News Room
16
Share
FSB Center 16 Targeted in Global Crackdown After Polish Power Grid Sabotage and Critical Infrastructure Infiltration
criticalCritical Infrastructure

FSB Center 16 Targeted in Global Crackdown After Polish Power Grid Sabotage and Critical Infrastructure Infiltration

Western allies issue a major joint advisory and sanctions targeting Russia’s FSB Center 16 for systematic exploitation of critical infrastructure networking devices and the Polish grid attack.

17 July 2026Last updated 20 August 20265 min readCISA / FBI / NSA / NCSC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2018-0171, CVE-2017-6742
Source:
CISA / FBI / NSA / NCSC
Read Time:
5 min

Executive Summary

On July 14, 2026, a coalition of international cybersecurity agencies, including the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the UK’s National Cyber Security Centre (NCSC), released a comprehensive joint advisory detailing a sustained campaign by Russia’s Federal Security Service (FSB) targeting critical infrastructure. The advisory specifically identifies FSB Center 16—known by aliases such as Berserk Bear and Energetic Bear—as the primary actor behind the systematic infiltration of networking devices across the energy, water, and communication sectors. This disclosure coincides with new sanctions imposed by the EU and UK following the formal attribution of a near-blackout event on the Polish power grid in late 2024 to this specific unit.

Threat Analysis

The current threat landscape is defined by a shift from simple espionage to pre-positioning for disruptive kinetic effects. FSB Center 16 has demonstrated a high degree of persistence, maintaining access to some Western critical infrastructure networks for over a decade. Unlike ransomware groups that seek immediate financial gain, Center 16 focuses on 'living-off-the-land' (LotL) techniques to remain undetected. By compromising edge devices like routers and firewalls, they establish a bridgehead into Operational Technology (OT) and Industrial Control Systems (ICS) environments. Their recent activities show an increased focus on European energy stability and North American municipal water treatment facilities, suggesting a coordinated effort to identify and exploit societal pain points.

Technical Details

The primary vector for Center 16 remains the exploitation of poorly configured or legacy networking hardware. Specifically, the group utilizes automated scanning of internet-facing IP ranges to identify devices with default or weak Simple Network Management Protocol (SNMP) community strings. Once identified, the actors use SNMP 'set-requests' from spoofed IP addresses to command the devices to copy their configuration files via Trivial File Transfer Protocol (TFTP) to actor-controlled infrastructure. Technical analysis has also revealed continued exploitation of long-standing vulnerabilities, including CVE-2018-0171 (Cisco Smart Install RCE) and CVE-2017-6742 (Cisco IOS SNMP RCE). In the Polish grid incident, the actors leveraged these configuration exfiltrations to map the internal network topology, eventually traversing from the corporate IT environment into the SCADA systems governing regional power distribution.

Attribution Assessment

Attribution is confirmed with high confidence to the Russian Federal Security Service (FSB) Center 16. This assessment is based on the overlap of infrastructure, unique TTPs such as the specific sequence of SNMP queries, and the use of the 'Jaguar Tooth' malware family. Additionally, the Polish Domestic Intelligence Agency (ABW) provided forensic evidence linking the C2 infrastructure used in the 2024 grid attack to known FSB-registered netblocks. The coordinated response by sixteen nations reinforces the consensus that these operations are part of a state-directed strategy of hybrid warfare intended to destabilize NATO allies.

Implications

The implications of these ongoing campaigns are severe. The ability of a nation-state actor to remain embedded within critical systems for years means that 'flipping the switch' for physical disruption is a political decision rather than a technical hurdle. The shift toward targeting smaller, municipal utilities (water and electricity) highlights a vulnerability in the supply chain where local entities lack the resources of major national providers. This creates a tiered security environment where the most critical nodes may be the most exposed.

Recommendations

Encrygma analysts recommend immediate action for all OT/ICS operators. First, disable Cisco Smart Install (SMI) and legacy SNMPv1/v2c across all network assets, transitioning strictly to SNMPv3 with encryption. Second, implement strict network segmentation to ensure that the compromise of an edge router cannot result in lateral movement to the OT zone. Third, perform a comprehensive audit of all internet-facing devices for default credentials and unnecessary services like TFTP. Finally, organizations should enroll in no-cost vulnerability scanning services provided by national cyber agencies to ensure real-time visibility into their attack surface.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo