Earlier this year, insurance executives gathered in a conference room above New York City’s Times Square to simulate one of the most alarming cybersecurity scenarios imaginable: a Chinese cyberattack that disables 5,000 US water utilities simultaneously. While the exercise was hypothetical, the threat behind it is real. WIRED senior correspondent Andy Greenberg was granted rare access to the private cybersecurity war game and uncovered troubling insights about Volt Typhoon, the Chinese state-sponsored hacking group that has spent years positioning itself inside critical American infrastructure.
Articles mentioned in this episode:
Follow Brian Barrett on Bluesky at @brbarrett. Follow Andy Greenberg at @agreenberg. Contact us at [email protected].
How to listen to this podcast
Listen to this week’s episode using the audio player on this page. You can also subscribe for free to receive every episode of WIRED Uncanny Valley.
On an iPhone or iPad, open the Podcasts app or visit this link. You can also use podcast apps such as Overcast or Pocket Casts and search for “Uncanny Valley.” The show is also available on Spotify.
Transcript
Note: This is an automated transcript and may contain errors.
Brian Barrett: This is WIRED Uncanny Valley. I’m Brian Barrett, executive editor. We are taking a short break from our regular roundtable episodes during August, but we’ve prepared two special conversations for you. This week, we’re examining a frightening scenario that has not happened—but could.
Brian Barrett: Earlier this year, roughly 30 insurance executives gathered in a conference room above Manhattan’s Times Square to simulate the consequences of a coordinated Chinese cyberattack on the US water supply. The exercise imagined 5,000 water utilities being disabled at the same time, with participants forced to respond against a countdown clock.
Brian Barrett: WIRED senior correspondent Andy Greenberg received an unusual invitation to join this private cybersecurity war game. The exercise was designed by a former cybersecurity strategist to explore what could happen if the Chinese hacking group known as Volt Typhoon activated the access it has reportedly spent the past three years establishing inside American infrastructure.
Archive audio: The group, known as Volt Typhoon, is a Chinese state-sponsored hacking operation.
Archive audio: China has quietly expanded its cyber operations and deployed Volt Typhoon malware across parts of the US infrastructure ecosystem.
Brian Barrett: The simulated attack could trigger broken water mains, hospital evacuations, medical supply shortages, insulin disruptions, and other cascading emergencies. Andy joins us to explain what he witnessed, what Volt Typhoon has been doing, and why the most frightening part of the scenario may not be the initial cyberattack—but the confusion over who is responsible once essential services begin to fail.
Brian Barrett: Andy, thanks for joining us.
Andy Greenberg: Thanks for having me, Brian.
Brian Barrett: Before we discuss the war game, explain what Volt Typhoon is and how seriously people should take the threat posed by this group.
Andy Greenberg: Volt Typhoon represents one of the most serious cybersecurity concerns facing the US government and the broader security community. It is a Chinese state-sponsored hacking group, but its apparent mission differs from the traditional espionage campaigns associated with many Chinese cyber operations.
Andy Greenberg: Over the past several years, Volt Typhoon appears to have focused on gaining persistent access to critical infrastructure in the United States. That access could potentially be used to disrupt industrial systems, interfere with communications, trigger power outages, damage operational technology, or affect water supplies.
Andy Greenberg: When the group was publicly identified in 2023, reporting and government warnings indicated that it had targeted power grids, communications systems, and other networks in the continental United States and Guam. Some of those targets appeared to be connected to US military installations and the civilian infrastructure surrounding them.
Andy Greenberg: One leading theory was that China could use this access during a conflict over Taiwan to slow or complicate the US military response. By disrupting communications, transportation, energy, or logistics systems, Chinese hackers could create delays at a critical moment.
Andy Greenberg: But investigators increasingly found evidence that the activity extended beyond military targets. Volt Typhoon also appeared to be accessing civilian infrastructure, including power and water providers in communities far from major strategic facilities. In one case, hackers reportedly targeted a utility serving Littleton, Massachusetts, a town of approximately 10,000 residents.
Andy Greenberg: I spoke with the chief information security officer for Littleton’s water and power company. He had no clear explanation for why a Chinese state-sponsored group would be interested in a relatively small American town. That uncertainty is part of what makes the campaign so unsettling.
Andy Greenberg: The activity suggests that China’s potential objectives could extend beyond disrupting the US military. During a Taiwan crisis, widespread attacks on civilian systems could create confusion, public panic, and social disruption across the United States. They could serve as a diversion or amplify the effects of a broader geopolitical conflict.
Andy Greenberg: Those motives remain theories, and the available evidence does not provide a complete picture. What we do know is that Chinese hackers have been penetrating US critical infrastructure. Former NSA cybersecurity director Rob Joyce described the situation as a digital bomb attached to America’s infrastructure.
Brian Barrett: That phrase captures why the war game was so important. It was not simply an exercise about whether a hacker could enter a network. It focused on what happens when an adversary has already gained access and decides to use it—potentially causing simultaneous failures across water systems and other essential services.
Andy Greenberg: Exactly. The exercise forced participants to consider the real-world consequences of a coordinated infrastructure attack. Water utilities are especially vulnerable because many operate with limited cybersecurity staff, aging technology, and systems that were never designed to withstand nation-state attacks.
Andy Greenberg: A major cyberattack would also create problems far beyond the initial technical failures. Hospitals could lose access to clean water, municipalities could struggle to communicate with residents, and emergency responders would have to operate while facing uncertainty about which systems were compromised. If power, telecommunications, fuel, and water networks were affected at the same time, the consequences could spread rapidly.
Brian Barrett: And the lack of certainty about the attacker could make the crisis even worse.
Andy Greenberg: Yes. Attribution takes time, especially during a fast-moving emergency. Officials might not immediately know whether a water outage was caused by a foreign government, a criminal ransomware group, an equipment failure, or an internal mistake. That ambiguity could delay the response and make it harder to reassure the public.
Andy Greenberg: The central warning from the exercise is that Volt Typhoon may not need to launch a dramatic attack today to create danger. By quietly establishing access in advance, the group could preserve the option to act later, at a time chosen for maximum disruption. That is why cybersecurity officials are urging utilities and infrastructure operators to identify and remove hidden access before it can be used.
Source: www.wired.com


