Russia’s Interior Ministry warns against keeping sensitive data on phones

The ministry advises users not to store document scans, passwords, bank-card details or intimate photos on smartphones. Such data could help criminals access accounts or be used for blackmail.

The Russian Interior Ministry materials reviewed by RIA Novosti on October 9 list scans of passports, SNILS social-insurance records, taxpayer identification numbers and driver’s licenses, as well as social-media and messaging passwords. The ministry says such information could help criminals access accounts, impersonate the device’s owner or use it for blackmail.

For documents, the ministry advises using protected cloud storage with two-factor authentication. It says intimate photos should be kept in password-protected folders or removed from the device. The ministry advises against sending passwords to oneself through messaging apps or saving them in notes or a browser. It recommends using a password manager or keeping written records offline instead.

The ministry also warns against leaving card numbers, PINs, addresses or bank notifications in chats. Such messages can reveal a person’s financial habits and income, so it recommends regularly clearing banking alerts from message histories. It also advises trimming contact lists, putting important contacts in a protected backup and avoiding personal notes in phone contact cards.

CISA says access to unencrypted data on a lost or compromised device can expose it. The agency recommends encrypting devices and keeping backups in a vetted cloud service or on a protected external drive. For passwords, CISA separately recommends password managers and multifactor authentication.