Volt Typhoon and the Weaponization of the Local Tap
A water system can fail without a reservoir running dry. A treatment plant can remain physically intact while the computers that monitor pumps, regulate chemicals, track pressure, or coordinate distribution become unreliable. For a city, that distinction may be invisible to residents. The tap either works, or it does not.
That possibility has made Volt Typhoon one of the most closely watched cyber threats facing the United States. The PRC state-sponsored group has compromised networks associated with communications, energy, transportation, and water and wastewater operations. U.S. agencies assess that Volt Typhoon has been positioning itself inside critical-infrastructure networks so that it could support disruptive or destructive operations during a future crisis, potentially involving the United States and China. (CISA, NSA, FBI et al., “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure,” February 7, 2024)
The danger is therefore less like a conventional data breach than a hidden reserve of access. The cited sources describe an intrusion that may produce no immediate public outage or ransom demand. Instead, an adversary can learn how a network works, obtain valid credentials, blend into ordinary administrative activity, and wait.
That is the logic behind the phrase “pre-positioning.” It describes access established before a conflict or major confrontation, when an attacker may want the ability to disrupt civilian systems quickly. Yet the public evidence also requires restraint. The available government advisories confirm compromises and persistent access across sectors, but they do not establish that Volt Typhoon has shut down thousands of American water utilities, planted malware in every plant, or currently controls municipal water supplies. The most serious claim supported by the evidence is narrower and more consequential: the group has demonstrated the ability to enter and remain inside networks that support critical services, and U.S. agencies believe that access could be used for disruption in a crisis.
From stealing secrets to shaping the battlefield
For much of the internet era, the public image of state-sponsored hacking centered on espionage. Governments stole military plans, diplomatic communications, industrial designs, and personal data. The damage could be severe, but it often remained abstract to the general public. A stolen database or compromised research program rarely changed what happened when a household turned on a faucet.
Volt Typhoon represents a different strategic concern. Microsoft identified the group in 2023 as a China-based state-sponsored actor targeting critical infrastructure in the United States, including organizations in communications, manufacturing, utilities, transportation, construction, maritime operations, government, information technology, and education. Microsoft assessed with moderate confidence that the campaign was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia during a future crisis. (Microsoft Security, “Volt Typhoon targets US critical infrastructure with living-off-the-land techniques,” May 24, 2023)
Microsoft also described the activity as involving espionage, information gathering, credential access, and efforts to maintain undetected access. The evidence therefore does not support a simple replacement of “espionage” with “disruption.” It supports a more complicated picture: the group collected information and credentials while developing access that U.S. officials believed could support disruptive operations.
The joint U.S. advisory issued by CISA, the National Security Agency, and the FBI in February 2024 went further. The agencies said they had confirmed Volt Typhoon compromises in multiple critical-infrastructure organizations, primarily in communications, energy, transportation systems, and water and wastewater systems, both in the continental United States and in U.S. territories including Guam. The agencies judged with high confidence that the group was positioning itself to move from information-technology networks toward operational-technology assets, the systems that monitor and control physical processes. (CISA, NSA, FBI et al., joint advisory)
That judgment does not mean every victim’s pumps were remotely controlled or every plant’s treatment process was altered. It means the observed choice of targets and the group’s behavior did not resemble ordinary intelligence collection. The agencies found the pattern consistent with preparing for possible disruption.
The distinction matters. Cyber espionage seeks information. A disruptive operation seeks leverage over a physical or social system. The target may be a control room, a network link, a scheduling system, or an administrator’s account. The desired effect could be a service outage, corrupted information, delayed repairs, confused operators, or a loss of confidence in the system. Physical damage is not always necessary. A city that cannot trust its own instruments may be forced to shut down equipment as a precaution.
The local tap as a strategic pressure point
Water systems are attractive targets for reasons that have little to do with their size. They provide essential services, and the government advisory identifies water and wastewater systems among the sectors affected by Volt Typhoon activity. Microsoft likewise reported targeting of utilities and other infrastructure organizations. A water utility may combine industrial equipment with administrative networks, remote-access tools, vendor connections, and internet-facing devices, although the sources provided here do not establish the specific configuration of every utility.
A water utility also has limited room for error. A disruption could affect public agencies, businesses, households, and other services that depend on reliable water and wastewater operations. The sources provided do not quantify those consequences for any particular utility, but they explain why U.S. agencies treat the sector as critical infrastructure.
The public record, however, does not support treating every local water utility as a confirmed Volt Typhoon victim. CISA’s advisory identifies water and wastewater systems among the sectors affected by the group’s activity, but it does not say that 5,000 utilities were compromised. The figure of 5,000 appears in a WIRED report describing a war-game scenario in which a Chinese cyberattack knocks out 5,000 U.S. water utilities at once. That number describes the scale of an exercise, not a verified count of real intrusions. (WIRED, “China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure: Is the US Ready?”)
This is more than a technical qualification. Inflating a scenario into an established fact obscures the actual problem. The threat does not require thousands of confirmed compromises to be serious. A smaller number of footholds in strategically important networks, combined with uncertainty about which systems are affected, could create a difficult national-security problem.
The strongest evidence supports three separate propositions:
- Volt Typhoon has compromised multiple U.S. critical-infrastructure organizations.
- Water and wastewater systems are among the sectors targeted or affected.
- U.S. agencies assess that the access may support future disruption, including movement toward operational technology.
The evidence does not establish that the group has already manipulated drinking-water chemistry, shut down a nationwide network of plants, or placed a controllable “digital bomb” inside every targeted facility.
Living off the land
Volt Typhoon’s most important advantage is its ability to make malicious activity resemble routine administration.
“Living off the land” refers to the use of legitimate tools already present in a system. Instead of installing a conspicuous malware package, an intruder may use command-line utilities, scripting tools, remote-management functions, credential stores, network-discovery commands, and other built-in capabilities. Those tools have legitimate purposes. Administrators use them to inspect systems, manage accounts, troubleshoot networks, and move files.
The problem for defenders is behavioral ambiguity. A security product may recognize a known malicious file, but a command issued through an authorized utility can look ordinary until its context is examined. Was the command run by the right account? From the right device? At the right time? Against the right system? Did the user normally perform that action?
Microsoft reported that Volt Typhoon relied almost exclusively on hands-on-keyboard activity and legitimate administrative functions after gaining access. The group collected credentials, discovered systems on the network, archived information for possible exfiltration, and used stolen credentials to maintain access. Microsoft also observed the group routing traffic through compromised small-office and home-office network equipment, including routers, firewalls, and virtual private network hardware. (Microsoft Security, 2023)
This method creates a defensive imbalance. The attacker needs only to make an unusual action appear routine. The defender must understand the normal behavior of users, devices, service accounts, vendors, and applications. For a utility with limited security staff, that level of monitoring may be difficult.

The group’s use of compromised edge devices also complicates attribution and detection. If traffic reaches a target through a home or small-business router that an attacker has taken over, the connection may not resemble traffic from a purpose-built criminal infrastructure. Microsoft said the technique reduced the group’s overhead and helped conceal its operations.
The tactic is not invisible by definition. Centralized logging, strong authentication, network segmentation, endpoint monitoring, and careful analysis of administrative behavior can expose it. But those defenses must exist, be configured correctly, and be monitored long enough to reveal a pattern. A utility that stores few logs or keeps them only on the compromised network may lose the evidence needed to reconstruct an intrusion.
Persistence measured in years
The word “persistence” can sound abstract until it is measured in time.
The February 2024 joint advisory said U.S. agencies had observed indications that Volt Typhoon actors maintained access and footholds in some victim environments for at least five years. The same advisory described extensive reconnaissance before exploitation, tailored tactics for individual victims, and continuing efforts to understand and preserve access after the initial compromise. (CISA, NSA, FBI et al., 2024 advisory)
A long dwell time changes the nature of an intrusion. A long-term foothold could give an operator time to map trust relationships, identify backup systems, learn maintenance schedules, observe vendor connections, and discover which credentials unlock more important parts of the network. The advisory does not say that every actor performed each of these actions in every victim environment, but the possibility explains why persistent access matters.
Persistence also creates a problem after detection. Changing one password or removing one device may not remove the adversary. The attacker may have created alternative access routes, compromised additional accounts, or learned enough about the environment to return through another weak point. Microsoft said compromised accounts must be closed or changed, while the CISA advisory urged organizations to hunt for similar malicious activity and investigate the wider environment.
The five-year figure should not be misread as a universal dwell time for every victim. It is an observation from some environments, not a claim that every compromise lasted five years. Nor does persistent access prove that an attacker continuously controlled operational equipment during that period. It shows that access to parts of a victim’s environment survived for a long time.
That is sufficient to undermine the assumption that an intrusion is over when the first malicious file disappears.
The path from IT to physical operations
Modern utilities often separate business information technology from operational technology, at least in design. IT networks support email, billing, records, identity management, and office work. OT networks operate or monitor pumps, valves, sensors, programmable logic controllers, and industrial processes.
The separation is rarely absolute. Operators need information from both environments. Vendors need remote access. Engineers move files. Shared credentials and administrative connections can create bridges. A foothold in IT does not automatically provide control of OT, but it may give an attacker a place from which to study the environment and search for a route across.
That is why the joint advisory emphasized “lateral movement to OT assets.” The agencies did not claim that every observed intrusion reached the final control layer. They assessed that the group’s targeting and behavior were consistent with preparing to do so.
The distinction between access and impact is central to understanding the threat. Cybersecurity reporting often compresses a long chain into a dramatic phrase: hackers enter a network, reach industrial systems, and shut down a service. In reality, each step may require different privileges, network paths, knowledge, and operational conditions. The ability to move from one step to the next must be investigated rather than assumed.
A disruptive operation could also exploit systems that are not direct process controllers. A billing platform, dispatch system, communications link, or monitoring dashboard could cause confusion or force manual procedures if it became unavailable or unreliable. The sources provided do not establish that Volt Typhoon has caused such an event in a water utility. They support treating these possibilities as operational concerns rather than documented outcomes.
In a crisis, uncertainty itself could become an operational burden.
Guam, Taiwan, and the timing problem
Volt Typhoon’s targeting has been interpreted within the wider security relationship between China and the United States, particularly the possibility of a confrontation over Taiwan.
Microsoft reported that Guam and other U.S. locations had been targeted. The 2024 U.S. intelligence assessment, as summarized by CyberScoop, described Volt Typhoon activity as likely intended to pre-position cyberattacks against infrastructure in Guam and enable disruption of communications between the United States and Asia. (Derek B. Johnson, CyberScoop, “FBI director warns of China’s preparations for disruptive infrastructure attacks,” April 19, 2024)
The sources identify Guam as a target of concern. They do not, in the material provided here, establish the specific role of any particular civilian facility there or document an actual disruption.
FBI Director Christopher Wray said in April 2024 that China was developing the ability to “physically wreak havoc” on U.S. critical infrastructure. He connected the warning to concerns about Beijing’s military planning and the possibility of a Taiwan crisis, while stressing that preparation for a future capability was occurring in the present. (Reuters, “What is Volt Typhoon, the Chinese hacking group the FBI warns could deal a ‘devastating blow’?” April 19, 2024; CyberScoop, April 19, 2024)
The 2027 date often appears in public discussion because U.S. officials have cited China’s goal of having military capabilities designed to deter or complicate U.S. intervention in a future cross-Strait crisis by that year. That date should not be treated as a scheduled invasion or a deadline for a cyberattack. It is a planning benchmark associated with military capability, not proof of a chosen political decision.
The same caution applies to motive. U.S. agencies attribute Volt Typhoon to the PRC and assess that its activity could enable disruption during a crisis. Public evidence supports that assessment. It does not reveal the full decision process inside the Chinese government, identify the precise circumstances in which access would be used, or prove that a particular intrusion was ordered for one specific future operation.
The hardest target may be institutional coordination
The technical challenge is only part of the problem. Water utilities are administered across many jurisdictions, and the sources provided describe a war-game scenario in which a Chinese cyberattack knocks out 5,000 U.S. water utilities at once. The exercise was designed to test what might happen during a large coordinated disruption, not to document an attack that has already occurred. (WIRED)
A scenario is not evidence that the same confusion has already occurred in a real Volt Typhoon attack. It does, however, pose a practical question. A cyber incident affecting several utilities at once would cross the boundaries between municipal government, state agencies, federal authorities, private vendors, law enforcement, intelligence organizations, and infrastructure operators. The systems may be connected, but responsibility is distributed.
That distribution creates a practical dilemma. Local operators know their equipment best, yet they may lack the staff to conduct a full forensic investigation. Federal agencies may possess broader threat intelligence, yet they do not operate each water plant. Vendors may control important equipment or remote-access channels, yet they may not see the full operational picture. A response could fail through delay even when each institution performs its narrow role competently.
The WIRED account describes the war game as producing disturbing conclusions about the country’s readiness. The source material provided here does not establish that a real Volt Typhoon incident has already produced the same conditions.
The threat therefore exposes a possible old weakness in a new form: essential services can be nationally consequential while remaining locally defended.
What the evidence says, and what it does not

Volt Typhoon has generated alarming descriptions, including comparisons to explosives placed inside civilian infrastructure. Such metaphors communicate the potential consequences of dormant access, but they can also blur the line between preparation and completed sabotage.
The evidence presently supports the following conclusions:
- U.S. agencies and allies have identified Volt Typhoon as a PRC state-sponsored cyber actor.
- The group has compromised multiple organizations associated with U.S. critical infrastructure.
- Water and wastewater systems are among the sectors identified in government warnings.
- The group has used legitimate tools, valid accounts, command-line activity, and compromised network devices to conceal operations.
- U.S. agencies have observed persistent access in some victim environments lasting at least five years.
- The agencies assess with high confidence that the activity is consistent with pre-positioning for possible disruption, including movement toward operational technology.
Several claims remain unproven or require narrower wording:
- There is no public evidence in the cited government advisory that Volt Typhoon compromised 5,000 water utilities.
- The 5,000-utility figure describes a war-game scenario reported by WIRED, not a confirmed tally of intrusions.
- Public sources cited here do not establish that Volt Typhoon has already altered drinking-water chemistry or caused a nationwide water outage.
- Access to an IT environment does not by itself prove control of pumps, valves, treatment systems, or other OT equipment.
- The existence of pre-positioned access does not prove that China has decided to activate it, or that activation would produce the exact consequences described in a scenario.
- The provided sources do not establish that the United States currently lacks a unified federal command structure for responding to such an attack. The war-game reporting raises readiness and coordination concerns, but those concerns should not be presented as findings from a completed real-world incident.
These distinctions do not make the threat less serious. They make it more intelligible. A credible warning does not need to include every worst-case outcome as an accomplished fact.
Defending the ordinary infrastructure
The government’s immediate recommendations are straightforward, even if difficult to execute across many organizations. CISA, NSA, and the FBI urged critical-infrastructure operators to patch internet-facing systems, prioritize vulnerabilities in appliances frequently exploited by Volt Typhoon, implement phishing-resistant multifactor authentication, and enable application, access, and security logging with centralized storage. (CISA, NSA, FBI et al., 2024 advisory)
Microsoft’s guidance adds several practical priorities: remove public exposure from management interfaces on network-edge devices, close or change compromised accounts, monitor legitimate administrative tools for unusual use, and investigate credential theft and lateral movement. (Microsoft Security, 2023)
For water utilities, defense also means understanding the physical process. Network monitoring cannot substitute for knowing which accounts can change chemical dosing, which systems can stop a pump, which vendor connections remain active, and which manual procedures can keep a plant safe if digital controls become unreliable. These are defensive planning questions, not documented findings about every utility or every Volt Typhoon victim. Segmentation is meaningful only when it reflects real operational pathways. A network diagram that omits a contractor’s remote-access tunnel is not a defense plan.
The most valuable improvement may be the least dramatic: making it difficult for an attacker to remain unnoticed. Strong authentication, accurate asset inventories, centralized logs, restricted administrative privileges, protected backups, tested incident procedures, and regular review of remote access can reduce the number of places where a dormant operator can hide.
The tap and the warning
The “local tap” is a useful symbol because it connects global rivalry to an ordinary act. A contest between major powers can appear to concern satellites, ships, advanced weapons, or classified networks. Volt Typhoon’s alleged targets point downward, into the municipal systems that residents rarely think about until they fail.
But the most responsible account is not that Chinese hackers have already placed digital explosives in every American water plant. It is that a PRC state-sponsored actor has, in some cases, maintained access to networks that support civilian and strategic infrastructure for years, using methods designed to avoid notice. U.S. agencies believe that access could be used to disrupt physical services during a major crisis.
The danger lies in the time between intrusion and consequence. A system may look normal while an adversary studies it. A utility may continue serving water while its network records an attacker’s presence. The absence of an outage does not prove the absence of preparation.
The strategic question is therefore not whether every tap is already under foreign control. The question is whether the United States can detect, remove, and prevent hidden access before a geopolitical crisis turns dormant capability into public disruption. The answer will depend less on a single security product than on whether local utilities, private vendors, and federal agencies can see the same threat, share evidence quickly, and maintain control of the systems that keep daily life running.
Sources/References
- Cybersecurity and Infrastructure Security Agency, National Security Agency, Federal Bureau of Investigation, U.S. Department of Energy, U.S. Environmental Protection Agency, U.S. Transportation Security Administration, Australian Signals Directorate’s Australian Cyber Security Centre, Canadian Centre for Cyber Security, United Kingdom National Cyber Security Centre, and New Zealand National Cyber Security Centre. “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure.” Product ID AA24-038A, February 7, 2024.
https://s3.documentcloud.org/documents/24412395/aa24-038a-csa-prc-state-sponsored-actors-compromise-us-critical-infrastructure.pdf
- Microsoft Security. “Volt Typhoon Targets US Critical Infrastructure with Living-off-the-Land Techniques.” May 24, 2023.
https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- Johnson, Derek B. “FBI Director Warns of China’s Preparations for Disruptive Infrastructure Attacks.” CyberScoop, April 19, 2024.
https://cyberscoop.com/fbi-warns-china-preparing-for-disruptive-attacks/
- Reuters. “What Is Volt Typhoon, the Chinese Hacking Group the FBI Warns Could Deal a ‘Devastating Blow’?” April 19, 2024.
https://www.reuters.com/technology/what-is-volt-typhoon-alleged-china-backed-hacking-group-2023-05-25/
- Greenberg, Andy. “China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure: Is the US Ready?” WIRED.
https://www.wired.com/story/china-is-strapping-digital-bombs-to-civilian-infrastructure-is-the-us-ready/
Appendix: Live Web Sources Retrieved for This Paper
The following 7 sources were retrieved from the live web during generation and provided to the model as grounding material:
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
- China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready? | WIRED
- Volt Typhoon targets US critical infrastructure with living-off-the-land techniques | Microsoft Security Blog
- Chinese hackers spent three years planting 'digital bombs' inside 5,000 US water utilities—and nobody has a plan
- FBI director warns of China’s preparations for disruptive infrastructure attacks | CyberScoop
- What is Volt Typhoon, the Chinese hacking group the FBI warns could deal a 'devastating blow'? | Reuters
- Explainer: what is Volt Typhoon and why is it the ‘defining threat of our generation’? | Hacking | The Guardian
Continue exploring
The Uninsurable Housing Trap
For decades, homebuyers have been taught to judge affordability by three numbers: the purchase price, the mortgage rate, and the…
The Kidnappers Outsmart Nigeria’s Surveillance State
Nigeria has more tools to track kidnappers than ever, but fragmented data systems and slow institutional response leave criminal…
Can the DSRB Get Startup Tech to the Battlefield Faster Than the MoD?
Nineteen governments have chartered a defence bank to finance rearmament, but the evidence says its power to rush startup weapons…
Comments
No comments yet. Start the conversation below.