Product1 publisher3 min readPublished
Insurers war-gamed 5,000 water utilities going down at once. That is a correlation problem.
About 30 insurance executives modelled a Chinese strike on 5,000 US water utilities. The exposure Volt Typhoon has built is not any single intrusion, it is the simultaneity.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Earlier this year about 30 insurance executives gathered in a conference room high above Times Square in Manhattan to simulate a Chinese cyberattack that would knock out 5,000 US water utilities all at once, under a countdown clock.
- WIRED senior correspondent Andy Greenberg got a rare invite to the closed-door war game.
- The war game was designed by a former cybersecurity strategist to test what would happen if and when hackers linked to the Chinese operation called Volt Typhoon follow through on groundwork they have been laying for three years.
- Volt Typhoon is a Chinese state-sponsored hacking group that has spent the past three years pre-positioning itself inside American infrastructure.
- Greenberg says Volt Typhoon, unlike most Chinese state hackers, does not focus on espionage but has been planting malware inside US critical infrastructure to enable disruption: turning off power, causing blackouts, disrupting telecommunications, and potentially affecting the water supply.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
About 30 insurance executives sat in a conference room above Times Square earlier this year and worked a countdown clock against one scenario: a Chinese cyberattack that knocks out 5,000 US water utilities all at once [1]. WIRED senior correspondent Andy Greenberg, given a rare invitation to the closed-door exercise, reports it was designed by a former cybersecurity strategist to test what happens if hackers linked to Volt Typhoon act on groundwork they have been laying for three years [2][3].
The interesting variable is not the water. It is who bothered to run the game. Read as an underwriting exercise rather than a security one, the design strips out the assumption every book of business depends on: independence. One intrusion at one utility is a claim. Five thousand utilities failing on the same trigger, attributed to the same actor, is a single correlated event with thousands of policyholders inside it [11]. That is the loss shape carriers price worst, and it is the reason the room was full of insurers instead of plant operators.
The adversary profile is what makes the correlation plausible rather than theoretical. Volt Typhoon, according to Greenberg, is a Chinese state-sponsored group that has spent the past three years pre-positioning inside American infrastructure [4], and that, unlike most Chinese state hackers, is not primarily running espionage: it plants malware to enable disruption, from cutting power and causing blackouts to disrupting telecommunications and potentially affecting the water supply [5]. When the group first came to light in 2023, the headlines placed it in electric grids and telecommunications networks in the continental US and in Guam, apparently around US military facilities and the infrastructure surrounding them [6]. The theory Greenberg says analysts have been working under is that China is preparing to delay a US response to an invasion of Taiwan [7].
For anyone holding the risk, the sequence is the uncomfortable part. The group surfaced in 2023 and had three years of pre-positioning behind it by the time the exercise was played earlier this year, which means the access being modelled was already installed inside the systems while the model was being built [12]. This is not a hazard that arrives with a warning; it is a hazard that arrives with a decision.
Brian Barrett, WIRED's executive editor, summarised the projected consequences as burst water mains, evacuated hospitals and insulin shortages [8]. Those do not land in one line of business, which is precisely why an aggregate limit written per-utility does little. And Barrett's other point is the harder one for the industry: the scariest finding may not be the hack, but what the exercise revealed about who is actually in charge when the water stops [9].
What to watch. The published transcript excerpt cuts off mid-sentence, as Greenberg begins describing further US systems Volt Typhoon was breaking into [10], so the participants' pricing conclusions are not in this material. The signals worth tracking are downstream of the game rather than in it: whether carriers move critical-infrastructure cyber cover toward war or state-actor exclusions, whether utility-sector policies acquire event definitions that treat simultaneous failures as one occurrence, and whether water systems, which are numerous and small, find that cover is simply withdrawn rather than repriced. A correlated loss no private balance sheet will hold ends up somewhere. The question the war game raises, and this excerpt does not answer, is who is holding it now.