Earlier this year, in a conference room high above the neon chaos of Times Square, a group of about thirty insurance executives gathered not to debate premiums or underwriting models, but to confront a nightmare they had spent much of their careers trying to price, predict, and politely ignore. The scenario was simple and horrifying: Chinese state-sponsored hackers had, in a single coordinated attack, knocked out five thousand water utilities across the United States. A countdown clock ticked at the front of the room, and the executives had to respond as the consequences cascaded outward: streets turned into rivers from burst water mains, hospitals began to evacuate, doctors ran out of insulin, and emergency hotlines overflowed with panicked callers. This was not a real attack, but an elaborate, closed-door war game designed by a former cybersecurity strategist to test what would happen if a group known as Volt Typhoon finally decided to detonate years of hidden work inside American infrastructure. WIRED senior correspondent Andy Greenberg received a rare invitation to observe the exercise, and later sat down with executive editor Brian Barrett for the Uncanny Valley podcast to describe what he saw. The experience left him with a deeply unsettling conclusion: the hack itself is frightening, but even more frightening is how little anyone actually knows about who would take charge, how decisions would be made, or whether the water would ever come back on.
To understand why those insurance executives were so anxious, you have to understand Volt Typhoon. It is a Chinese state-sponsored hacking group that, for the past three years, has been doing something that sets it apart from almost every other Chinese cyber operation. Most state hackers are spies. They steal secrets, map networks, and quietly leave. Volt Typhoon, according to the US government and cybersecurity researchers, appears to be doing something more ominous. It has been breaking into American critical infrastructure and planting malware with the patience of someone laying railroad track for a bomb. These intrusions have targeted electric grids, telecommunications networks, and, increasingly, water and wastewater systems. When the group first came to light in 2023, the initial headlines focused on military bases and the island of Guam, which led many to believe that China was positioning itself to disrupt American military operations in the event of a conflict over Taiwan. But then the picture widened. Volt Typhoon was found inside civilian utilities in small towns across the United States, including Littleton, Massachusetts, a community of just ten thousand people. The town’s chief information security officer told Andy Greenberg that he had no idea why Chinese hackers would want to break into a system serving so few residents. The answer, researchers suspect, is that China is not aiming at one target. It is trying to build an ability to cause widespread societal chaos, to turn off power and water in places large and small, and to create so much confusion and pain that the United States would be unable to act decisively in a crisis. As former NSA cybersecurity director Rob Joyce put it, this is like having digital bombs strapped to American infrastructure, waiting for the order to detonate.
During the war game, the precise horror of that idea became visceral. The insurance executives in that Times Square room were not cybersecurity specialists, and that was exactly the point. They were people who model risk for a living, who calculate the likelihood of floods, fires, and financial collapses. But when the water stopped flowing in this simulation, they found themselves in a fog. No one knew which agency had the authority to tell utilities to shut down or bypass compromised systems. No one knew whether to trust the federal government, state governments, or private companies. No one knew whether calling in the National Guard would help or make things worse. The scenario called for hospitals to be evacuated, and the executives had to decide whether those evacuations were even possible when roads were breaking apart and emergency vehicles couldn’t get the water they needed. Insulin shortages were particularly terrifying because they turned an abstract attack on infrastructure into a direct threat to people with diabetes waiting in hospital beds. At the heart of the exercise was a question that sounds simple but has no obvious answer: if five thousand water utilities fail all at once, who is actually in charge? Is it the federal government? The states? The private companies that own most of America’s water systems? The insurance industry itself? In room after room, the participants discovered that the systems we rely on for resilience are as fragmented as the infrastructure they are meant to protect. The game was designed to stress test a response, but what it really exposed was the absence of a response at all.
Part of the reason the war game felt so difficult, Andy Greenberg explains, is that Volt Typhoon has not actually destroyed anything yet. It has been prepositioning inside American networks, burrowing into systems, maintaining access, and building a capacity for sabotage that can be triggered at a moment’s notice. This is a strategy that military planners sometimes call “left of boom,” meaning the attack has already effectively happened even if the violence has not begun. The malware is already in place. The backdoors are already open. The question is not whether China could turn off the water in five thousand places at once, but why it hasn’t yet, and what would make it decide to do so. That uncertainty is perhaps the most mentally corrosive part of the threat. The insurance executives in the room had no way of knowing how widespread the compromise was, because no one truly knows. Hackers have been observed moving laterally through networks, stealing credentials, and burying their presence inside systems that may remain untouched for years. When the attack finally comes, it may not be a single event but a wave of coordinated failures, water systems in Massachusetts going dark at the same moment as utilities in Texas and California, each one compounding the chaos of the others. The war game simulated that wave, but even a simulation cannot fully capture the emotional reality of watching a hospital run out of water or a town go dark with no way to know whether the engineers on the other end are even still able to respond.
The most disturbing takeaway from Andy Greenberg’s reporting is that the United States is not starting from zero in its response to Volt Typhoon, but it is dangerously close to it. The federal government has issued warnings, alerts, and advisories. The Cybersecurity and Infrastructure Security Agency has identified Volt Typhoon and tracked its activity. Utilities have been encouraged to harden their defenses, and some have made real progress. But the war game made clear that the gap between detecting a threat and actually responding to it is enormous. Even among the insurance executives, people who think about catastrophic scenarios all the time, there was confusion about what they could do to help. Insurance companies have a powerful ability to shape behavior: they can raise premiums for utilities with weak security, demand audits, and force organizations to invest in protection. But in the room, many participants realized that they had never seriously considered a scenario this broad, this coordinated, or this malicious. They had plans for hurricanes and earthquakes and even cyberattacks against individual companies, but not for an attack that would strike at the very systems that make civilization possible all at once. The game also revealed that private companies are often reluctant to admit they have been breached, fearful of liability and reputational damage, which means the true scope of Volt Typhoon may be far greater than what has been publicly disclosed. Until that hesitation is overcome, preparers will be working with a map that has enormous blank spaces.
None of this means that the scenario is inevitable. War games are meant to evoke worst-case thinking so that the worst case can be prevented, and the mood in that Times Square conference room was not despair. It was something more useful: a growing awareness that the American infrastructure was never designed to defend against a patient, state-sponsored adversary with the ability to hide for years inside critical systems. The answer is not panic, but it is also not business as usual. It means investing in cybersecurity at the local level, not just at federal agencies or giant tech companies. It means treating water utilities, electric cooperatives, and small municipal networks as national security assets, not left-behind pieces of forgotten infrastructure. It means building playbooks for coordination before the attack happens, so that the first time government officials, utility executives, and insurance companies meet is not in the middle of a national emergency. It means accepting that China has already crossed the threshold that was once considered unthinkable. The digital bombs are strapped in place. Whether they are ever detonated depends on many factors far beyond the control of any single town or utility or boardroom, but how the country prepares in the months and years ahead will determine whether it can absorb a blow like the one simulated above Times Square. The water in your tap and the lights in your home may feel ordinary, but they are now part of a greater contest. The war game was only a simulation, but the warning it carried was real, and the clock is still ticking.