
FSB Center 16 Targeted in Global Crackdown After Polish Power Grid Sabotage and Critical Infrastructure Infiltration
Western allies issue a major joint advisory and sanctions targeting Russia’s FSB Center 16 for systematic exploitation of critical infrastructure networking devices and the Polish grid attack.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2018-0171, CVE-2017-6742
- Source:
- CISA / FBI / NSA / NCSC
- Read Time:
- 5 min
Executive Summary
On July 14, 2026, a coalition of international cybersecurity agencies, including the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the UK’s National Cyber Security Centre (NCSC), released a comprehensive joint advisory detailing a sustained campaign by Russia’s Federal Security Service (FSB) targeting critical infrastructure. The advisory specifically identifies FSB Center 16—known by aliases such as Berserk Bear and Energetic Bear—as the primary actor behind the systematic infiltration of networking devices across the energy, water, and communication sectors. This disclosure coincides with new sanctions imposed by the EU and UK following the formal attribution of a near-blackout event on the Polish power grid in late 2024 to this specific unit.
Threat Analysis
The current threat landscape is defined by a shift from simple espionage to pre-positioning for disruptive kinetic effects. FSB Center 16 has demonstrated a high degree of persistence, maintaining access to some Western critical infrastructure networks for over a decade. Unlike ransomware groups that seek immediate financial gain, Center 16 focuses on 'living-off-the-land' (LotL) techniques to remain undetected. By compromising edge devices like routers and firewalls, they establish a bridgehead into Operational Technology (OT) and Industrial Control Systems (ICS) environments. Their recent activities show an increased focus on European energy stability and North American municipal water treatment facilities, suggesting a coordinated effort to identify and exploit societal pain points.
Technical Details
The primary vector for Center 16 remains the exploitation of poorly configured or legacy networking hardware. Specifically, the group utilizes automated scanning of internet-facing IP ranges to identify devices with default or weak Simple Network Management Protocol (SNMP) community strings. Once identified, the actors use SNMP 'set-requests' from spoofed IP addresses to command the devices to copy their configuration files via Trivial File Transfer Protocol (TFTP) to actor-controlled infrastructure. Technical analysis has also revealed continued exploitation of long-standing vulnerabilities, including CVE-2018-0171 (Cisco Smart Install RCE) and CVE-2017-6742 (Cisco IOS SNMP RCE). In the Polish grid incident, the actors leveraged these configuration exfiltrations to map the internal network topology, eventually traversing from the corporate IT environment into the SCADA systems governing regional power distribution.
Attribution Assessment
Attribution is confirmed with high confidence to the Russian Federal Security Service (FSB) Center 16. This assessment is based on the overlap of infrastructure, unique TTPs such as the specific sequence of SNMP queries, and the use of the 'Jaguar Tooth' malware family. Additionally, the Polish Domestic Intelligence Agency (ABW) provided forensic evidence linking the C2 infrastructure used in the 2024 grid attack to known FSB-registered netblocks. The coordinated response by sixteen nations reinforces the consensus that these operations are part of a state-directed strategy of hybrid warfare intended to destabilize NATO allies.
Implications
The implications of these ongoing campaigns are severe. The ability of a nation-state actor to remain embedded within critical systems for years means that 'flipping the switch' for physical disruption is a political decision rather than a technical hurdle. The shift toward targeting smaller, municipal utilities (water and electricity) highlights a vulnerability in the supply chain where local entities lack the resources of major national providers. This creates a tiered security environment where the most critical nodes may be the most exposed.
Recommendations
Encrygma analysts recommend immediate action for all OT/ICS operators. First, disable Cisco Smart Install (SMI) and legacy SNMPv1/v2c across all network assets, transitioning strictly to SNMPv3 with encryption. Second, implement strict network segmentation to ensure that the compromise of an edge router cannot result in lateral movement to the OT zone. Third, perform a comprehensive audit of all internet-facing devices for default credentials and unnecessary services like TFTP. Finally, organizations should enroll in no-cost vulnerability scanning services provided by national cyber agencies to ensure real-time visibility into their attack surface.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iran-Linked Actors and Qilin Ransomware Escalate Strikes on UK Energy and Defense Supply Chains

US Declares National Emergency as Foreign-Linked Cyberattacks Target Critical Power and Water Infrastructure

