NCSC and Global Allies Expose Russian FSB Router Attacks: What UK Businesses Need to Do Now

The National Cyber Security Centre (NCSC), working with 18 agencies across 12 countries, has published a joint advisory exposing a sustained campaign by Centre 16 of Russia’s Federal Security Service (FSB). The same unit has now been formally blamed for the December 2025 attack on Poland’s energy grid, an attack that could have left half a million people without power. On the same day, the UK Government sanctioned 24 individuals and entities linked to Russian cyber and hybrid operations.

This is not a distant, government-only problem. The attackers are not hand-picking their victims. They are scanning the internet for any poorly configured router or network device they can find, and taking whatever access presents itself.

How the attacks work

The group, tracked under names including Berserk Bear, Static Tundra and Ghost Blizzard, favours quiet, low-effort routes into networks:

  • Legacy SNMP scanning: older versions of the Simple Network Management Protocol are queried at scale to identify and compromise exposed routers.
  • Unpatched network devices: known vulnerabilities in Cisco equipment, including the Smart Install feature, are exploited to seize control of switches and routers.
  • Long-term persistence: once inside, the actors sit quietly on network infrastructure, gathering intelligence and positioning for future disruption.

Communications, energy, healthcare, defence and financial services organisations are named as priority targets, but opportunistic scanning means any business with a neglected router is exposed.

Why this matters to Gloucestershire businesses

Routers, switches and firewalls are the least-loved devices on most networks. They were installed years ago, they still pass traffic, and nobody has looked at their firmware or configuration since. That is precisely the gap this campaign exploits. A compromised edge device gives an attacker a vantage point over everything that flows through your network, without ever touching a laptop or triggering endpoint protection.

What you should do now

The advisory sets out clear, practical steps:

  1. Disable legacy SNMP (v1 and v2c) and move to SNMPv3 with strong authentication.
  2. Patch network devices, not just servers and workstations. Firmware on routers, switches and firewalls needs the same discipline.
  3. Disable unused services such as Cisco Smart Install.
  4. Restrict management access so devices cannot be administered from the open internet.
  5. Monitor network infrastructure for unexpected configuration changes and logins.

The NCSC also encourages organisations to achieve Cyber Essentials certification, the UK Government-backed minimum standard, and to use the updated Cyber Assessment Framework to measure their resilience.

How System Force IT can help

As a Cyber Essentials accredited, ISO/IEC 27001:2022 certified managed service provider, System Force IT builds this discipline into every network we manage: hardened configurations, managed firmware patching, restricted management access and continuous monitoring across your entire estate, edge devices included.

If you cannot say with confidence when your routers were last patched, or whether legacy SNMP is still enabled on your network, now is the time to find out. Contact System Force IT on 01452 701355 for a network infrastructure security review.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name