Product1 distinct publisher3 min readUpdated
About 30 insurance executives modelled a Chinese strike on 5,000 US water utilities. The exposure Volt Typhoon has built is not any single intrusion, it is the simultaneity.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
About 30 insurance executives sat in a conference room above Times Square earlier this year and worked a countdown clock against one scenario: a Chinese cyberattack that knocks out 5,000 US water utilities all at once [1]. WIRED senior correspondent Andy Greenberg, given a rare invitation to the closed-door exercise, reports it was designed by a former cybersecurity strategist to test what happens if hackers linked to Volt Typhoon act on groundwork they have been laying for three years [2][3].
The interesting variable is not the water. It is who bothered to run the game. Read as an underwriting exercise rather than a security one, the design strips out the assumption every book of business depends on: independence. One intrusion at one utility is a claim. Five thousand utilities failing on the same trigger, attributed to the same actor, is a single correlated event with thousands of policyholders inside it [11]. That is the loss shape carriers price worst, and it is the reason the room was full of insurers instead of plant operators.
The adversary profile is what makes the correlation plausible rather than theoretical. Volt Typhoon, according to Greenberg, is a Chinese state-sponsored group that has spent the past three years pre-positioning inside American infrastructure [4], and that, unlike most Chinese state hackers, is not primarily running espionage: it plants malware to enable disruption, from cutting power and causing blackouts to disrupting telecommunications and potentially affecting the water supply [5]. When the group first came to light in 2023, the headlines placed it in electric grids and telecommunications networks in the continental US and in Guam, apparently around US military facilities and the infrastructure surrounding them [6]. The theory Greenberg says analysts have been working under is that China is preparing to delay a US response to an invasion of Taiwan [7].
For anyone holding the risk, the sequence is the uncomfortable part. The group surfaced in 2023 and had three years of pre-positioning behind it by the time the exercise was played earlier this year, which means the access being modelled was already installed inside the systems while the model was being built [12]. This is not a hazard that arrives with a warning; it is a hazard that arrives with a decision.
Brian Barrett, WIRED's executive editor, summarised the projected consequences as burst water mains, evacuated hospitals and insulin shortages [8]. Those do not land in one line of business, which is precisely why an aggregate limit written per-utility does little. And Barrett's other point is the harder one for the industry: the scariest finding may not be the hack, but what the exercise revealed about who is actually in charge when the water stops [9].
What to watch. The published transcript excerpt cuts off mid-sentence, as Greenberg begins describing further US systems Volt Typhoon was breaking into [10], so the participants' pricing conclusions are not in this material. The signals worth tracking are downstream of the game rather than in it: whether carriers move critical-infrastructure cyber cover toward war or state-actor exclusions, whether utility-sector policies acquire event definitions that treat simultaneous failures as one occurrence, and whether water systems, which are numerous and small, find that cover is simply withdrawn rather than repriced. A correlated loss no private balance sheet will hold ends up somewhere. The question the war game raises, and this excerpt does not answer, is who is holding it now.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Volt Typhoon is a Chinese state-sponsored hacking group that has spent the past three years pre-positioning itself inside American infrastructure.
Greenberg says Volt Typhoon, unlike most Chinese state hackers, does not focus on espionage but has been planting malware inside US critical infrastructure to enable disruption: turning off power, causing blackouts, disrupting telecommunications, and potentially affecting the water supply.
Earlier this year about 30 insurance executives gathered in a conference room high above Times Square in Manhattan to simulate a Chinese cyberattack that would knock out 5,000 US water utilities all at once, under a countdown clock.
WIRED senior correspondent Andy Greenberg got a rare invite to the closed-door war game.
The war game was designed by a former cybersecurity strategist to test what would happen if and when hackers linked to the Chinese operation called Volt Typhoon follow through on groundwork they have been laying for three years.
When Volt Typhoon first came to light in 2023, the headlines said it was targeting electric grids and telecommunication networks in the continental US and in Guam specifically, and it seemed to be targeting US military facilities and the surrounding infrastructure.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-hand but single-source and truncated
The strongest evidence is direct: a WIRED correspondent attended the exercise and describes its design, participants and premise, and the Volt Typhoon background is consistent with widely reported prior disclosure referenced in the episode. But everything here comes from one publisher's podcast transcript, the transcript breaks off before the exercise's conclusions, the designer and sponsoring organisation are unnamed, and the headline consequences are asserted rather than modelled.
One exercise, no institutional follow-through shown
Adoption of correlated cyber-physical catastrophe modelling is evidenced by exactly one documented event: a single closed-door tabletop with roughly 30 executives. Separately, the underlying intrusions are reported as real and widespread across civilian utilities, which raises the practical relevance. Nothing in the supplied material shows repeat exercises, industry-wide programmes, pricing changes, policy-wording revisions or utility remediation, so uptake cannot be scored higher.
Framing runs ahead of what is shown
The episode's language — 'digital bombs', worst nightmares, burst mains and insulin shortages — is stronger than what the supplied material demonstrates. The 5,000-utility figure is a scenario parameter, the Taiwan motive is explicitly labelled a theory, and the transcript ends before the insurers' conclusions, so the alarming payoff is promised rather than delivered. The gap is moderate rather than severe because the underlying pre-positioning is corroborated by prior public disclosure and a named former NSA official's characterisation cited in the episode.
Publisher promoting its own scoop; designer undisclosed
The item is a WIRED podcast built to promote a WIRED feature, with the host emphasising rare access and 'disturbing conclusions' — a direct attention incentive to heighten threat framing. The exercise designer is described only as a former cybersecurity strategist, with no disclosure of who commissioned or funded the game, and insurance participants have their own interest in documenting tail exposure. None of these incentives are hidden, but none are disclosed in detail either.
Moderate-low: one publisher, partial record
Confidence is limited by structure rather than plausibility: a single publisher, an automated transcript flagged as possibly containing errors, truncation before the exercise's outcome, no named designer or organiser, and no second account of the game. The Volt Typhoon background is well-established enough to raise confidence in the threat premise, but not in the exercise's specific findings or in the correlated-loss interpretation, which is derived here rather than sourced.
product
Proton's Yen stops refusing AI and ships Lumo, moving the privacy fight to terms1 distinct publisher
build
Flock's OS Investigate starts the search before there is a suspect1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
product
Rogue Studio ships an uncensored video model and prices permission from $29 to $2991 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026