China Strapping Digital Bombs to Infrastructure: War Game
A war game simulates a Chinese cyberattack on 5,000 US water utilities, revealing scary gaps in insurance-led response.
China Strapping Digital Bombs to Infrastructure: War Game
The threat is no longer theoretical. China is strapping digital bombs to civilian infrastructure, and that's the premise of a closed-door war game held earlier this year where insurance executives gathered in a Times Square conference room to simulate a coordinated cyberattack knocking out 5,000 US water utilities at once. The scenario, set in July 2027, was designed by Joshua Corman, a former strategist for the Cybersecurity and Infrastructure Security Agency. Andy Greenberg, a WIRED senior correspondent, got rare access to the exercise. What he witnessed paints a grim picture. The nation might be woefully unprepared, and that's the takeaway that should keep you up at night. So don't expect a quick fix anytime soon.
The game centers on Volt Typhoon, a Chinese state-sponsored hacking group. They've spent three years planting malware inside US critical infrastructure. But unlike most Chinese hackers who focus on espionage, this group appears to be pre-positioning for disruption, not theft. They're not stealing secrets. They're laying the groundwork to turn off power, disrupt telecommunications, and potentially poison the water supply. So Rob Joyce, the former NSA director of cybersecurity, describes this as China strapping digital bombs to our infrastructure, and that's a chilling way to frame it. It's a warning we can't ignore.
When Volt Typhoon first came to light in 2023, headlines focused on electric grids and telecommunication networks in the continental US and Guam, and the initial theory was that China was preparing for a potential invasion of Taiwan and wanted to delay a US military response. But then the picture shifted. The hackers were breaking into US electric and water utilities in civilian towns, some as small as Littleton, Massachusetts, a town of 10,000 people. It's a tiny place. The chief information security officer of Littleton’s water and electric utility told Greenberg he had no idea why Chinese hackers would target his town, so he just shrugged and kept patching systems.
Who Answers When the Water Stops?
The war game was designed to answer a chilling question: what happens if China actually pulls the trigger? Corman's goal, as he put it, was to "surface and shatter assumptions." He wanted to shock people out of complacency. So the first assignment for the insurance executives was brutally simple: decide who they'd tell about the attack, and then figure out how to prioritize which water utilities to help first, knowing that every choice meant another community went without. Resource scarcity was an immediate problem. It only got worse.
The exercise churned on. Then Corman wandered over to Greenberg's table and delivered a devastating blow: "OK, actually, you all don't get any incident responders." The main companies that do kind of infrastructure security like Dragos and CrowdStrike and Mandiant, they're completely at capacity already, so the insurance companies were on their own, forced to figure out who to save with limited resources. But the simulation made it clear that there aren't enough cybersecurity professionals in the country to handle 5,000 simultaneous victims. It's a brutal math problem.
Greenberg's table initially suggested prioritizing the biggest customers first. But when Corman asked "biggest by what metric?" the spokesperson off the cuff said, "biggest by revenue." A knee-jerk insurance industry answer. Greenberg noted it was likely a naive and disastrous response, one that would ripple through the game's logic and expose a fundamental misunderstanding of the challenge they'd just begun. The consequences became clear on day two. So it's safe to say they'd made a mess of things from the start.
Day Two: The Second-Order Effects Hit
Twenty-four hours in, things got real. The second-order effects of the water utility outages started cascading, and that's when the whole system began to buckle under its own weight, a slow groan that turned into a sharp crack. Data centers couldn’t cool their computers, taking down cloud services. Manufacturing, especially drug manufacturing, is heavily water-dependent, leading to an insulin shortage. Hospitals faced HVAC outages and potential evacuations in the hottest parts of the country. But even electrical generation requires water in some form, so the failure rippled outward, touching every sector that relies on the grid, from transport to food storage to the pumps that move fuel. It's a chain reaction with no easy off switch. And there isn't one.

Corman posed the same prioritization question again, yet now a chorus of stakeholders clamored for different answers. The public and media wanted insurance companies to protect human life. The Treasury demanded a focus on economic concerns. The US military insisted on safeguarding military infrastructure. So the executives faced an impossible choice. They couldn't satisfy everyone at once, and they had to determine what they valued most,no, what they truly valued, stripped of all pretense: human life, the economy, or national security. It was a brutal test. There was no middle ground.
“The fact is that China really is breaking into US civilian critical infrastructure. And I don’t want to sound overdramatic here, but laying what Rob Joyce, the former NSA director of cybersecurity, describes as digital bombs strapped to our infrastructure.”
Almost everyone in the room said saving human lives was the priority. But not everyone did. That disagreement, captured in the war game, highlights a fundamental problem with how the US would respond to such an attack. There is no clear chain of command, no established playbook for who makes the calls when 5,000 water utilities go down simultaneously.
Why Insurance Companies Are the First Call
Greenberg explained why insurance executives were the focus of this exercise. When a company gets hacked, their first call is very often to their insurance agency, and that insurer then unlocks the lawyers and cybersecurity incident responders who have been preapproved and are ready to be paid for. So cyber insurance, on a surprising level, controls the entire national response to a cyber event. That's a heavy load. They're financially on the hook, so they need to know exactly what will happen.
The comparison is apt. When you think about recovery from a hurricane, it's the home insurers like Allstate and State Farm who are there for every step of the process, guiding homeowners through damage assessments, paperwork, and the long, grinding path back to normalcy. A large-scale cybersecurity disaster is no different. But here's the uncomfortable truth. The insurance industry is the de facto first responder, and they are not prepared for the scale of a Volt Typhoon attack, so they can't just wing it when the digital storm finally makes landfall.
China’s Restraint Won’t Last Forever
Volt Typhoon has never actually pulled the trigger on a disruptive attack. That restraint is part of why this story has gone under the radar. But the pre-positioning has been happening for three years, and the malware is planted while the infrastructure is compromised, so the only question now is when, not if, China decides to detonate those digital bombs. It's a quiet, patient siege. They're waiting.
The Takeaway for the Rest of Us
The war game revealed that the US is not ready. The incident responders are over capacity in a hypothetical scenario, meaning they would be over capacity in a real one. The insurance companies are making decisions based on revenue rather than human impact. The government’s priorities are unclear. And the hackers are already inside.
China strapping digital bombs to infrastructure is a reality. The game simply showed what happens when they go off. It’s not a pretty picture.
The scenario was set just a year from now. The clock is ticking.
Frequently Asked Questions
What was the premise of the war game held earlier this year with insurance executives?
The war game simulated a coordinated cyberattack by China that knocked out 5,000 US water utilities at once. The scenario was set in July 2027 and was designed by Joshua Corman, a former strategist for the Cybersecurity and Infrastructure Security Agency.
Why did the insurance executives struggle to prioritize which water utilities to help first?
The executives faced resource scarcity, as they had limited responders and supplies. They had to decide how to prioritize, knowing that every choice meant another community would go without water, and they were forced to make decisions without sufficient information, as seen when they initially suggested prioritizing by revenue, which was later deemed a naive and disastrous response.
How did the second-order effects of the water utility outages escalate on day two?
The second-order effects cascaded, causing data centers to lose cooling and cloud services to go down, manufacturing to suffer, especially drug manufacturing leading to an insulin shortage, and hospitals facing HVAC outages and potential evacuations. Even electrical generation was affected because it requires water, so the failure rippled across all sectors that depend on the grid.
Who is Volt Typhoon and what have they been doing for three years?
Volt Typhoon is a Chinese state-sponsored hacking group that has spent three years planting malware inside US critical infrastructure. Unlike most Chinese hackers who focus on espionage, they are pre-positioning for disruption, not theft, to potentially turn off power, disrupt telecommunications, and poison water supplies.
What role do insurance companies play in a cyberattack response, and why were they the focus of the exercise?
Insurance companies are often the first call when a company gets hacked, and they control the national response by unlocking preapproved lawyers and incident responders. They are financially on the hook, so they need to know what will happen, but they are not prepared for the scale of a Volt Typhoon attack, making them the de facto first responders who are unprepared.
💬 Comments (0)
No comments yet. Be the first!













