The UK, France, the EU, and partner cyber agencies publicly attributed a broad cyber-espionage campaign to FSB Centre 16, linking the Russian intelligence unit to both the long-running Turla intrusion set and active exploitation of internet-facing routers and network devices. UK and allied authorities warned that the actor is scanning globally for poorly configured infrastructure, abusing default or weak SNMP credentials and known Cisco-related weaknesses such as Smart Install and web-management flaws to seize control of devices, with critical sectors including communications, defence, energy, financial services, government, and healthcare identified as high-risk targets.
French authorities said entities in France, including ministries and organizations in the diplomatic, defence, justice, and technology sectors, were targeted and compromised using Turla tradecraft that has been active since at least 2004. The coordinated disclosures were accompanied by formal attribution statements from France and the EU, while the UK said EU member states and London also attributed the December 2025 attack on Poland’s energy grid to FSB Centre 16 and announced sanctions against 24 individuals and entities tied to Russian destructive cyber and hybrid operations. Defenders were urged to harden network devices by adopting SNMPv3, disabling legacy SNMP versions, enforcing strong unique passwords, and restricting access to management interfaces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
In 2019, French investigators said Turla compromised a justice-sector server hosting a continuing-education service by exploiting a Microsoft SharePoint-related vulnerability and installing malware. The intrusion potentially exposed information associated with several thousand user accounts.
On 2026-07-13, CISA added CVE-2008-4128, a Cisco IOS flaw affecting Cisco 871 Integrated Services Routers, to its Known Exploited Vulnerabilities catalog after confirming real-world exploitation. The reference ties the exploitation to actors associated with Russia's FSB Center 16 and notes the affected IOS release has been unsupported since 2016.
On 2026-07-13, the European Union imposed sanctions on Russian military intelligence officers, hackers, and private companies over what it described as a yearslong cyber espionage and sabotage campaign targeting governments and critical infrastructure in at least nine countries. The EU said the network contributed to efforts to destabilize the bloc and highlighted the FSB's 16th Centre as controlling multiple threat groups.
The NCSC notice states that the UK simultaneously sanctioned 24 individuals and entities linked to destructive cyber and hybrid operations associated with Russian intelligence services.
The NCSC said the UK and EU member states formally attributed the December 2025 attack on Poland's energy grid to FSB Centre 16 as part of coordinated public action on 13 July 2026.
On 13 July 2026, the UK NCSC and 18 partner agencies from 12 countries issued a joint advisory warning that Russia's FSB Centre 16 is exploiting poorly configured and vulnerable routers and network devices globally, especially in critical sectors.
On 13 July 2026, France and the European Union issued formal attribution statements regarding malicious cyber activities linked to the Turla intrusion set and attributed them to the 16th Centre of Russia's FSB.
France said the FSB-linked Turla campaign had targeted French entities for more than a decade, including French military ministry email accounts, the French diplomatic network in Moscow, technology-sector companies, an advanced-technologies entity, and a justice-sector organization. The attribution was based on investigations by ANSSI, DGSE, DGSI, the Direction générale de l’armement, and the French Cyber Defence Command.
Members of France's Cyber Crisis Coordination Centre (C4) observed French entities being targeted and compromised using the Turla intrusion set, affecting ministries and organizations in the diplomatic, defence, justice, and technology sectors.
UK and EU officials said a failed January attack on Poland’s energy grid was carried out by actors linked to FSB Center 16. Officials warned the operation could have disrupted electricity service for 500,000 Polish citizens.
The NCSC notice states that an attack on Poland's energy grid occurred in December 2025 and was later formally attributed to FSB Centre 16 by the UK and EU member states.
CERT-FR reported that the Turla intrusion set, attributed to the 16th Centre of Russia's FSB, has been used since at least 2004 for intelligence-gathering against strategic entities and individuals worldwide, including in France.
The reference says the Russia-affiliated group identified as FSB Center 16 has targeted vulnerable routers and network infrastructure affecting telecommunications, higher education, and manufacturing since 2015, with activity especially impacting Ukraine and allied countries. The campaign used SNMP scanning and exploitation of older Cisco flaws, including CVE-2018-0171 and CVE-2008-4128.
In August 2025, an FBI IC3 warning said operators linked to Russia's FSB Center 16 had compromised thousands of network devices in critical infrastructure sectors. The warning described two main access vectors: exposed SNMP v1/v2 with weak or default community strings and exploitation of Cisco Smart Install flaw CVE-2018-0171.
CERT-FR anchored ongoing Turla espionage campaigns against Ukraine, NATO countries, and EU member states to the context of Russia's war of aggression launched on 24 February 2022.
The joint advisory said the Russian group tied to FSB Center 16 has exploited Cisco Smart Install vulnerability CVE-2018-0171 since November 2021. The activity was linked to the group's broader targeting of routers and network devices used to access critical infrastructure networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcekyberturvallisuuskeskus.fi
Open sourcefoxbusiness.com
Open sourcemalware.news
Open sourcedarkreading.com
Open sourcencsc.gov.uk
Open sourcetp-link.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.