Earlier this year, insurance executives gathered in a Times Square conference room to play out a scenario: a Chinese cyberattack knocks out 5,000 US water utilities at once. If you think that’s a far-fetched scenario, think again. WIRED’s Andy Greenberg got rare access to the closed-door war game and walked away with some disturbing conclusions. This week, Brian Barrett sits down to talk with Andy about Volt Typhoon, the Chinese state-sponsored hacking group that’s spent the past three years pre-positioning itself inside American infrastructure.
Article mentioned in this episode:
You can follow Brian Barrett on Bluesky at @brbarrett and Andy Greenberg on Bluesky at @agreenberg. Write to us at [email protected].
How to Listen
You can always listen to this week's podcast through the audio player on this page, but if you want to subscribe for free to get every episode, here's how:
If you're on an iPhone or iPad, open the app called Podcasts, or just tap this link. You can also download an app like Overcast or Pocket Casts and search for “uncanny valley.” We’re on Spotify too.
Transcript
Note: This is an automated transcript, which may contain errors.
Brian Barrett: This is WIRED's Uncanny Valley. I'm Brian Barrett, executive editor. We're on a short break from our usual roundtable for the rest of August. Everybody needs some time off sometimes. But we prepared two special conversations for you. This week, we're diving into something alarming that hasn't happened yet, but could. Earlier this year, about 30 insurance executives stepped into a conference room high above Times Square in Manhattan to simulate what would happen if a group of hackers from China attacked the US water supply. Specifically, the idea was to simulate a Chinese cyberattack that would knock out 5,000 water utilities in the US all at once and to do it under a countdown clock. WIRED senior correspondent Andy Greenberg got a rare invite to this closed door war game, call it Dungeons & Dragons for a national security nightmare. It was designed by a former cybersecurity strategist to test what would happen if and when hackers linked to an infamous Chinese operation called Volt Typhoon finally decide to follow through on groundwork that they've been laying for three years.
Archival audio: This group that's known as Volt Typhoon, this is a state-sponsored Chinese hacking group.
Archival audio: China has secretly stepped up its electronic warfare, deploying what is being called the Volt Typhoon malware throughout the US ecosystem.
Brian Barrett: The result could include burst water mains, evacuated hospitals, insulin shortages. Andy's here to tell us more about what he saw and heard, and why the scariest part might not quite be the hack itself, but what it revealed about who's actually in charge when the water stops. Andy, thanks so much for being here.
Andy Greenberg: Glad to do it, Brian.
Brian Barrett: Before we get any deeper into the game itself, could you tell us what Volt Typhoon is and how worried people should be in general about this group?
Andy Greenberg: Well, Volt Typhoon is a hacker group that I think represents some of the worst nightmares of the cybersecurity community and the US government, those who have to plan for catastrophic national security scenarios. This is a Chinese state-sponsored hacker group that does not, like most Chinese state hackers, focus on espionage, but rather has been, it appears, for the last three years, planting malware inside of US critical infrastructure, prepositioning, as people put it, sort of laying the groundwork for the ability to disrupt these systems, to turn off the power, to cause blackouts, to disrupt telecommunications, and as I delved into in this story, potentially to affect the water supply. When Volt Typhoon first came to light in 2023, it's been three years now, the headlines said that they were targeting electric grids and telecommunication networks in the continental US and in Guam specifically. It seemed like they were probably targeting US military facilities and the surrounding infrastructure. We were kind of trying to figure out their motives for this, and the theory that I think all of us have been working under is that perhaps China is laying the groundwork, preparing for an invasion of Taiwan perhaps, and they want to be able to disrupt these US military facilities to delay a US response to an invasion of Taiwan. But then, it began to become clear that they were actually breaking into US electric and water utilities and other civilian critical infrastructure, not just military, but US civilian infrastructure across the whole US, including, it seems, towns as small as Littleton, Massachusetts. I spoke, in fact, to the chief information security officer of the water and electric utility in Littleton who just had no idea why Chinese hackers would be targeting his town of 10,000 people. But what that suggests is that China is trying to gain the ability not just to disrupt the US military, but to actually cause widespread societal chaos in the US as another perhaps diversionary distraction tactic maybe in the midst of this crisis when they invade Taiwan. This is all just a theory, but the pieces are there. The fact is that China really is breaking into US civilian critical infrastructure. And I don't want to sound overdramatic here, but laying what Rob Joyce, the former NSA director of cybersecurity, describes as digital bombs strapped to our infrastructure.
Brian Barrett: It's a theory that's at the heart of this war game exercise that you went to. The theory is, what if they do pull the trigger on this? How do people react? Do you mind setting the scene, even just how you got there in the first place? Because this is not the kind of thing that people are normally invited to. You normally don't get a look into something like this. So how'd you get invited? Who's there?
Andy Greenberg: I have been trying to find a way into this story about Volt Typhoon for years because I feel like this actually is one of the most important things happening in cybersecurity today. It's gone under the radar in part because China has this incredible restraint that they've never actually pulled the trigger and caused a disruptive cyberattack. So I was talking a lot to Joshua Corman about this. Joshua is a former strategist for CISA, the Cybersecurity and Infrastructure Security Agency. So he mentioned to me that he runs these war games, actually dozens of them, for different groups. He invited me to one in particular that he was doing with insurance executives. I thought this sounded like maybe the most boring approach to this very dramatic cyberwar story, but Josh explained, and I have now persuaded that insurance plays such an important role in the response to an event like this. It turns out that when a company gets hacked or hit with a cyberattack like this, their first call is very often to their insurance agency who then are the ones who unlock the lawyers and the cybersecurity incident responders, who they have already pre-approved and are now willing to pay for. So cyber insurance actually controls, on this kind of surprising level, our whole national response to an event like this. They are the first call. They want to actually know exactly what is going to happen because they are the ones who will be financially on the hook. And that, to me, sounded actually like a kind of counterintuitively very interesting perspective.
Brian Barrett: It makes sense. I mean, when you think about who knows the most about recovery from a hurricane, it's probably Allstate and State Farm. It's home insurers who are there for every step of the process. When you think about these large scale disasters, which is what we're describing here, a large-scale cybersecurity disaster, that's the equivalent, right? It's the equivalent of the Allstates or the State Farms.
Andy Greenberg: Absolutely. The fact is they were doing this internally for their own benefits. In fact, I was kind of sworn to secrecy in a sense I'm not allowed to identify anybody in the room. They didn't want this to be public. So I felt like this is maybe the closest thing to ground truth of an estimate of what this would be like that I was going to be able to find.
Brian Barrett: So you're in the conference room near Times Square, you've got a bunch of the executives. What is the scenario that they're playing? And what were your sort of first impressions as the exercise began?
Andy Greenberg: So Joshua, he gives us some ground rules first, like don't fight the scenario, which is, Brian, you understand that as a former improv comedian.
Brian Barrett: Yes and. Yes and your way through the apocalypse.
Andy Greenberg: Yes, that's true of Dungeons & Dragons, and it's true of cybersecurity role-playing as well. So it turns out that his scenario was that 5,000 water utilities across the US appear to have been hacked and disrupted. And in some cases, the hackers have even caused physical destruction of equipment, like change the water pressure to the degree that water mains have burst. Nobody knows who has done this, nobody knows exactly what the effects have been, but everybody downstream of these water utilities has lost water. All of this is unfolding in July of 2027, just a year from now. And Josh, he did read us a New York Times headline from that morning that he invented, which was something like, "As the United States prepares to celebrate its independence, Taiwan fears for its own." Meaning tension is building between China and Taiwan, and that was laying the groundwork for this notion that that's when this kind of catastrophic cyberattack might come. So after laying out this day one scenario, 5,000 water utilities hacked, these groups of insurance executives who were actually set up at tables role-playing are told, "You have just received a kind of restricted memo from the US government." The two questions that Josh initially put to them, their kind of first assignment in the game, is to decide who are they going to tell about this? Do they tell all of their customers? Do they tell just the ones that they think have been affected? Do they say nothing and wait for their customers who are affected to come to them? And then probably the more important of these two questions, when they do start to get claims from affected water utilities, who are their customers? How do they prioritize who to dole out resources to? Because it's already going to start to become clear that there is real resource scarcity here.
Brian Barrett: Then Joshua, who's acting as the guide for this exercise, starts making things gradually worse and worse, right?
Andy Greenberg: As soon as he's given them this assignment, he's wandering around the room and comes over to our table, and he says, "OK, actually, you all don't get any incident responders. The main companies that do kind of infrastructure security like Dragos and CrowdStrike and Mandiant, they're completely at capacity already. So sorry, you don't get any incident responders. You have to figure out how to deal with this on your own."
Brian Barrett: What do you think Josh was going for in that moment?
Andy Greenberg: Josh told me before it began actually that his entire goal with this was to, as he says, surface and shatter assumptions. He wants to shock people out of complacency about thinking that they might know how this is going to unfold and know how to deal with it. I think 5,000 water utilities is enough that that makes sense. I think that there are not enough incident responders in the country for all of those victims to get professionals in the room looking at their network. So the insurance companies, they're going to have to figure out like, who do they prioritize? That was really the question that Josh was posing to them. In fact, my table was already trying to brainstorm about, "Well, maybe we can get people from academia to help. Maybe we can beg for help from the US government. Maybe we can get a national guard to help us." I mean, it was kind of a desperate situation from the very beginning. What the table I was sitting at came up with was, "Let's just say the biggest customers first." And Josh was like, "Well, biggest by what metric?" And the kind of spokesperson for the table just off the cuff was like, "Well, biggest by revenue." And that I think was just their kind of knee-jerk insurance industry answer. It turned out to be, I think, a very unfortunately naive and probably quite disastrous response.
Brian Barrett: Coming up after the break, we'll get into why there are no simple decisions when dealing with a national cybersecurity emergency. So, tell me why. I mean, other than that it sort of feels callous, what's the rationale? What are the repercussions of prioritizing revenue when you're dealing with a cybersecurity emergency like Volt Typhoon could cause?
Andy Greenberg: Well, that started to become clear on day two of the game. On day two was when it started to hit the fan, so to speak, things got very real and disturbing. So Josh kind of announces, "OK, 24 hours have passed. Now the second order effects of all of those water utility outages and destructions and burst water means is starting to become clear." Data centers can't get water, can't cool their computers. All kinds of cloud services are going down. Manufacturing is extremely water-dependent, drug manufacturing especially, so there's a shortage of insulin. Even electrical generation, most of it requires water in some form. But maybe the most critical of all of these things is that hospitals definitely need water, their HVAC systems in particular. So thousands of hospitals across the US are facing HVAC outages and may have to be evacuated in the hottest parts of the country. OK, now Josh is asking this same question again for round two. How do you prioritize your response now? He kind of upped the pressure by introducing different figures in the story who are making different demands of the insurance companies. The public in the media are asking like, what are insurance companies doing to protect human life in this scenario? Treasury is asking them to focus on economic concerns. And then the US military is actually asking them to focus on protecting US military infrastructure. So now the stakes have kind of become clear and the insurance companies have a sense of like, well, which of these things do we value? Human life, the economy, or US national security and military priorities?
Brian Barrett: It's a remarkable moment in the story, I thought, because almost everyone in that room says saving human lives are the priority, but not everyone. One person pushes back pretty hard.
Andy Greenberg: Yeah. I mean, I think the easy answer in a role-playing game especially is to say, "Well, of course, we'll protect human life. We'll prioritize that." But there was just one person at one table who brought up this very uncomfortable arguments that we all want to say we're going to protect human life, but we have contracts with customers. We have US government officials telling us to focus on other things. I just don't know if we'll really be able to focus on human life. Also, it started to become clear quite quickly that simply saying we're going to protect human life is not a simple answer. Which towns do you try to protect then? Do you go for the most hospital dense ones? Do you go for protecting the ones that are in the hottest climate? How do you figure out where the most life-threatening cyberattack, second order effects are actually happening? It's just an incredibly complex answer and one that the insurance companies really did not actually seem prepared to figure out.
Brian Barrett: I wonder about another question and whether they were prepared to think it out. Did it ever come up the idea of potentially refusing to pay out claims at all?
Andy Greenberg: Josh talked to me about that before and after, that he was kind of trying in part to test whether these insurance companies would claim this exclusion as you're getting at. So insurance policies, cyber insurance policies do not pay out for cyberattacks that are considered an act of war. They have this exception in them. And that became a huge legal argument after the NotPetya cyberattack, the biggest cyberattack in history in 2017.
Archival audio: The cyber weapon NotPetya started in Ukraine in June of 2017. It quickly spread paralyzing major companies and causing more than $10 billion in damage.
Andy Greenberg: A lot of victims lost more than a billion dollars. This was an act of war, but they wanted to claim that it wasn't because they wanted their insurance companies to cover those losses. So Josh wanted to probe whether that would come up here too. But it didn't actually, because we were still too much in the fog of war to know whether this was a war, to know who the adversary was. But in the discussion I had with Josh and other of these insurance company executives afterwards, it became clear that, I think this is maybe the biggest takeaway of the entire game, and it was not sort of spoken out loud in the room, that this event was uninsurable. The insurance companies as a whole did not have the capacity, the money to fund a response to this big cyberattack. There's almost no doubt that they would have to try to find exceptions or go bankrupt to paying out. They would definitely be looking for act of war exclusions. Some of them brought up to me this terrorism fund called TRIA, where essentially the government kind of runs this fund to help backstop insurance companies for after a terrorist attack. And they were arguing, "We need something like that for cyberattacks too, because we cannot actually afford this," which to me is maybe the most disturbing takeaway from the entire story.
Brian Barrett: Because if they can't, then no one can.
Andy Greenberg: Right. I mean, who is going to pay for this? The US government, I suppose, could. The US government can kind of afford anything depending on how much national debt we're willing to rack up. But the insurance companies alone, who we do depend on by default, weren't ready for this.
Brian Barrett: Coming away from this, how did it change how you feel about Volt Typhoon? Not just the response, but the situation that the US is in right now and is still in. I think it's important to note that nothing has much changed. We know that Volt Typhoon is in these systems. They're still there in many cases. This is an ongoing concern. How did this exercise make you rethink, if at all, what you have already described as the biggest threat to the US and the biggest issue of cybersecurity today?
Andy Greenberg: Well, it's one of those situations where you get really obsessed with. I have gotten obsessed with Volt Typhoon at times and thought this is the biggest threat we face from any hacker group in the world. But then nothing happens and it kind of falls off everyone's radar. And you start to tell yourself, "Well, maybe I was just completely wrong about that, and maybe that was all hype, or that was just a weird nightmare I had." But then following this exercise, I did go back to sources who are doing incident response, who are dealing with these intrusions by Volt Typhoon to check like, are you seeing this continuing? Is this still happening? The answer is unequivocally yes. Volt Typhoon, or perhaps some hacker group that they have evolved into, is still out there breaking into networks under the radar, going undetected in many cases, getting detected in some cases and evicted, but probably in just a fraction of all of the intrusions that they do. And they are still laying the groundwork for this very large, very disruptive, extremely expensive cyberattack of the future.
Brian Barrett: Andy, thank you so much for joining us today.
Andy Greenberg: Happy to talk about it.
Zoë Schiffer: That's our show for today. We'll link all the stories we spoke about in the show notes. Adriana Tapia produced this episode. It was mixed by Pran Bandi, who's also our New York studio engineer. It was fact-checked by Matt Giles and Daniel Roman. Kate Osborn is our executive producer, and Katie Drummond is WIRED's global editorial director.