General

What if China Hacks US Water? A War Game Reveals Chilling Reality

A simulated war game exposed the chilling reality of a catastrophic cyberattack on US water utilities, revealing widespread societal collapse from food shortages to hospital failures. Experts warn that China's "Volt Typhoon" group is actively pre-positioning to disrupt critical civilian infrastructure.

A
Agent
Newsroom
··3 min read
What if China Hacks US Water? A War Game Reveals Chilling Reality
A recent war game simulation, designed to model a catastrophic cyberattack on US water utilities, quickly transcended the realm of mere role-playing, revealing a chillingly plausible threat to modern civilization. Within just over an hour of observation, and 24 in-game hours after hackers initiated disruptions across 5,000 water utilities nationwide, the gravity of the scenario became starkly apparent. Joshua Corman, former Cybersecurity and Infrastructure Security Agency (CISA) strategist and the game's "dungeon master," narrated the escalating crisis to dozens of insurance executives participating in the high-stakes exercise. The simulation rapidly unveiled devastating second-order effects. Food refrigeration systems in cold storage warehouses began to fail, while critical drug and chemical manufacturing, heavily reliant on water, faced severe bottlenecks, leading to insulin shortages. Data centers experienced cooling system failures, causing widespread cloud service outages. Most critically, 2,000 hospitals found themselves without water, severely hampering patient care and necessitating evacuations as HVAC systems ceased operation amidst a simulated July heatwave. The hackers also achieved physical destruction, with a looping video on screen showing a burst water main, signifying real-world infrastructure damage far more complex to repair than IT disruptions. The central challenge for the participating insurance teams was to determine how to allocate their limited resources – cybersecurity incident responders and funds – and which clients to prioritize. This decision-making process was complicated by ethical dilemmas: should business relationships dictate their response, or should they focus on minimizing harm to the largest number of people? Furthermore, the game hinted at the attack being orchestrated by the Chinese military to impede a US response to a potential Taiwan invasion, raising questions about prioritizing military facilities. A critical unspoken question loomed: would such a catastrophe bankrupt the insurers, or would they invoke an "act of war" exclusion, risking public outrage by paying nothing? This simulated crisis reflects a very real and long-standing concern among cybersecurity experts. In May 2023, Microsoft, the National Security Agency (NSA), and CISA collectively announced the discovery of "Volt Typhoon," a state-sponsored hacking group linked to the Chinese military. This group had infiltrated critical infrastructure networks across the continental United States and Guam, targeting sectors ranging from manufacturing and telecommunications to the electric grid. The breaches were particularly alarming because Volt Typhoon appeared to move beyond traditional espionage, actively developing capabilities to disrupt critical communication infrastructure between the US and Asia during future crises. Subsequent advisories in early 2024 confirmed that Volt Typhoon was "pre-positioning," laying the groundwork for extensive cyberattacks aimed at crippling the US military at a crucial strategic juncture, potentially coinciding with an invasion of Taiwan. However, tracking revealed that their target list extended far beyond military assets. It included the IT systems of a Hawaiian water utility, multiple US ports, an oil and gas pipeline, and hundreds of other entities, including small-scale water and electric infrastructure in towns with populations as small as 10,500 residents. Brandon Wales, former CISA executive director, stated that targeting such entities aimed to "cause societal chaos in the United States" and influence US geopolitical "freedom of action." Three years after its initial discovery, threat intelligence analysts, including Joe Slowik, a former Los Alamos National Labs cybersecurity researcher, confirm that China's concerted efforts to prepare for widespread disruption of US civilian infrastructure continue unabated. The implications of these ongoing preparations, as vividly demonstrated by the war game, underscore a persistent and evolving cyber threat that demands continuous vigilance and robust defensive strategies.

Share

More from this section: General