EU, UK Sanction Russia's Centre 16 Amid Sustained Cyberattacks on European Critical Infrastructure

The EU has imposed restrictive measures on nine individuals and four entities linked to the 16th Centre of Russia’s FSB, including GRU intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies, with targets spanning France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland. France has seen cyber espionage against strategic governmental entities since 2010 and against the defence industry in 2025, and Poland has experienced disruptive sabotage against critical infrastructure such as combined heating and power plants.
Centre 16 is also known by the aliases Berserk Bear, Static Tundra, and Ghost Blizzard, and its operators have focused on SNMP scanning to identify vulnerable routers, as well as exploiting Cisco device vulnerabilities and the Cisco Smart Install feature to seize network devices.
The UK’s National Cyber Security Centre, in a joint advisory with 18 agencies, warns that Centre 16 has been opportunistically targeting vulnerable routers and critical national infrastructure worldwide; the advisory highlights sectors at heightened risk including communications, energy, healthcare, defense, and financial services, and notes sanctions against 24 individuals and entities involved in destructive cyber and hybrid operations.
Poland’s energy network has been named among the targets of these operations, with EU officials pointing to the 16th Centre’s disruptive sabotage of critical infrastructure in Poland, including actions affecting energy facilities.
The UK's National Cyber Security Centre has issued a joint warning with 18 international agencies about a Russian intelligence-linked hacking group called Centre 16, also known as Berserk Bear or Ghost Blizzard. The group, tied to Russia's FSB spy service, has been targeting vulnerable routers and critical infrastructure across Europe and beyond, according to IT Pro and HEAL Security.
The EU has responded with sanctions against nine individuals and four entities linked to Centre 16. Targets hit by the group include energy networks in Poland, government bodies in France, and critical infrastructure across multiple EU member states.
Centre 16 operators use a technique called SNMP scanning to find routers with weak security. SNMP stands for Simple Network Management Protocol — it is a tool that manages devices on a network. Hackers can abuse it to spot easy targets. The group also exploits flaws in Cisco devices and a feature called Cisco Smart Install to seize control of network equipment, according to IT Pro.
Once inside a network, the group can spy on communications or disrupt services entirely. The NCSC advisory flags sectors at the highest risk: communications, energy, healthcare, defense, and financial services. The warning applies to organizations worldwide, not just in Europe, according to HEAL Security.
Poland has been one of the hardest-hit countries. EU officials say Centre 16 carried out disruptive sabotage against Polish critical infrastructure, including combined heating and power plants. These are not just espionage operations — they are attacks designed to cause real physical disruption.
France has faced cyber espionage targeting strategic government bodies since 2010. In 2025, attacks expanded to hit the French defense industry directly. The EU Council pointed to these incidents as part of a long-running pattern of Russian aggression, according to PubAffairs Bruxelles and EU Neighbours East.
The EU Council imposed restrictive measures on nine individuals and four entities linked to Centre 16. Those sanctioned include GRU intelligence officers, cybercriminals, and self-proclaimed hacktivists. Private companies that supported the operations were also hit. Affected countries span France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland, according to PubAffairs Bruxelles.
The UK's joint advisory listed sanctions against 24 individuals and entities involved in destructive cyber and hybrid operations. Romania's president also publicly condemned the attacks and pledged to work with international partners to bolster cybersecurity. Officials across the EU have called this part of a broader hybrid campaign to weaken democracies and break EU unity, according to EU Neighbours East.
The NCSC advisory urges all organizations — especially in energy, healthcare, and finance — to check their routers for weak settings. Disabling the Cisco Smart Install feature is a key step. Using strong authentication for SNMP and keeping firmware updated are also recommended. These are basic steps, but the advisory warns many networks remain exposed, according to IT Pro.
The coordinated response from the UK, EU, and allied agencies signals a shift toward collective deterrence. Rather than acting alone, governments are naming names, imposing sanctions, and publishing technical details together. The goal is to raise the cost for Russia's cyber operators and make it harder for them to hide their methods.
Publishers
43
Articles
88
Reach
131