data. A first significant payment, for a rental deposit or furniture — an atypical amount with no history to compare against. Any one of these is survivable. Three at once on the same evening is a near-certain hold.

The practical response is not to fight the filters but to space things out. Set up the SIM and the bank app, then let a few days pass before a large payment. Make that payment from the device and the network you use daily, without a VPN. Warn the bank's support in advance if the amount is unusual.

What happens when a sign fires

The bank must suspend the transfer for two days or refuse the operation — this covers card transfers, electronic money and SBP. It must also notify you immediately of the fact, the reasons and the duration, and tell you that you can confirm the instruction no later than the following day, or repeat the operation to the same details for the same amount (Bank of Russia explanation, in Russian).

The hold applies even if you insist and try again during the two-day cooling-off period. That is deliberate: those are the hours when a fraudster would be applying pressure.

What to do when a transfer is held

  1. Do not retry repeatedly. It will not speed anything up and will add triggers.
  2. Read the notification. It should state the reason and the term. If nothing arrives, that itself is a breach worth raising.
  3. Confirm the instruction the way the bank offers, or repeat the operation to the same details for the same amount.
  4. Wait out the two days. After that the bank must execute a confirmed instruction without delay, absent other legal grounds for refusal.
  5. If the term passes and nothing moves, this is no longer anti-fraud. Ask for written grounds — the matter has most likely moved to 115-FZ, where documents are required.

If the bank lets a fraudulent transfer through

The same rules work in your favour. Since 25 July 2024 the bank must screen a transfer before executing it, and if it pushes an operation through to details held in the Bank of Russia database, it must refund the client within 30 calendar days (Bank of Russia statement, in Russian).

The two-day pause that irritates everyone is the price of a refund mechanism that did not exist at all before.

If it reaches 115-FZ: what documents to prepare

When the two days pass and the money still does not move, the question has almost certainly gone to compliance. Different logic applies: the bank is not protecting you from fraud, it is checking where your money came from. No automation is involved and no two-day limit applies.

What is usually requested:

  • Proof of income — an employment contract, income statement, or for self-employed status, receipts from the tax app.
  • Grounds for the specific payment — a contract, invoice, or acceptance act, including invoices from foreign clients.
  • Documents for one-off large amounts — a vehicle or property sale contract, inheritance certificate, deed of gift.

Three things speed this up. Respond within the stated deadline, since delay reads as refusal to cooperate. Send documents rather than explanations — "a friend repaid a loan" is not evidence without a written record. And send exactly what was requested; extra paperwork lengthens the review.

Crypto income is harder to document than a salary, because an exchange screenshot is not a document. What works is exchange statements showing a withdrawal to your own details, contracts with clients where the payment was for services, and the counterparty's own payment records. Collect these before they are needed — reconstructing six months of history under a bank deadline is considerably worse.

A specific case: money connected to crypto

If your income arrives in USDT, the standard route is to sell on P2P, receive rubles by transfer from a stranger, and then spend them. That route collects triggers better than any other.

An incoming transfer from someone you have never dealt with is already atypical under the "recipient" parameter. Several trades a day add the "frequency" parameter. Consolidating the proceeds into another of your own accounts and sending them onward brings in the 200,000 RUB clause. And there is a separate exposure: a P2P counterparty may themselves be in the Bank of Russia database, which turns attention towards you as the person who received their money.

The way to reduce this is the same as everywhere — fewer intermediate transfers between individuals means fewer occasions to be screened. Paying a ruble QR code directly from a crypto balance removes the intermediate step entirely: rubles never land on your card, and the merchant receives an ordinary SBP payment from the service.

That is how the OneSix mini app on Telegram works: scan the code, check the ruble amount and the final USDT debit, confirm. Stated plainly, the limits are: a 1,000 RUB minimum per QR payment, payments from a USDT balance only, and a fee built into the conversion rate at roughly 0.4–0.7% above the Central Bank rate. On large amounts P2P usually gives a better rate — the question is what the risk and the time are worth to you.

Quick answers

How long can a bank hold a transfer?

Two days, and it must tell you the reason and the term immediately.

Is the whole account frozen?

No. Anti-fraud stops one operation. Freezing account access and demanding proof of the source of funds is the separate 115-FZ procedure.

Can I check a recipient against the database first?

No. It is available to banks only.

Will I be refunded if the bank misses a fraudulent transfer?

Yes, within 30 calendar days, if the operation went to details held in the Bank of Russia database.

About the author

Alexander Lebedev, analyst at OneSix

Alexander Lebedev — analyst at OneSix. Covers Russian payment infrastructure and settlement scenarios from crypto balances.

Published: 3 August 2026. Last updated: 3 August 2026.

This article is for information only and is not investment, tax or legal advice.

Fewer transfers, fewer checks

If your income arrives in USDT, paying by QR code straight from a crypto balance removes the P2P step and the incoming transfers from strangers that come with it. Open the OneSix wallet on Telegram — it runs as a mini app, with nothing to install.

Updates on Russian payment infrastructure and banking rules are posted in the OneSix channel.