NSA-Led Advisory Pins FSB Center 16 on Router Intrusions Across Critical Infrastructure
A 19-agency joint advisory attributes a decade-long campaign of router exploitation to Russia's FSB Center 16, as the EU and UK sanction 24 individuals and entities over a linked attack on Poland's power grid.
The U.S. government and 15 allied cybersecurity agencies released a joint advisory on July 13 warning that operators inside Russia's Federal Security Service are still moving through critical infrastructure networks by walking in through the front door, specifically, routers left running default credentials and deprecated management protocols.
The advisory, cataloged by CISA as AA26-194A and titled "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," attributes the activity to FSB Center 16. The private sector tracks overlapping activity under at least six names. As the CISA advisory itself notes, those naming conventions don't always map cleanly onto government attribution, so treat any single vendor's label as a partial view, not a complete picture.
The technique isn't exotic. According to the joint advisory reviewed by Security Info Watch, Center 16 operators scan internet-connected address ranges for routers accepting default or commonly known Simple Network Management Protocol authentication strings. Once in, they can pull device configurations containing network topologies, credentials, and VPN details. The Cisco Smart Install protocol, patched in 2018 and added to CISA's Known Exploited Vulnerabilities catalog in November 2021, remains a favored pivot point. That's a vulnerability with a four-year KEV listing still showing up in active intrusion activity, which tells you something about patch compliance rates in operational environments.
The sectors named as most at risk in the advisory include communications, defense industrial base, energy, financial services, government facilities, and healthcare. That's not a narrow target set.
The advisory dropped the same week the EU and UK announced coordinated sanctions against 24 Russian individuals and entities. According to reporting reviewed by Viakoo, those sanctions are formally tied to a December 2025 attempt to deploy wiper malware against Poland's energy grid, an operation that would have cut power to roughly 500,000 people in winter conditions. The EU Council also sanctioned the Center for Applied Research of Special Developments, identified as responsible for attacks on EU government bodies, financial institutions, and media outlets.
There's an attribution caveat worth flagging here. According to analysis published by Picus Security drawing on the joint advisory, CERT Polska attributed the Poland grid attack to Center 16 with high confidence based on infrastructure overlaps. ESET and Dragos reached a different conclusion, assigning the wiper activity to Sandworm, the GRU-linked group, at moderate confidence. The EU and UK formally blamed Center 16 on July 13. That's a meaningful disagreement between credible technical analysts, and the moderate-confidence Sandworm assessment shouldn't just disappear because governments issued sanctions.
The advisory's mitigation list reads like a network hygiene baseline from a decade ago: upgrade to SNMPv3, disable SNMPv1 and v2c, disable Cisco Smart Install, block TFTP and Smart Install at the firewall, enforce strong unique passwords, update firmware. As Decode39 noted in coverage of the advisory, these aren't complex countermeasures. The political message in a document signed by 19 agencies across 13 countries is that a state-sponsored intrusion campaign is still succeeding, at scale, against some of the world's most sensitive infrastructure, by exploiting basic configuration failures.
The advisory builds directly on an FBI public service announcement from August 2025, according to the CISA advisory page. That continuity matters. This isn't a new threat vector getting an initial disclosure. It's a documented, long-running campaign that's been named, sanctioned, and warned about repeatedly, and it's still working.
Sources cited:
- CISA Advisory AA26-194A (cisa.gov) (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a)
- CISA Press Release, July 14 2026 (cisa.gov) (https://www.cisa.gov/news-events/news/cisa-joins-nsa-fbi-dc3-and-international-partners-warning-russian-cyber-threat-activity-targeting)
- Picus Security, FSB Center 16 SNMP/Smart Install analysis (https://www.picussecurity.com/resource/blog/fsb-center-16-how-russian-hackers-exploit-routers-via-snmp-and-cisco-smart-install)
- Security Info Watch, Router Advisory Coverage (https://www.securityinfowatch.com/cybersecurity/news/55390764/russian-state-backed-hackers-target-vulnerable-routers-in-critical-infrastructure-agencies-warn)
- Viakoo, Daily OT Security News July 14 2026 (https://www.viakoo.com/blog/daily-ot-security-news-july-14-2026/)
- Decode39, NSA Router Hygiene Advisory Coverage (https://decode39.com/15671/nsa-warns-russian-fsb-is-exploiting-weak-routers-to-target-critical-infrastructure/)
This release was originally distributed via ETL Newswire. Visit CISA Advisory AA26-194A (cisa.gov) for the full story, related releases, and contact information.
Visit CISA Advisory AA26-194A (cisa.gov) →