Criminal Code Article 274.1, Unlawful Impact on Critical Information Infrastructure
Criminal Code of the Russian Federation, Art. 274.1 (added 2017)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not create, distribute, or use malicious computer programs, or gain unauthorized access to protected information, aimed at Russia's critical information infrastructure, under Criminal Code Article 274.1; a version committed by a group or causing grave consequences carries imprisonment up to 10 years.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Creation, distribution, or use of malware aimed at critical information infrastructure: forced labor up to 5 years (with or without restriction of freedom up to 2 years) or imprisonment 2 to 5 years, plus a fine of 500,000 rubles to 1,000,000 rubles (or income for 1 to 3 years). Unauthorized access to protected information in critical information infrastructure causing destruction, blocking, modification, or copying: forced labor up to 5 years with the same fine, or imprisonment 2 to 6 years with the same fine. Violation of operating or access rules causing the same result: forced labor up to 5 years with optional disqualification up to 3 years, or imprisonment up to 6 years with the same disqualification. Committed by a group, organized group, or using an official position: imprisonment 3 to 8 years with optional disqualification up to 3 years. Any tier causing grave consequences: imprisonment 5 to 10 years with optional disqualification up to 5 years.
Penalty structure
Fine tiers run 500,000 to 1,000,000 rubles for the malware and unauthorized-access offenses (parts 1-2), alongside imprisonment ranging 2 years up to a maximum of 10 years for the grave-consequences tier (part 5), which carries no separate fine.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- RUB
- Fixed cap
- 1,000,000
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 274.1, added by Federal Law No. 194-FZ of 26 July 2017, criminalizes creating or using malicious software aimed at Russia's critical information infrastructure, unlawful access to protected information held in it, and violating the operating or access rules for systems classified as critical information infrastructure, across five escalating tiers running from forced labor up to five years to imprisonment of five to ten years for grave consequences.
A 2026 amendment added a cooperation-based exemption from liability for a person who actively assists the investigation.
When LexLint raises it
crawls_web
Read the law
Consultant.ru, codified text of the Criminal Code of the Russian Federation, Art. 274.1