On July 13, 2026, the European Union and the United Kingdom took an unprecedented step by announcing a coordinated package of severe sanctions. The measures targeted 9 individuals and 4 organizations directly involved in conducting destructive operations in cyberspace. Official Brussels and London openly identified the main organizer of this long-term campaign as “Center 16” — not another group of “independent hackers,” but a systematic militarized structure within the FSB of Russia that is waging a full-scale hybrid war against Europe’s critical infrastructure, governments, and civil society.
To understand the scale and specifics of “Center 16,” it is necessary to examine its history. This unit did not emerge out of nowhere during the rise of internet technologies; it is the direct successor to the legendary 16th Directorate of the KGB of the USSR, which for decades engaged in radio-electronic intelligence, interception of communications, and decryption of messages from foreign states. After the collapse of the Soviet Union, the structure underwent several transformations, temporarily becoming part of the Federal Agency for Government Communications and Information (FAPSI). However, in 2003, as part of a major reform of Russian special services, the unit returned to the structure of the Federal Security Service — the bosom of its historical “parent” organization. Today it is officially known as the Center for Radio-Electronic Intelligence on Communications Facilities (CRRSCF) of the FSB of Russia, and is better known in professional circles as military unit 71330 (v/ch 71330).
The headquarters of this structure is located in Moscow, but the key technological hub and training ground has traditionally been Ryazan, where specialized communications facilities and personnel training sites are situated. According to assessments by specialized investigators and independent media, the staff of “Center 16” currently exceeds 500 specialists. The internal structure of the Center is strictly classified and is divided into specialized directorates by area of focus (including Directorates “A,” “B,” “V,” and others), as well as regional departments that provide round-the-clock monitoring of global networks and the execution of targeted tasks.
While the civilian sector discusses cybercrime as a decentralized phenomenon, military unit 71330 operates under strict military laws, coordinating the actions of an entire “constellation” of hacker groups.
The technical arsenal available to “Center 16” specialists is extensive. For more than twenty years, the main technological pride and at the same time the most dangerous espionage weapon of the Center has been the malicious software (malware) known by the codename “Snake,” also referred to in the expert community as “Turla” or “Uroboros.” “Snake” is an extremely sophisticated cyber-espionage platform designed for covert infiltration into the most protected government and military networks. The program is capable of remaining undetected for years, creating its own encrypted communication channels within infected infrastructure, and silently transmitting gigabytes of confidential information to FSB servers. It was only in May 2023 that the U.S. Department of Justice, together with the FBI and international partners, announced the successful completion of a technical operation to neutralize and disrupt the global “Snake” network. The coordinates of the command servers and the malware’s infrastructure led directly to the Ryazan hub of “Center 16.”
In addition to targeted spyware, “Center 16” actively employs tactics of large-scale, indiscriminate campaigns. According to joint official technical alerts and cybersecurity advisories issued by the FBI, the U.S. National Security Agency (NSA), CISA, and cybersecurity agencies of 12 allied countries in 2025–2026, the priority target for Russian military hackers has become the mass “penetration” of network equipment.
The methodology followed by “Center 16” specialists is a well-oiled assembly line, where each stage logically flows into the next. The process begins with continuous automated scanning of the global internet. Special software complexes search in real time for devices with critical security flaws. The agency has a particular interest in outdated but still widely used administration protocols such as SNMPv1/v2, as well as known vulnerabilities in network routers — a prominent example being the exploitation of flaws in the Cisco Smart Install system.
Upon discovering such weak points, the hackers do not simply breach the devices; they turn thousands of compromised home and corporate routers around the world into a large-scale distributed network of “proxy servers.” This intermediate infrastructure serves as an ideal shield, and by routing subsequent destructive attacks through it, “Center 16” reliably masks its true digital footprints. As a result, government structures in the attacked countries face an extremely complex task, since the use of proxy nodes significantly complicates investigations, entangles traffic redirection chains, and makes rapid attribution of incidents almost impossible.
It is precisely because of this sophisticated stealth tactics and constant change of digital signatures that the activities of “Center 16” and the commercial IT contractors under its control were for a long time recorded only fragmentarily. In reports from leading international information security companies and government cybersecurity agencies, this large-scale state-sponsored interference by Russia was for years identified under various names. Depending on the toolkit used and the specific targeted sector, researchers assigned this activity the names of such well-known hacker groups as “Turla,” “Berserk Bear,” “Energetic Bear,” “Sitting Yeti,” “Dragonfly,” “Ghost Blizzard,” and “Static Tundra.” Today it is becoming clear that behind all these disparate pseudonyms lies a single coordination center of Russian military cyber intelligence.
The activities of “Center 16” are distinctly transnational in nature. Its focus is on critical life-support systems of European countries, the defense-industrial complex, and diplomatic agencies.
The French Republic has been one of the main targets of the CRRSCF since the early 2010s. Hackers from military unit 71330 carried out methodical work to penetrate closed networks of ministries, agencies, and leading defense-industrial enterprises. A detailed picture of this interference was documented by the French CERT (C4 service), which published a comprehensive technical report in 2026 numbered CERTFR-2026-CTI-005. According to the document, cyberattacks by “Center 16” in France pursued exclusively intelligence goals, such as collecting data on the latest military developments, diplomatic correspondence, and Paris’s strategic plans within NATO.
While in France “Center 16” preferred to act discreetly, direct aggression methods were used against Poland. The most dangerous incident occurred in December 2025, amid winter cold, when the “Static Tundra” group, directly controlled by “Center 16,” attempted a coordinated breach of the Polish energy system and water supply systems. The attackers’ goal was to implant destructive code into the automated process control systems (SCADA/ICS) of power plants. According to the Polish CERT, which promptly detected the anomalous activity, a successful attack could have left more than 500,000 civilians without heating, electricity, and clean drinking water for an indefinite period in sub-zero temperatures. This incident showed that the goals of Russian special services’ cyberattacks have gone beyond classical espionage and now pose a direct physical threat to the lives of civilians.
The scale of “Center 16’s” destructive activity is not limited to isolated incidents but has the character of total expansion. Official documents of the Council of the European Union directly emphasize that the geography of harmful operations by military unit 71330 covers almost the entire European continent, affecting the most diverse spheres — from national security to the everyday life of ordinary citizens. Analysis of documented cyber intrusions reveals a clear logic according to which, for each European capital, the Russian special service selects its own individual scenario based on Moscow’s geopolitical interests.
Thus, in Germany, the key targets of the hackers were government networks and the infrastructure of leading political parties. Here, “Center 16” operatives solved classic tasks of compromising political leadership by organizing targeted leaks of internal correspondence and collecting confidential compromising material for subsequent manipulation of public opinion. A completely different vector was chosen for the Netherlands, where attacks targeted international organizations based in the country and major port logistics facilities. In this case, FSB handlers were interested in espionage on independent international investigations and intercepting data on cargo movements in key European transport hubs.
In parallel, “Center 16” conducts systematic reconnaissance of the European energy sector. In Austria and Slovakia, the efforts of the groups were concentrated on collecting detailed technical information about the operation of gas transport hubs, giving the Kremlin additional leverage in the event of an energy crisis escalation. On the northern flank, in Finland, the priority shifted toward defense agencies, where Russian cyber specialists, seeking to obtain alliance military secrets, established continuous monitoring of Helsinki’s integration processes into NATO defense structures. Finally, the examples of Cyprus and Romania clearly demonstrate the cynicism of the Center’s methods: by attacking the financial sector and healthcare institutions, the hackers provoked massive leaks of personal data of millions of citizens and temporarily paralyzed hospital operations, endangering patients’ lives.
However, state institutions are far from the only target of the raging “digital war.” Objects of permanent pressure from “Center 16” also include the coordinating structures of the North Atlantic Alliance itself, Russian opposition politicians who have left the country, as well as independent investigative journalists and human rights organizations. This comprehensive approach proves that military unit 71330 solves tasks across a wide spectrum — from classical military espionage to the physical suppression of civil resistance and preparation for large-scale technological sabotage.
The joint actions of the EU and the United Kingdom in July 2026 demonstrated that the patience of European leaders has been exhausted. Their coordinated sanctions aim not only to punish but also to disrupt the financial flows that sustain the functioning of military unit 71330. The restrictions introduced by the British government affected 24 individuals and legal entities, including IT contractor companies that acted as developers for the FSB. The EU sanctions imposed a strict ban on any financial transactions with persons involved in “Center 16’s” activities and closed their access to the territory of European states. At the same time, efforts of Western intelligence services are being consolidated. International alliances have moved from passive defense to active identification and public disclosure of the methods used by Russian special services’ hackers. The publication of detailed technical indicators of compromise (IoCs) allows commercial companies and government agencies worldwide to promptly cleanse their networks of spyware.
The activities of “Center 16” of the FSB of Russia have shown that modern interstate confrontation has finally moved into cyberspace, and military unit 71330 is a full-fledged tool for conducting contactless but extremely dangerous hybrid warfare by the Kremlin. For Europe, the key conclusion should be the need for further tightening of control over the security of critical infrastructure, a complete rejection of potentially vulnerable equipment in the public sector, and a multiple increase in investment in national CERTs. The security border for European citizens now runs not only on land and sea but also through every home router and server rack.
