A simulated cyberattack war game targeting 5,000 U.S. water utilities was conducted in an office tower above Times Square. The scenario focused on disruption caused by the Volt Typhoon hacking group.

Joshua Corman, a former Cybersecurity and Infrastructure Security Agency (CISA) strategist, served as the facilitator for the war game. Participants, including insurance executives, were divided into six teams during the exercise, which tasked them with allocating cybersecurity incident responders and financial resources.

The simulated attack was set in July 2027, just before Independence Day, and depicted hackers triggering physical destruction such as burst water mains. The scenario further illustrated broad societal impacts, including 2,000 hospitals without water, affecting patient care and causing evacuations. Food refrigeration systems at cold storage warehouses failed due to water outages, and water-dependent drug and chemical manufacturing bottlenecks led to insulin shortages. Data center cooling system failures also occurred, resulting in cloud service outages.

The war game scenario suggested the cyberattack was carried out by the Chinese military to hinder a U.S. response to an invasion of Taiwan. In May 2023, Microsoft, the National Security Agency (NSA), and CISA announced the discovery of Volt Typhoon, identifying it as a group of hackers working for the Chinese military.

Volt Typhoon intruders breached critical infrastructure facilities across the continental United States and Guam, impacting manufacturing, telecommunications, and the electric grid. Microsoft stated Volt Typhoon was pursuing capabilities to disrupt critical communications infrastructure between the United States and the Asia region during future crises. An advisory from CISA and NSA in early 2024 described these activities as pre-positioning for broad cyberattacks. The group's target lists included the IT systems of a water utility in Hawaii, multiple U.S. ports, at least one oil and gas pipeline, and hundreds of other entities, including the Littleton Electric Light & Water Departments in Littleton, Massachusetts.

Brandon Wales, former executive director of CISA, stated, "The only reason to target that sort of entity is to cause societal chaos in the United States." Jen Easterly, who was director of CISA when the Volt Typhoon campaign was first discovered and is now CEO of the RSA cybersecurity conference, indicated that the initial findings were extensive. "What we found was really just the tip of the iceberg," Easterly said. She also questioned the intent behind Volt Typhoon's actions, stating, "Do I believe there's any change to China's very deliberate strategy to create access points in our most important civilian infrastructure, to be able to launch disruptive attacks in the event of a crisis in the Taiwan Strait?" Easterly separately noted that artificial intelligence could make mass-sabotage scenarios far more plausible in the coming years.