A classified war game this week exposed a chilling reality: Chinese hackers have spent the last three years quietly embedding malware into American water utilities and civilian infrastructure, and the United States has no unified plan to stop them or respond if they activate.
The simulation, which Andy Greenberg of Wired attended, dramatized what national security officials have known but struggled to act on — that a Chinese hacking group called Volt Typhoon has been methodically planting what amount to digital bombs inside the pipes, pumps, and control systems that keep water flowing to American homes and hospitals. These aren’t ransomware attacks demanding payment or data breaches stealing credentials. This is something far more deliberate: persistent access, embedded deep, waiting.
- The Scale of Penetration: Volt Typhoon has embedded malware across thousands of American water utilities, electric grids, gas pipelines, and telecommunications systems over a three-year campaign.
- No Unified Response Exists: A classified war game revealed that no single federal command structure coordinates defense across compromised infrastructure — utilities operate in isolation with no shared playbook.
- The Threat Is Already Inside: CISA, the NSA, and the FBI jointly confirmed that Volt Typhoon actors have achieved and maintained persistent access inside US critical infrastructure, meaning the access exists now, not as a future risk.
Volt Typhoon’s three-year campaign represents a fundamental shift in how state-sponsored hackers operate. Rather than smash-and-grab theft or immediate disruption, the group has focused on what security researchers call “living off the land” — using legitimate administrative tools and blending into normal network traffic to avoid detection. The group has targeted not just water systems but also electric grids, gas pipelines, and telecommunications infrastructure across multiple US states. The goal appears to be positioning for maximum damage should geopolitical tensions with China escalate into actual conflict. This pattern fits squarely within the broader dynamic of nations competing for digital dominance as a geopolitical instrument.
What makes this threat distinct from past cyberattacks is its scale and patience. No immediate ransom demand, no stolen data dumps, no public claim of responsibility. Instead, Volt Typhoon has been establishing what’s known as “persistence” — the ability to maintain access even if one entry point is discovered and closed. It’s the digital equivalent of an adversary quietly placing explosives throughout a building and then leaving, waiting for the order to detonate.
• The US Department of Justice confirmed in January 2024 that Volt Typhoon used a compromised botnet of hundreds of routers to conceal its intrusions into critical infrastructure, making detection significantly harder for defenders.
• A joint advisory from CISA, NSA, and FBI released in February 2024 documented that Volt Typhoon actors maintained persistence inside US networks for at least five years in some cases.
• Water utilities across the US frequently operate on control systems installed in the 1990s and 2000s, designed for a threat environment that did not include nation-state cyber operations.
What Did the War Game Actually Reveal?
The war game that Greenberg observed simulated exactly what happens when the order to activate comes. The exercise revealed a fragmented, unprepared response. Water utilities operate independently, often with aging infrastructure and minimal cybersecurity staffing. There is no single federal command center coordinating defense across all compromised systems. State agencies have different protocols. The military and civilian government don’t have a unified playbook. When the simulated attack unfolded, the response was chaos — confusion about who was in charge, delays in information sharing, utilities operating in isolation without knowing whether neighboring systems were also under attack.
The Volt Typhoon campaign also exposes a structural vulnerability in how America secures critical infrastructure. Many water utilities still run on systems installed decades ago, designed for a world where the biggest threat was a disgruntled employee with physical access, not a nation-state with advanced hacking capabilities. Updating these systems costs money that municipal budgets often don’t have. Cybersecurity expertise is scarce in rural areas. The result is a patchwork of defenses — some utilities are hardened and monitored constantly; others are essentially unguarded. The financial exposure this creates extends well beyond operational disruption, as explored in the context of data breaches and cyberattack liability more broadly.
Why Has Volt Typhoon Targeted These Specific Systems?
Volt Typhoon’s targeting pattern reveals strategic thinking. The group hasn’t scattered its efforts randomly. It has focused on utilities in regions that would cause maximum cascading disruption if water systems failed simultaneously — areas where hospitals, data centers, and population centers depend on reliable supply. A coordinated shutdown across multiple states wouldn’t just cut off drinking water; it would disable firefighting capacity, collapse sewage treatment, and create public health emergencies within hours.
This mirrors a critical pattern from the Cambridge Analytica era, though in reverse. Where Cambridge Analytica harvested behavioral data at scale to identify and micro-target individual voters with psychographic precision — mapping the vulnerabilities of democratic opinion — Volt Typhoon is mapping critical infrastructure at scale to identify and pre-position access for mass disruption. Both operations exploit the same underlying truth: centralized systems with distributed vulnerabilities create opportunities for actors with patience and resources. Cambridge Analytica weaponized data profiles; Volt Typhoon is weaponizing infrastructure blueprints. The difference is one targeted your vote, the other targets your water.
• CISA’s February 2024 advisory warned explicitly that Volt Typhoon’s behavior is inconsistent with traditional espionage objectives and instead suggests pre-positioning for potential disruptive or destructive cyberattacks against US critical infrastructure in the event of a major crisis or conflict.
• The advisory notes that the group’s use of legitimate tools — rather than custom malware — makes attribution and detection substantially harder, as malicious activity blends with routine administrative behavior.
• The practical implication for infrastructure operators is that conventional intrusion detection systems calibrated for known malware signatures are insufficient against this class of threat.
Is the US Government’s Response Adequate?
The US government has known about Volt Typhoon for years. The FBI and CISA have issued warnings. But warnings alone haven’t translated into coordinated action. Utilities remain fragmented. Funding for upgrades is inadequate. There is no legal mandate requiring water systems to meet baseline cybersecurity standards, no federal authority with power to force rapid remediation across all compromised sites.
The contrast with past infrastructure attacks is instructive. The Colonial Pipeline ransomware attack in 2021 — which disrupted fuel distribution across the Eastern Seaboard — prompted emergency regulatory action and exposed how quickly physical consequences follow digital intrusions. A detailed analysis of the Colonial Pipeline attack illustrates how a single point of failure in critical infrastructure can cascade into a national emergency within days. Volt Typhoon represents not one such point of failure but thousands, embedded simultaneously and activated on command.
What you should understand about this threat is that it is not hypothetical. The tap water, the shower, the toilet — the systems delivering those rely on networks that state-sponsored hackers have already penetrated and can access at will. If Volt Typhoon activates even a fraction of its embedded access simultaneously, the disruption would cascade. Hospitals couldn’t operate. Fire departments couldn’t respond. Sewage would back up. The impact would be physical, immediate, and felt in every home.
What Happens If the Next War Game Is Not a Simulation?
The war game this week was meant to force a reckoning. It did expose the gaps. But exposure isn’t the same as action. As of now, there is still no unified federal command structure for responding to a coordinated infrastructure attack. Utilities are still operating independently. Funding for cybersecurity upgrades is still inadequate. And Volt Typhoon’s digital access remains embedded, waiting.
The question now is whether this simulation becomes a catalyst for change or simply another warning that gets filed away. The structural problems — fragmented governance, underfunded utilities, aging control systems, and no mandatory baseline standards — existed before Volt Typhoon and will persist after any single advisory or war game. Closing those gaps requires legislative action, sustained federal investment, and a level of coordination between civilian agencies, the military, and thousands of independent utilities that the US has not yet demonstrated it can achieve at speed. The next war game might not be a simulation.
