China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?
China's Volt Typhoon group is pre-positioning malware in US critical infrastructure.
Summary
A war game simulating a Chinese cyberattack on US water utilities revealed the potential impact of Volt Typhoon's three-year pre-positioning campaign. This state-sponsored Chinese hacking group is planting malware within US critical infrastructure, aiming to disrupt essential services like water supply, power, and telecommunications, rather than focusing on espionage.
Full text
CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyEarlier this year, insurance executives gathered in a Times Square conference room to play out a scenario: A Chinese cyberattack knocks out 5,000 US water utilities at once. If you think that’s a far-fetched scenario, think again. WIRED’s Andy Greenberg got rare access to the closed-door war game and walked away with some disturbing conclusions. This week, Brian Barrett sits down to talk with Andy about Volt Typhoon, the Chinese state-sponsored hacking group that’s spent the past three years pre-positioning itself inside American infrastructure.Article mentioned in this episode:What Happens If China Hacks the US Water Supply? I Went to a Secret War Game to Find OutYou can follow Brian Barrett on Bluesky at @brbarrett and Andy Greenberg on Bluesky at @agreenberg. Write to us at [email protected].How to ListenYou can always listen to this week's podcast through the audio player on this page, but if you want to subscribe for free to get every episode, here's how:If you're on an iPhone or iPad, open the app called Podcasts, or just tap this link. You can also download an app like Overcast or Pocket Casts and search for “Uncanny Valley.” We’re on Spotify too.TranscriptNote: This is an automated transcript, which may contain errors.Brian Barrett: This is WIRED’s Uncanny Valley. I'm Brian Barrett, executive editor. We're on a short break from our usual roundtable for the rest of August. Everybody needs some time off sometimes. But we prepared two special conversations for you. This week, we're diving into something alarming that hasn't happened yet, but could. Earlier this year, about 30 insurance executives stepped into a conference room high above Times Square in Manhattan to simulate what would happen if a group of hackers from China attacked the US water supply. Specifically, the idea was to simulate a Chinese cyberattack that would knock out 5,000 water utilities in the US all at once and to do it under a countdown clock. WIRED senior correspondent Andy Greenberg got a rare invite to this closed-door war game; call it Dungeons & Dragons for a national security nightmare. It was designed by a former cybersecurity strategist to test what would happen if and when hackers linked to an infamous Chinese operation called Volt Typhoon finally decide to follow through on groundwork that they've been laying for three years.Archival audio: This group that's known as Volt Typhoon, this is a state-sponsored Chinese hacking group.Archival audio: China has secretly stepped up its electronic warfare, deploying what is being called the Volt Typhoon malware throughout the US ecosystem.Brian Barrett: The result could include burst water mains, evacuated hospitals, and insulin shortages. Andy's here to tell us more about what he saw and heard, and why the scariest part might not quite be the hack itself, but what it revealed about who's actually in charge when the water stops. Andy, thanks so much for being here.Andy Greenberg: Glad to do it, Brian.Brian Barrett: Before we get any deeper into the game itself, could you tell us what Volt Typhoon is and how worried people should be in general about this group?Andy Greenberg: Well, Volt Typhoon is a hacker group that I think represents some of the worst nightmares of the cybersecurity community and the US government, those who have to plan for catastrophic national security scenarios. This is a Chinese state-sponsored hacker group that does not, like most Chinese state hackers, focus on espionage, but rather has been, it appears, for the last three years, planting malware inside of US critical infrastructure, pre-positioning, as people put it, sort of laying the groundwork for the ability to disrupt these systems, to turn off the power, to cause blackouts, to disrupt telecommunications, and potentially to affect the water supply. When Volt Typhoon first came to light in 2023—it's been three years now—the headlines said they were targeting electric grids and telecommunication networks in the continental US and in Guam specifically. It seemed like they were probably targeting US military facilities and the surrounding infrastructure. We were trying to figure out their motives for this, and the theory that I think all of us have been working under is that perhaps China is laying the groundwork, preparing for an invasion of Taiwan perhaps, and they want to be able to disrupt these US military facilities to delay a US response to an invasion of Taiwan. But then, it began to become clear that they were actually breaking into US electric and water utilities and other civilian critical infrastructure, not just military, but US civilian infrastructure across the whole US, including, it seems, towns as small as Littleton, Massachusetts. I spoke, in fact, to the chief information security officer of the water and electric utility in Littleton who just had no idea why Chinese hackers would be targeting his town of 10,000 people. But what that suggests is that China is trying to gain the ability not just to disrupt the US military, but to actually cause widespread societal chaos in the US as another perhaps diversionary distraction tactic maybe in the midst of this crisis when they invade Taiwan. This is all just a theory, but the pieces are there. The fact is that China really is breaking into US civilian critical infrastructure. And I don't want to sound overdramatic here, but laying what Rob Joyce, the former NSA director of cybersecurity, describes as digital bombs strapped to our infrastructure.Brian Barrett: It's a theory that's at the heart of this war game exercise that you went to. The theory is, what if they do pull the trigger on this? How do people react? Do you mind setting the scene, even just how you got there in the first place? Because this is not the kind of thing that people are normally invited to. You normally don't get a look into something like this. So how'd you get invited? Who's there?Andy Greenberg: I have been trying to find a way into this story about Volt Typhoon for years, because I feel like this actually is one of the most important things happening in cybersecurity today. It's gone under the radar in part because China has this incredible restraint that they've never actually pulled the trigger and caused a disruptive cyberattack. So I was talking a lot to Joshua Corman about this. Joshua is a former strategist for CISA, the Cybersecurity and Infrastructure Security Agency. So he mentioned to me that he runs these war games, actually dozens of them, for different groups. He invited me to one in particular that he was doing with insurance executives. I thought this sounded like maybe the most boring approach to this very dramatic cyberwar story, but Josh explained, and I am now persuaded, that insurance plays such an important role in the response to an event like this. It turns out that when a company gets hacked or hit with a cyberattack like this, their first call is very often to their insurance agency, which then is the one that unlocks the lawyers and the cybersecurity incident responders, whom they have already preapproved and are now willing to pay for. So cyber insurance actually controls, on this kind of surprising level, our whole national response to an event like this. They are the first call. They want to actually know exactly what is going to happen, because they are the ones who will be financially on the hook. And that, to me, sounded actually like a kind of counterintuitively very interesting perspective.Brian Barrett: It makes sense. I mean, when you think about who knows the most about recovery from a hurricane, it's probably Allstate and State Farm. It's home insurers who are there for every step of the process. When you think about these large-scale disasters, which is what we're describing here, a large-scale cybersecurity disaster, that's the equivalent, right? It's the equivalent of the Allstates or the