FSB Centre 16 is a Russian state cyber actor attributed by the United Kingdom and European partners to an attempted December 2025 cyberattack against Poland’s energy grid. The operation was publicly assessed as unsuccessful, but officials stated that a successful compromise could have disrupted electricity supply to roughly 500,000 people during winter, indicating a capability and intent to target critical national infrastructure for disruptive effect. FSB Centre 16 is associated with Russian state-directed cyber and hybrid operations aligned with Moscow’s strategic objectives. In the available reporting, the group is specifically linked to attempted intrusion activity against the energy sector in Poland. High-confidence public attribution in this case supports characterization of the actor as a Russian government threat actor engaged in hostile operations against foreign critical infrastructure. No additional aliases, malware families, or sub-groups are directly supported at high confidence in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state actor attributed with an attempted attack against Poland's energy grid, cited as broader threat context for energy-sector targeting.
Russian intelligence-linked cyber actor attributed with a failed attack on Poland’s energy grid that could have disrupted electricity for hundreds of thousands of citizens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.