
WIRED's Andy Greenberg discusses a secret war game modeling a coordinated cyberattack by Volt Typhoon.
Insurance executives participated in a secret war game simulating a simultaneous cyberattack by Chinese state-sponsored hackers on 5,000 US water utilities, revealing critical national security and resource response vulnerabilities.
AI-generated summary
Volt Typhoon is a state-sponsored Chinese hacking group that has spent years pre-positioning malware inside American critical infrastructure.
Earlier this year, insurance executives gathered in a Times Square conference room to play out a scenario: A Chinese cyberattack knocks out 5,000 US water utilities at once. If you think that’s a far-fetched scenario, think again. WIRED’s Andy Greenberg got rare access to the closed-door war game and walked away with some disturbing conclusions. This week, Brian Barrett sits down to talk with Andy about Volt Typhoon, the Chinese state-sponsored hacking group that’s spent the past three years pre-positioning itself inside American infrastructure.
Brian Barrett: This is WIRED’s Uncanny Valley. I'm Brian Barrett, executive editor. We're on a short break from our usual roundtable for the rest of August. Everybody needs some time off sometimes. But we prepared two special conversations for you. This week, we're diving into something alarming that hasn't happened yet, but could. Earlier this year, about 30 insurance executives stepped into a conference room high above Times Square in Manhattan to simulate what would happen if a group of hackers from China attacked the US water supply. Specifically, the idea was to simulate a Chinese cyberattack that would knock out 5,000 water utilities in the US all at once and to do it under a countdown clock. WIRED senior correspondent Andy Greenberg got a rare invite to this closed-door war game; call it Dungeons & Dragons for a national security nightmare. It was designed by a former cybersecurity strategist to test what would happen if and when hackers linked to an infamous Chinese operation called Volt Typhoon finally decide to follow through on groundwork that they've been laying for three years.
Brian Barrett: The result could include burst water mains, evacuated hospitals, and insulin shortages. Andy's here to tell us more about what he saw and heard, and why the scariest part might not quite be the hack itself, but what it revealed about who's actually in charge when the water stops. Andy, thanks so much for being here.
Andy Greenberg: Glad to do it, Brian.
Brian Barrett: Before we get any deeper into the game itself, could you tell us what Volt Typhoon is and how worried people should be in general about this group?
Andy Greenberg: Well, Volt Typhoon is a hacker group that I think represents some of the worst nightmares of the cybersecurity community and the US government, those who have to plan for catastrophic national security scenarios. This is a Chinese state-sponsored hacker group that does not, like most Chinese state hackers, focus on espionage, but rather has been, it appears, for the last three years, planting malware inside of US critical infrastructure, pre-positioning, as people put it, sort of laying the groundwork for the ability to disrupt these systems, to turn off the power, to cause blackouts, to disrupt telecommunications, and potentially to affect the water supply. When Volt Typhoon first came to light in 2023—it's been three years now—the headlines said they were targeting electric grids and telecommunication networks in the continental US and in Guam specifically. It seemed like they were probably targeting US military facilities and the surrounding infrastructure. We were trying to figure out their motives for this, and the theory that I think all of us have been working under is that perhaps China is laying the groundwork, preparing for an invasion of Taiwan perhaps, and they want to be able to disrupt these US military facilities to delay a US response to an invasion of Taiwan. But then, it began to become clear that they were actually breaking into US electric and water utilities and other civilian critical infrastructure, not just military, but US civilian infrastructure across the whole US, including, it seems, towns as small as Littleton, Massachusetts. I spoke, in fact, to the chief information security officer of the water and electric utility in Littleton who just had no idea why Chinese hackers would be targeting his town of 10,000 people. But what that suggests is that China is trying to gain the ability not just to disrupt the US military, but to actually cause widespread societal chaos in the US as another perhaps diversionary distraction tactic maybe in the midst of this crisis when they invade Taiwan. This is all just a theory, but the pieces are there. The fact is that China really is breaking into US civilian critical infrastructure. And I don't want to sound overdramatic here, but laying what Rob Joyce, the former NSA director of cybersecurity, describes as digital bombs strapped to our infrastructure.
Brian Barrett: It's a theory that's at the heart of this war game exercise that you went to. The theory is, what if they do pull the trigger on this? How do people react? Do you mind setting the scene, even just how you got there in the first place? Because this is not the kind of thing that people are normally invited to. You normally don't get a look into something like this. So how'd you get invited? Who's there?
Andy Greenberg: I have been trying to find a way into this story about Volt Typhoon for years, because I feel like this actually is one of the most important things happening in cybersecurity today. It's gone under the radar in part because China has this incredible restraint that they've never actually pulled the trigger and caused a disruptive cyberattack. So I was talking a lot to Joshua Corman about this. Joshua is a former strategist for CISA, the Cybersecurity and Infrastructure Security Agency. So he mentioned to me that he runs these war games, actually dozens of them, for different groups. He invited me to one in particular that he was doing with insurance executives. I thought this sounded like maybe the most boring approach to this very dramatic cyberwar story, but Josh explained, and I am now persuaded, that insurance plays such an important role in the response to an event like this. It turns out that when a company gets hacked or hit with a cyberattack like this, their first call is very often to their insurance agency, which then is the one that unlocks the lawyers and the cybersecurity incident responders, whom they have already preapproved and are now willing to pay for. So cyber insurance actually controls, on this kind of surprising level, our whole national response to an event like this. They are the first call. They want to actually know exactly what is going to happen, because they are the ones who will be financially on the hook. And that, to me, sounded actually like a kind of counterintuitively very interesting perspective.
Brian Barrett: It makes sense. I mean, when you think about who knows the most about recovery from a hurricane, it's probably Allstate and State Farm. It's home insurers who are there for every step of the process. When you think about these large-scale disasters, which is what we're describing here, a large-scale cybersecurity disaster, that's the equivalent, right? It's the equivalent of the Allstates or the State Farms.
Andy Greenberg: Absolutely. The fact is, they were doing this internally for their own benefit. In fact, I was kind of sworn to secrecy in a sense; I'm not allowed to identify anybody in the room. They didn't want this to be public. So I felt like this was maybe the closest thing to the ground truth of an estimate of what this would be like that I was going to be able to find.
Brian Barrett: So you're in the conference room near Times Square, you've got a bunch of the executives. What is the scenario that they're playing? And what were your first impressions as the exercise began?
Andy Greenberg: So Joshua, he gives us some ground rules first, like don't fight the scenario, which is, Brian, you understand that as a former improv comedian.
Brian Barrett: Yes, and your way through the apocalypse.
Andy Greenberg: Yes, that's true of Dungeons & Dragons, and it's true of cybersecurity role-playing as well. So it turns out that his scenario was that 5,000 water utilities across the US appear to have been hacked and disrupted. And in some cases, the hackers have even caused physical destruction of equipment, like changing the water pressure to the degree that water mains have burst. Nobody knows who has done this, nobody knows exactly what the effects have been, but everybody downstream of these water utilities has lost water. All of this is unfolding in July of 2027, just a year from now. And Josh, he read us a New York Times headline from that morning that he invented, which was something like, "As the United States prepares to celebrate its independence, Taiwan fears for its own." Meaning tension is building between China and Taiwan, and that was laying the groundwork for this notion that that's when this kind of catastrophic cyberattack might come. So after laying out this day-one scenario, 5,000 water utilities hacked, these groups of insurance executives who were actually set up at tables role-playing are told, "You have just received a kind of restricted memo from the US government." The two questions that Josh initially put to them, their first assignment in the game, is to decide who are they going to tell about this? Do they tell all of their customers? Do they tell just the ones that they think have been affected? Do they say nothing and wait for their customers who are affected to come to them? And then probably the more important of these two questions, when they do start to get claims from affected water utilities, who are their customers? How do they prioritize who to dole out resources to? Because it's already going to start to become clear that there is real resource scarcity here.
Brian Barrett: Then Joshua, who's acting as the guide for this exercise, starts making things gradually worse and worse, right?
Andy Greenberg: As soon as he's given them this assignment, he's wandering around the room and comes over to our table, and he says, "OK, actually, you all don't get any incident responders. The main companies that do kind of infrastructure security like Dragos and CrowdStrike and Mandiant, they're completely at capacity already. So sorry, you don't get any incident responders. You have to figure out how to deal with this on your own."
Brian Barrett: What do you think Josh was going for in that moment?
Andy Greenberg: Josh told me before it began, actually, that his entire goal with this was to, as he says, surface and shatter assumptions. He wants to shock people out of complacency about thinking that they might know how this is going to unfold and know how to deal with it. I think 5,000 water utilities is enough that that makes sense. I think that there are not enough incident responders in the country for all of those victims to get professionals in the room looking at their network. So the insurance companies, they're going to have to figure out, like, who do they prioritize? That was really the question that Josh was posing to them. In fact, my table was already trying to brainstorm about, "Well, maybe we can get people from academia to help. Maybe we can beg for help from the US government. Maybe we can get the National Guard to help us." I mean, it was kind of a desperate situation from the very beginning. What the table I was sitting at came up with was, "Let's just say the biggest customers first." And Josh was like, "Well, biggest by what metric?" And the spokesperson for the table just off the cuff was like, "Well, biggest by revenue." And that I think was just their kind of knee-jerk insurance industry answer. It turned out to be, I think, a very unfortunately naive and probably quite disastrous response.
Brian Barrett: Coming up after the break, we'll get into why there are no simple decisions when dealing with a national cybersecurity emergency. So, tell me why. I mean, other than that it sort of feels callous, what's the rationale? What are the repercussions of prioritizing revenue when you're dealing with a cybersecurity emergency like Volt Typhoon could cause?
Andy Greenberg: Well, that started to become clear on day two of the game. On day two was when it started to hit the fan, so to speak, things got very real and disturbing. So Josh kind of announces, "OK, 24 hours have passed. Now the second-order effects of all of those water utility outages, destructions, and burst water mains are starting to become clear." Data centers can't get water, can't cool their computers. All kinds of cloud services are going down. Manufacturing is extremely water-dependent, drug manufacturing especially, so there's a shortage of insulin. Even electrical generation, most of it requires water in some form. But maybe the most critical of all of these things is that hospitals definitely need water, their HVAC systems in particular. So thousands of hospitals across the US are facing HVAC outages and may have to be evacuated in the hottest parts of the country. OK, now Josh is asking this same question again for round two. How do you prioritize your response now? He kind of upped the pressure by introducing different figures in the story who are making different demands of the insurance companies. The public and the media are asking, like, what are insurance companies doing to protect human life in this scenario? Treasury is asking them to focus on economic concerns. And then the US military is actually asking them to focus on protecting US military infrastructure. So now the stakes have kind of become clear, and the insurance companies have a sense of, like, well, which of these things do we value? Human life, the economy, or US national security and military priorities?
Brian Barrett: It's a remarkable moment in the story, I thought, because almost everyone in that room says saving human lives are the priority, but not everyone. One person pushes back pretty hard.
Andy Greenberg: Yeah. I mean, I think the easy answer in a role-playing game especially is to say, "Well, of course, we'll protect human life. We'll prioritize that." But there was just one person at one table wh
AI outlook — possibilities, not facts
Insurance companies will face increasing pressure to address critical infrastructure cyber risks.
Likely · Within months

A roundup of tech and science developments including NASA's cancellation of the Swift telescope rescue, Tesla's massive recall in China, Meta's ongoing legal challenges regarding child safety, and the rise of Inner Mongolia as an AI data center hub.

A humanoid robot named Lightning, developed by Honor, completed a 100-metre sprint in 9.32 seconds, beating Usain Bolt's 9.58-second human world record. The feat occurred during preparations for the World Humanoid Robot Games in Beijing.

WIRED reports on Flock Safety's AI tools, OpenAI's safety overhaul, and vulnerabilities allowing 'zombified' expired Visa cards to be used for fraud. Additionally, Apple issued record spyware warnings, and Ukraine targeted Russian retailer Wildberries with cyber and drone attacks.

Ulanqab, Inner Mongolia, is rapidly becoming a major AI data center hub due to low energy costs and cold climate. While companies like DeepSeek and ByteDance invest heavily, the region faces significant water scarcity and ongoing reliance on coal power.

Award-winning Hollywood writers and directors are taking gig jobs paying $12 to $200 an hour to train AI models, seeking income amid a severe industry job slump despite concerns they are helping automate their own professions.

Experts in Silicon Valley warn of an imminent AI takeoff and existential risks, citing recursive self-improvement, autonomous agent breakouts, and a lack of global regulatory coordination amid US-China rivalry.