The United States National Security Agency (NSA) issued an alert this Monday in which it attributes to the Russian Federal Security Service’s Center 16 (FSB) a systematic campaign of intrusion into routers and other network devices with poorly secured or outdated configurations. The notice, prepared together with 17 cybersecurity agencies from 11 other countries, identifies the most exposed sectors—defense, energy, communications, finance, government facilities, and health—and urges operators to implement measures to close the access routes that Russian hackers have been exploiting for more than a decade.
Washington’s warning does not come in isolation. Hours earlier, the UK’s National Cyber Security Centre (NCSC), which reports to the GCHQ signals intelligence headquarters, had published a parallel guide with an identical focus: Center 16 acts opportunistically against strategic networks worldwide, and basic configuration flaws in network devices remain its primary entry point. The coordinated publication of both notices coincided with the announcement of the first joint sanctions between London and Brussels against members of that FSB unit since Brexit. The trigger was the December 29, 2025, attack on Poland’s power grid, formally attributed to Center 16, which could have left 500,000 citizens without power in the middle of winter. The malware used was DynoWiper, a destructive tool historically associated with Russian state operations. The operation failed, but only by a narrow margin.
We recommend reading: U.S. requests extradition of four linked to the Sinaloa Cartel
The technical mechanism described in the advisory is revealing. Center 16 scans the internet for routers that still use default passwords or insecure community strings for the SNMP protocol—keys like “public” or “private” that manufacturers include by default and that many administrators never change. Once a vulnerable device is identified, the operatives issue SNMP commands to copy its configuration file and redirect it, using the TFTP transfer protocol, to servers under their control. That file contains, in practice, a complete map of the network: routing tables, firewall rules, stored credentials, and subnet architecture. For an intelligence operation seeking to understand the interior of a network without triggering intrusion detection alarms, that document is, according to the advisory, more valuable than most conventional malware.
A man holds a laptop while cyber code is projected onto it in this illustration taken on May 13, 2017.
The NSA and its partners—including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and agencies from Australia, Canada, New Zealand, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden—note that the group, also known as Berserk Bear, Energetic Bear, Dragonfly, or Static Tundra, has been active since at least the first half of the 2010s. In addition to the SNMP protocol, it has exploited known vulnerabilities in the Cisco Smart Install function and device administration web portals. As of August 2025, the FBI had already documented the collection of configurations from thousands of devices associated with U.S. critical infrastructure entities. This Monday’s advisory expands on that assessment with new tactics and adds a significant detail: Center 16’s techniques partially overlap with those of the China-linked actor known as Salt Typhoon, suggesting that the weaknesses exploited by Moscow are the same ones leveraged by other foreign intelligence services.
The recommended measures are technically accessible: adopt version 3 of the SNMP protocol—the only one with robust encryption and authentication—, disable the Cisco Smart Install function, set unique and strong passwords on each network device, block TFTP and SMI protocols on the firewall, and keep the firmware updated.
The cadence of incidents attributed to Russia against European infrastructure has accelerated in recent months. Sweden reported in April 2026 that a group linked to the FSB had attacked a district heating plant. France attributed intrusions against ministerial systems in 2014 and against a research institute linked to the defense industry in February 2025 to the same operational environment. The Kremlin has systematically denied any involvement. The coordination between 18 agencies from 12 countries to simultaneously publish a technical guide, impose sanctions, and formally attribute a specific attack represents the broadest Western response to date, although the track record of Center 16—more than a decade of sustained operations without appreciable consequences—raises reasonable doubts about its real deterrent capacity.




