Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

NCSC names FSB Centre 16 over routers

2 min read
12:09UTC

NCSC and 18 partner agencies named Russia's FSB Centre 16 over an SNMP router-hijacking campaign, a different service from the GRU unit named in April.

TechnologyDeveloping
Key takeaway

Centre 16's SNMP campaign makes router hygiene a UK critical-infrastructure defence task, not a back-office chore.

NCSC, the UK's National Cyber Security Centre, and 18 partner agencies named Russia's FSB Centre 16 in a joint router-hygiene advisory published on Thursday 9 July, according to secondary coverage of the alert 1. The advisory attributes a campaign that hijacks the Simple Network Management Protocol (SNMP), the service administrators use to monitor and configure network gear remotely, to harvest device data and reconfigure routers. It names communications, energy, healthcare, defence and financial-services operators as targets.

An April advisory named a different Russian service. That earlier alert attributed DNS hijacking on home routers to the GRU's Unit 26165, also tracked as APT28 . Centre 16 sits inside the FSB, Russia's domestic security service, rather than military intelligence, and works through SNMP where APT28 rewrote DNS entries. Both campaigns hit the same network edge from two different Russian agencies.

The joint advisory tells operators to retire legacy SNMP versions 1 and 2c for the authenticated, encrypted SNMPv3, and to restrict management-protocol access to trusted hosts 2. SNMP hygiene rarely reaches a board Agenda, yet a second Russian service now treats it as a collection route into critical national infrastructure. For a UK operator, the action is a configuration audit this quarter, not a procurement cycle.

Deep Analysis

In plain English

NCSC, the UK's cyber-security agency, joined 18 partner agencies on 9 July to publicly blame Russia's FSB Centre 16 for hijacking routers through SNMP, an old protocol used to monitor and manage network equipment. Many devices still ship with SNMP switched on and protected only by a simple shared password, called a community string, rather than a proper login. FSB Centre 16 is a separate Russian unit, and this is a separate technique, from the DNS-hijacking campaign NCSC named back in April.

Deep Analysis
Root Causes

SNMP versions 1 and 2c, still enabled by default on much legacy edge-network gear, authenticate with a plaintext community string rather than per-user credentials. Any actor that guesses or intercepts the string, commonly left at a factory default, gets read or write access to routing tables without needing an exploit at all.

That is why FSB Centre 16 could run a sustained campaign against unpatched infrastructure: the weakness is a configuration default carried over from 1990s protocol design, not a software vulnerability Fortinet or any single vendor could patch away.

First Reported In

Update #10 · One operator worked both ransomware brands

NCSC and 18 partner agencies· 14 Jul 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.