Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

NCSC names FSB Centre 16 over routers

2 min read
16:08UTC

NCSC and 18 partner agencies named Russia's FSB Centre 16 over an SNMP router-hijacking campaign, a different service from the GRU unit named in April.

TechnologyDeveloping
Key takeaway

Centre 16's SNMP campaign makes router hygiene a UK critical-infrastructure defence task, not a back-office chore.

NCSC, the UK's National Cyber Security Centre, and 18 partner agencies named Russia's FSB Centre 16 in a joint router-hygiene advisory published on Thursday 9 July, according to secondary coverage of the alert 1. The advisory attributes a campaign that hijacks the Simple Network Management Protocol (SNMP), the service administrators use to monitor and configure network gear remotely, to harvest device data and reconfigure routers. It names communications, energy, healthcare, defence and financial-services operators as targets.

An April advisory named a different Russian service. That earlier alert attributed DNS hijacking on home routers to the GRU's Unit 26165, also tracked as APT28 . Centre 16 sits inside the FSB, Russia's domestic security service, rather than military intelligence, and works through SNMP where APT28 rewrote DNS entries. Both campaigns hit the same network edge from two different Russian agencies.

The joint advisory tells operators to retire legacy SNMP versions 1 and 2c for the authenticated, encrypted SNMPv3, and to restrict management-protocol access to trusted hosts 2. SNMP hygiene rarely reaches a board Agenda, yet a second Russian service now treats it as a collection route into critical national infrastructure. For a UK operator, the action is a configuration audit this quarter, not a procurement cycle.

Deep Analysis

In plain English

NCSC, the UK's cyber-security agency, joined 18 partner agencies on 9 July to publicly blame Russia's FSB Centre 16 for hijacking routers through SNMP, an old protocol used to monitor and manage network equipment. Many devices still ship with SNMP switched on and protected only by a simple shared password, called a community string, rather than a proper login. FSB Centre 16 is a separate Russian unit, and this is a separate technique, from the DNS-hijacking campaign NCSC named back in April.

Deep Analysis
Root Causes

SNMP versions 1 and 2c, still enabled by default on much legacy edge-network gear, authenticate with a plaintext community string rather than per-user credentials. Any actor that guesses or intercepts the string, commonly left at a factory default, gets read or write access to routing tables without needing an exploit at all.

That is why FSB Centre 16 could run a sustained campaign against unpatched infrastructure: the weakness is a configuration default carried over from 1990s protocol design, not a software vulnerability Fortinet or any single vendor could patch away.

First Reported In

Update #10 · One operator worked both ransomware brands

NCSC and 18 partner agencies· 14 Jul 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.