Skip to content
SPECIAL Informat. ro / What is Center 16 of the FSB and Turla, one of the oldest and most ...

SPECIAL Informat. ro / What is Center 16 of the FSB and Turla, one of the oldest and most ...

Informat.Ro July 13, 2026

Center 16 of the FSB (Federal Security Service of the Russian Federation) was publicly exposed by the EU on Monday as a command structure for Turla and other cyber espionage groups, responsible for infiltrating government networks and sabotaging critical infrastructures in EU member states, including Romania .

The statement from the High Representative of the EU explicitly describes a "cyber ecosystem" in Russia where intelligence services, cybercriminal groups, hacktivists, and private companies operate under state coordination. The EU denounces that this ecosystem is systematically used for espionage, infiltration of government networks, and sabotage of critical infrastructure, with a distinct reference to the operations of the FSB, especially those of Center 16.

The document mentions countries such as France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland as targets of these operations, with concrete examples – cyber espionage against government institutions and the defense industry or attacks on thermal power plants in Poland.

Romania, through the voice of President Nicușor Dan, "strongly condemned the hostile cyber activities carried out by FSB-controlled groups" and placed these operations within a "broader hybrid campaign" aimed at undermining Western democracies and testing the cohesion of the EU and NATO.

On a European level, the response includes sanctions against nine individuals and four entities – GRU officers, cybercriminals, hacktivists, and private companies – which shows that Turla and similar groups are viewed as political instruments of the Russian state, not merely as networks of cybercrime.

From a security perspective, the message from the EU and that of Romania seeks to draw a clear line: cyberspace is becoming a field of geopolitical confrontation, and Russian digital espionage is treated as a strategic threat, just like classic intelligence operations or military pressure on Ukraine.

What is Center 16 of the FSB

Center 16 of the Federal Security Service (FSB) is considered Russia's main hub for interception and technical espionage, inheriting the capabilities of the former "Directorate 16" of the KGB and the FAPSI agency. Academic analyses and OSINT investigations show that Center 16 "houses the majority of the FSB's technical intelligence capabilities," from intercepting communications to complex intrusion operations in computer networks.

A investigation conducted by the CheckFirst group, presented in the security press in Romania , describes Center 16 as a structure much more complex than previously believed, with at least ten internal departments, each assigning different missions in the spectrum of interception and cyber operations. The report emphasizes that Center 16 explicitly presents itself as the successor to the KGB's capabilities in the field of technical espionage, highlighting the continuity between the old Soviet apparatus and the current architecture of Russian intelligence.

Western services – including American, British, and Australian agencies – have attributed the most sophisticated cyber espionage tools , such as the Snake/Uroburos malware, directly to Center 16. These tools have been identified in infrastructures across more than 50 countries, indicating a global mandate for information collection, not just regional. The EU now adopts this conclusion in the official statement, specifying that Center 16 "controls a variety of cyber threat groups, including Turla," marking a political leap: from technical attribution to diplomatic acceptance of responsibility by the Russian state.

For Romania, the fact that it is mentioned in the European document as a target of Center 16's operations confirms the assessments of internal intelligence services regarding the increasing Russian cyber pressure on government institutions and critical infrastructure. From the perspective of intelligence specialists, this official publication also serves as a deterrent message: Russia is "named" directly, and structures like Center 16 are exposed as actors of espionage and sabotage, not merely as technical security entities.

Turla: the profile of a cyber espionage group

Turla is an "APT" (advanced persistent threat) group, active since the early 2000s, known for prolonged cyber espionage campaigns against governments, the military, and diplomatic missions. Organizations such as the Council on Foreign Relations (CFR) note that Turla has targeted entities in France, Russia, Belarus, Romania, the USA, the Netherlands, Germany, Poland, Austria, and other states, with a clear intelligence profile: government and military networks, not commercial entities.

In the technical environment, Turla is also known as Snake, Uroburos, Waterbug, VENOMOUS Bear, or Secret Blizzard, each label reflecting different campaigns or families of associated malware. Cybersecurity companies and Western services describe Turla as one of the most persistent and hardest-to-detect groups, capable of remaining in a network for years, using modular malware such as Snake, Carbon, Epic Turla, or Kazuar, continuously adapted for new targets.

Several threat intelligence reports have attributed Turla to the Russian Federation, with direct or indirect links to the FSB, and the analysis of a German media investigation cited by European experts mentions Turla programmers who have worked for Center Inform, a contractor that officially operates for the FSB. Moreover, a factsheet from the British government identifies actors from Center 16 behind monitoring and intrusion operations in Western government networks, confirming the convergence between Turla and the institutional capabilities of the FSB.

Kaspersky and other researchers have documented that Turla uses particularly sophisticated techniques to hide its command and control infrastructure, including exploiting vulnerabilities in satellite communication networks to mask the location of servers and direct exfiltrated data traffic through legitimate user IPs. This level of complexity is specific to state actors, with access to considerable technical and financial resources, and specialists in Russian espionage interpret Turla as a "technological arm" of the FSB, complementary to other GRU-associated groups, such as Fancy Bear/APT28 .

Implications for Romania and the EU

Politically, the exposure of Center 16 and the naming of Turla in the official European communication marks a change in tone: Russian cyber espionage is no longer treated as a technical subject, but as an explicit tool of foreign policy and pressure on the EU, NATO, and member states. President Nicușor Dan's reaction, which speaks of a "hybrid campaign aimed at undermining the stability of democracies, fueling divisions, and testing the cohesion of the EU and NATO," essentially reiterates the diagnosis of Western services regarding how Moscow uses digital tools.

For Romania, the message has two dimensions. Externally, the firm positioning alongside the EU and NATO aims to strengthen credibility as a security partner, at a time when alliances are testing the robustness of collective defense and in cyberspace. Internally, the communication serves as a call to strengthen cyber resilience – from protecting critical infrastructure to educating institutions and the public against phishing campaigns, disinformation, and digital intrusion.

Overall, Center 16 and Turla represent two faces of the same reality: an architecture of technical and cyber espionage, designed for massive information collection, compromising government networks, and, when necessary, sabotaging infrastructure – all integrated into Russia's broader strategy to contest the Euro-Atlantic security order. To the extent that the EU now publicly assumes attribution, and Romania aligns with this message, it follows a stage in which the game will no longer be just exposing Turla, but the ability of European states to transform this exposure into concrete investments in cyber defense and reforming legislation regarding responses to digital attacks.

Synthesis made with the help of Perplexity.