Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

NCSC names FSB Centre 16 over routers

2 min read
18:20UTC

NCSC and 18 partner agencies named Russia's FSB Centre 16 over an SNMP router-hijacking campaign, a different service from the GRU unit named in April.

TechnologyDeveloping
Key takeaway

Centre 16's SNMP campaign makes router hygiene a UK critical-infrastructure defence task, not a back-office chore.

NCSC, the UK's National Cyber Security Centre, and 18 partner agencies named Russia's FSB Centre 16 in a joint router-hygiene advisory published on Thursday 9 July, according to secondary coverage of the alert 1. The advisory attributes a campaign that hijacks the Simple Network Management Protocol (SNMP), the service administrators use to monitor and configure network gear remotely, to harvest device data and reconfigure routers. It names communications, energy, healthcare, defence and financial-services operators as targets.

An April advisory named a different Russian service. That earlier alert attributed DNS hijacking on home routers to the GRU's Unit 26165, also tracked as APT28 . Centre 16 sits inside the FSB, Russia's domestic security service, rather than military intelligence, and works through SNMP where APT28 rewrote DNS entries. Both campaigns hit the same network edge from two different Russian agencies.

The joint advisory tells operators to retire legacy SNMP versions 1 and 2c for the authenticated, encrypted SNMPv3, and to restrict management-protocol access to trusted hosts 2. SNMP hygiene rarely reaches a board agenda, yet a second Russian service now treats it as a collection route into critical national infrastructure. For a UK operator, the action is a configuration audit this quarter, not a procurement cycle.

Deep Analysis

In plain English

NCSC, the UK's cyber-security agency, joined 18 partner agencies on 9 July to publicly blame Russia's FSB Centre 16 for hijacking routers through SNMP, an old protocol used to monitor and manage network equipment. Many devices still ship with SNMP switched on and protected only by a simple shared password, called a community string, rather than a proper login. FSB Centre 16 is a separate Russian unit, and this is a separate technique, from the DNS-hijacking campaign NCSC named back in April.

Deep Analysis
Root Causes

SNMP versions 1 and 2c, still enabled by default on much legacy edge-network gear, authenticate with a plaintext community string rather than per-user credentials. Any actor that guesses or intercepts the string, commonly left at a factory default, gets read or write access to routing tables without needing an exploit at all.

That is why FSB Centre 16 could run a sustained campaign against unpatched infrastructure: the weakness is a configuration default carried over from 1990s protocol design, not a software vulnerability Fortinet or any single vendor could patch away.

First Reported In

Update #10 · One operator worked both ransomware brands

NCSC and 18 partner agencies· 14 Jul 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.