Russian state actors are systematically harvesting router configurations from critical infrastructure networks. The sectors in their crosshairs map almost directly onto New Zealand’s commercial cyber insurance market – and the domestic loss data makes the stakes concrete.
On July 14, 2026, the New Zealand National Cyber Security Centre (NCSC-NZ) joined 18 partner agencies in releasing a joint Cybersecurity Advisory (CSA) warning that Russian Federal Security Service (FSB) Center 16 cyber actors are exploiting poorly configured routers and networking devices across critical infrastructure sectors worldwide. Co-sealing agencies include the US National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and counterparts from Australia, Canada, the UK, France, Estonia, Finland, Italy, Poland, Sweden, the Czech Republic, and Denmark. The advisory, classified TLP:CLEAR for unrestricted distribution, builds on more than a decade of documented FSB Center 16 activity. The threat group is tracked under several names in the cybersecurity industry, including Berserk Bear, Energetic Bear, Dragonfly, Ghost Blizzard, and Static Tundra.
FSB Center 16 actors scan internet-facing IP ranges for networking devices running Simple Network Management Protocol (SNMP) agents configured with common or default authentication strings. Using proxies and spoofed IP addresses, they direct vulnerable devices to copy their configurations to files – typically named “config.bkp” or “output.txt” – then transfer those files via Trivial File Transfer Protocol (TFTP) to actor-controlled virtual private servers or compromised FTP servers. The advisory also documents exploitation of known Cisco vulnerabilities, including CVE-2018-0171 and CVE-2008-4128.
The advisory explicitly notes that these tactics overlap with those used by Salt Typhoon, the Chinese state-sponsored group that the White House warned in December 2024 had compromised major global telecommunications providers across dozens of countries. Subsequent reporting has linked the campaign to attacks on around 80 telecommunications providers worldwide. The campaign did not stop there. Recorded Future’s Insikt Group identified Salt Typhoon attempting to exploit more than 1,000 internet-facing Cisco network devices globally between December 2024 and January 2025, targeting unpatched devices associated primarily with telecommunications providers. The NCSC has assessed that New Zealand’s critical infrastructure operators could be vulnerable to similar activity from People’s Republic of China state-sponsored actors. The common thread across both campaigns – Russian FSB and Chinese Salt Typhoon – is unpatched, internet-exposed network devices running with default or weak credentials. The advisory’s mitigations address both threats simultaneously.
The advisory identifies six critical infrastructure sectors as most exposed: communications, Defense Industrial Base, energy, financial services, government services and facilities, and healthcare and public health. For cyber underwriters, the domestic loss picture gives these categories financial weight.
The NCSC’s Cyber Threat Report 2025 recorded 5,995 incidents between July 1, 2024, and June 30, 2025, with 331 classified as incidents of potential national significance. Of those, 82 were linked to suspected state-sponsored actors. In Q1 2026, direct financial losses totalled $5.6 million – a 76% increase from the previous quarter – with three incidents classified at the NCSC’s second-highest severity level, the first time that threshold had been reached since the 2021/22 financial year.
New Zealand is losing more than $1.6 billion annually to cybercrime, and 59% of large businesses experienced a cyber incident in the past year. The 2026 Kordia New Zealand Business Cyber Security Report, surveying nearly 250 businesses of 50 or more employees, found that one in five businesses impacted by a cyber incident faced financial extortion, and 17% of cyberattack victims filed insurance claims.
The advisory arrives against a shifting regulatory backdrop with direct consequences for insurance. The New Zealand government’s Cyber Security Strategy 2026-2030, released in February 2026, proposes mandatory requirements for approximately 200 of New Zealand’s most significant entities across seven essential services – from energy and finance to health, transport, and communications – including the development and maintenance of a risk management programme aligned with recognised frameworks such as NIST CSF or ISO 27001 and mandatory reporting of significant cyber incidents within 72 hours. The consultation on those measures closed in April 2026, with regulatory action expected to follow.
For insurers, a move toward mandatory baseline controls for critical infrastructure operators would directly affect both the risk profile of policyholders in those sectors and the adequacy of existing policy wordings. That shift is already visible at the application stage. New Zealand cyber insurers have materially tightened application requirements, with multi-factor authentication and role-based access controls now functioning as baseline eligibility criteria. Certification against recognised security frameworks has shifted from a premium discount lever to a precondition for coverage in mid-market and enterprise policies. Network device configuration – including SNMP version, default credential exposure, and management protocol access – represents exactly the category of internet-facing risk that automated carrier scans are increasingly designed to detect before a policy is bound.
The advisory’s recommended mitigations include disabling Cisco Smart Install, replacing SNMPv1 and SNMPv2 with SNMPv3, using Cisco hashing type 8 for stored credentials, restricting SNMP OID access via a Management Information Base (MIB) allow list, blocking TFTP and SNMP ports at edge firewalls, and replacing end-of-life devices. Marsh notes that cyber premiums in New Zealand have levelled off, but cautions that carriers expect effective cybersecurity controls, and organisations without basic protections may find it more difficult to secure coverage.
New Zealand organisations that suspect compromise are encouraged to contact NCSC-NZ at [email protected] or through the NCSC’s online reporting tool. The helpline operates Monday to Friday, 7am to 7pm, at 0800 114 115 at no charge from within New Zealand.