A Chinese state-sponsored hacking group known as Volt Typhoon has spent the last three years embedding malware into critical infrastructure across the United States, positioning itself to disrupt essential services. This activity, described by some as "digital bombs" strapped to infrastructure, has prompted concerns about potential widespread societal chaos.
Initially, Volt Typhoon was believed to be targeting electric grids and telecommunication networks in the continental U.S. and Guam, likely with a focus on U.S. military facilities and surrounding infrastructure. The prevailing theory suggested these actions were in preparation for a potential Chinese invasion of Taiwan, aiming to delay a U.S. response.
However, subsequent analysis revealed that the group's activities extended beyond military targets to include civilian critical infrastructure, such as electric and water utilities, across the entire U.S. This includes smaller towns like Littleton, Massachusetts, raising questions about the broader motivations behind these intrusions. Experts now theorize that China might be seeking the capability to cause significant disruption and distraction within the U.S. during a potential crisis, such as a Taiwan invasion.
While Volt Typhoon has not yet initiated any disruptive cyberattacks, the groundwork laid by the group has spurred simulations and war games to assess potential responses. One such closed-door exercise, attended by approximately 30 insurance executives in Times Square, simulated a scenario where a Chinese cyberattack simultaneously disabled 5,000 U.S. water utilities.
The war game, designed by a former strategist for the Cybersecurity and Infrastructure Security Agency (CISA), aimed to test reactions under a countdown clock. The simulated outcomes included burst water mains, hospital evacuations, and insulin shortages, highlighting the potential for severe societal impact.
The involvement of insurance executives in such a simulation underscores their critical, if often overlooked, role in national cybersecurity response. When organizations experience a cyberattack, their first call is frequently to their insurance provider. These providers then facilitate access to pre-approved lawyers and cybersecurity incident responders, effectively controlling the initial stages of a national response due to their financial backing of recovery efforts.
The persistent and widespread nature of Volt Typhoon's intrusions into U.S. civilian infrastructure represents a significant concern for cybersecurity experts and government officials. The group's apparent restraint in activating these "digital bombs" has, paradoxically, allowed their activities to remain somewhat under the radar, despite the severe potential consequences should they decide to launch a disruptive attack.






