CISA, the NSA, and the FBI have confirmed that a Chinese state-sponsored group known as Volt Typhoon compromised IT networks at multiple U.S. critical infrastructure organizations. The sectors they named are communications, energy, transportation, and water and wastewater. That includes the continental United States, the territories, and Guam. This is not a future risk assessment. It is access they already found.
In the February 2024 joint advisory, those agencies said the pattern does not look like ordinary espionage. They assess with high confidence that Volt Typhoon is pre-positioning on IT networks so it can move toward operational technology and disrupt functions in a crisis. In some victim environments they saw footholds held for at least five years. The public advisory is AA24-038A.
Rob Joyce, former NSA Director of Cybersecurity, put it in plainer language in the Army’s Cyber Defense Review. China, he wrote, has strapped the digital equivalent of explosives to the backbone of American society. Volt Typhoon went after the nodes that would matter in the first 72 hours of a Pacific fight: ports, transport, Guam communications, utilities. That essay is here.
What is confirmed, and what is not
Confirmed: persistent access in multiple organizations across those four sectors. Living-off-the-land techniques. Valid accounts and built-in admin tools instead of noisy custom malware. Water and wastewater is on the victim list. WaterISAC told utilities the same thing when the advisory dropped.
Not confirmed: a public count of how many water plants are infected. Officials have said any number they gave would likely be an underestimate. Dragos, which has worked Volt Typhoon cases, said in 2026 the group was still embedding in U.S. utilities and that some compromised sites will never be found. The Record reported that assessment.
One named case is enough to make it real. The FBI called the Littleton Electric Light and Water Department in Massachusetts and told them Chinese state hackers had been inside a town of about 10,000 people for months. That is not a think-tank slide. That is a Friday phone call.
Then they ran the nightmare on a clock
Separately, insurance executives sat in a Times Square conference room and played a tabletop designed by Josh Corman, a former CISA strategist, with CyberAcuView. The scenario was not “Volt Typhoon is in 5,000 plants today.” It was: what if 5,000 U.S. water utilities go down at once.
Andy Greenberg sat in that room for WIRED. After a simulated day, the injects were ugly. Burst mains. About 2,000 hospitals without water. Insulin and other water-dependent manufacturing bottlenecked. Data-center cooling in trouble. The question on the table was not how to evict the hackers. It was who gets the limited responders first, and who gets nothing.
The exercise found what anyone who has dealt with a small municipal plant already knows. Utilities operate as islands. There is no single federal command that can run a shared playbook across thousands of local systems at the same time. Insurers also ran into the act-of-war problem: a catastrophe that large may be uninsurable if the clauses hold.
That is a game. Treat it as a game. The reason it is worth writing down is that the pieces under the game are not fictional. The access campaign is documented. The water sector is fragmented on purpose. Most of those plants do not have a hunt team.
If that scenario ran in the real world
You do not need Hollywood. You need pressure, pumps, and time.
- Loss of pressure and failed controls at enough plants at once, and boil-water orders, hospital diversions, and fire-suppression problems stack up in hours, not weeks.
- Small towns cannot surge cybersecurity staff they never hired. The Littleton case is the model: they found out because the FBI called.
- A state-linked disruption that large would immediately become an attribution and insurance fight, which is another way of saying the people without water wait.
- The “just reset the passwords” instinct fails against living-off-the-land access that was built to look like the IT guy.
None of that requires 5,000 confirmed implants today. It requires enough persistent access, and a decision in Beijing, and a sector that is mostly local.
What is actually useful
- If you run or sit on a board for a water or power utility, read the CISA advisory and the living-off-the-land guidance. Assume admin tools and VPNs are the front door.
- Ask, on the record, whether your plant has been briefed on Volt Typhoon and whether anyone has hunted for LOTL persistence, not just malware alerts.
- Segment IT from the controls that move water. Internet-facing PLCs are how other countries have already caused real pressure loss this year. That is a different campaign. The lesson is the same.
- At home, a few days of drinking water is an ice-storm kit. It is not a China plan. Do not confuse the two.
The story is not that 5,000 utilities already have bombs in the SCADA. The story is that a Chinese military-linked crew has been living in American infrastructure, including water, and when serious people simulated the worst day, nobody owned the response. That is enough. You do not have to dress it up.
Primary Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
