Back Computing NCSC urges critical sectors to strengthen defences against FSB attacks
The National Cyber Security Centre (NCSC), alongside 18 agencies from 12 countries, published a new advisory warning of the risks to critical national infrastructure (CNI) from Russian intelligence targeting.
The advisory highlights the methods of Federal Security Service (FSB) Centre 16 cyber actors, who are exploiting vulnerable routers and opportunistically targeting CNI networks
In addition to the NCSC agencies from Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden and the United States advice that sectors most at risk include communications, defence, energy, financial services, government and healthcare. All organisations categorised as such are urged to take action including recommendations to use SNMPv3 and disable legacy SNMP versions, implement strong and unique passwords for network devices, and restrict access to management protocols through appropriate access controls.
The advisory builds on one issued in April this year NCSC warns of Russian-linked hackers hijacking and business routers which warned of the risks posed by groups linked to the Russian military which the NCSC had observed carrying out DNS hijacking,
Centre 16, known by a host of other names such as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, has been seen hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings.
Whilst the actor primarily uses SNMP scans to locate and compromise vulnerable routers, they have also exploited well-known vulnerabilities relating to Cisco devices, Cisco’s Smart Install (SMI) feature and web-portal flaws to gain control of network devices.
Jonathon Ellison, NCSC Director of National Resilience said:
“The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter.
“Today’s joint advisory provides decisive, actionable directions from the global security community that network defenders should implement to protect against Russian Intelligence operations and secure the UK’s critical infrastructure.
“I’d strongly encourage all organisations, especially those entrusted with UK critical networks, to adopt these recommended measures immediately, thereby reducing the risk of compromise.”
Organisations are also encouraged to obtain Cyber Essentials certification, the government-backed scheme for all organisations to show they meet the recognised UK minimum standard for cyber security, and make use of the updated Cyber Assessment Framework , enabling them to assess their security maturity, address vulnerabilities and build their resilience against increasing threats.
The advisory has been published on the same day as the UK government has sanctioned 24 individuals and entities behind destructive cyber and hybrid operations including cyber criminals involved in proxy networks linked to the Russian Intelligence Services.
The UK together with EU member states has also today formally attributed the December 2025 attack on Poland’s energy grid to Russia’s FSB Centre 16 – an attack that if it had been successful could have caused 500,000 civilians to lose electricity.
The advisory builds on repeated warnings from GCHQ and its Director Anne Keast-Butler , the severity of risks posed to UK citizens from Russian hybrid warfare which is a blend of tactics such as propaganda, cyberattacks, deception and sabotage.
Ms Keast-Butler accused Russia of intensifying its "daily hybrid activity" against the UK and Europe in May this year, saying that Moscow is "relentlessly targeting critical infrastructure, democratic processes, supply chains and public trust."
The New York Times recently reported that the investigation into the attack on JLR last year which was so damaging that it was reflected in GDP figures for the last quarter of 2025, now believe that attack to have been not only a Russian operation, but one which was likely to have been sanctioned by the Kremlin.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
