Weak Security Continues to Fuel Russian Cyberattacks
In a first, the UK and the EU jointly imposed sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.
State- threat actors affiliated with Russia's Federal Security Service (FSB) Center 16 continue to compromise weakly protected routers and other networking equipment to gain access to critical infrastructure networks worldwide, according to US cybersecurity agencies and counterparts in a dozen allied countries in a joint advisory this week.
Organizations most at risk include those in the defense industrial base, energy, financial services, government, and healthcare sectors, the advisory noted.
In related guidance on improving router security, the US National Security Agency (NSA) described the malicious activity as an ongoing issue that has impacted US and foreign organizations for years. "NSA and co-sealing agencies emphasize the importance of basic router hygiene as a means for companies and organizations to deter state-level cyber actors," the agency said.
The joint advisory coincided with news of the United Kingdom and the European Union imposing sanctions on 24 Russian individuals and entities for their role in orchestrating cyberattacks across Europe and the UK, for election interference, and Ukraine-related disinformation campaigns . The list of those sanctioned included senior officials in Russia's military intelligence agency (GRU), cybercriminal proxies, and organizations accused of supporting Russian cyber operations and influence campaigns.
UK and EU officials also formally attributed a failed attack on Poland's energy grid in January to FSB Center 16 calling the incident "a reckless attack" that could have left 500,000 Polish citizens with no electricity in the middle of winter. "It is another example of the Russian state's irresponsible attempts to sow chaos across Europe," representatives from the UK and the EU said in a statement disclosing the sanctions.
This is the first time that the UK and the EU have jointly sanctioned Russian state actors and their proxies for cyberattacks and other malicious activities in the region. The latest sanctions bring to 3,400 the number of individuals and entities that the UK has sanctioned so far in connection with Russia's war in Ukraine.
The joint advisory on the Russian attacks targeting insecure routers and other networking gear builds on an FBI advisory last year on the same threat. It offers a detailed look at the tactics that FSB Center 16 actors — tracked variously as Energetic Bear , Crouching Yeti, Ghost Blizzard ( Turla ), and Static Tundra — use to gain access to targeted environments. The most common method, according to the advisory, is for the actors to scan for exposed SNMP services that accept factory-default or easily guessed passwords. They then instruct compromised devices to export their configuration files to attacker-controlled servers using Trivial FTP (TFTP) or FTP.
Many of these technique overlap with those used by other advanced persistent threat (APT) actors such as Salt Typhoon , the advisory said. Though poor configuration and weak security hygiene are the primary enablers of compromise, the threat actors also exploit known Cisco vulnerabilities and misuse Cisco Smart Install (SMI) for initial access, the agencies added.
From a risk mitigation standpoint, critical infrastructure organizations should disable Cisco Smart Install and swap out SNMPv1 for v2 SNMPv3, which offers stronger authentication and encryption support. The authoring agencies also want organizations to replace default passwords with strong, unique ones for all network devices, monitor SNMP Set requests and unusual local account activity, use access control lists, and block unneeded TFTP, SNMP, and Smart Install traffic at network boundaries.
The advisory is another reminder how state actors continue to succeed by exploiting problems that organizations are well aware of and should have addressed years ago, said John Strand, owner of Black Hills Information Security, Inc., in a statement. Security teams have known tactics like abusing SNMP or leveraging Cisco Smart Install for more than a decade and should be able to protect against them, Strand said.
“Every time we see a large nation-state campaign, there's a temptation to focus on the newest exploit or the most sophisticated technique," he said. In reality, these campaigns are often built around vulnerabilities and insecure configurations that have been public knowledge for years. Attackers are succeeding "because too many organizations still struggle with the fundamentals of computer security."
Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.
Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.
Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.
His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.
The State of Cloud Security: The Latest Challenges
The total economic impact™ of Snyk
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure
Governing the Agent; Identity Security in the Age of Autonomous AI
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
