In early August 2026, Russia's largest banks moved their websites to TLS certificates issued by the National Certification Authority run by Mintsifry, the digital ministry. To anyone on a foreign browser it looks like an outage: instead of online banking, a red warning about an unsafe connection.
What happened
As late as July 31, the banks' sites still ran on certificates from the Chinese authority TrustAsia. By August 3 a wave of migration to the Russian certificates had gone through — first spotted by iPhones.ru.
The switch covers:
- Sberbank
- VTB
- Alfa-Bank
- T-Bank (tinkoff.ru)
- Rosselkhozbank
- Promsvyazbank
- Uralsib
- Bank Saint Petersburg
- Bank Levoberezhny — partially, the business banking portal
Why the browsers refuse to play along
Safari, Chrome and Edge validate a site's certificate against the lists of authorities trusted by Apple, Google and Microsoft. The Mintsifry CA is not on those lists — so the browser does exactly what it is supposed to do with an unknown authority: it blocks the page as potentially unsafe. The typical picture is a "Your connection is not private" warning or an ERR_CERT_AUTHORITY_INVALID error.
The key point: this is the browser's own behaviour, not the network's. The error reproduces anywhere — Moscow or Berlin, VPN on or off — on any device without the Russian certificates installed.
Who is affected
Hardest hit are people abroad: their browsers and systems don't carry the Russian root certificates. The banks' mobile apps are untouched — the certificates they need are built in, and the apps work as before.
What to do
There are three options: Yandex Browser with the Russian certificates built in, installing the Mintsifry certificates manually from gosuslugi.ru/crt, or the bank's mobile app. The step-by-step walkthrough of all three — including why access from a foreign IP is a separate problem — is in our guide: "Bank Websites Won't Open Even with a VPN".