Relevance: primary · Type: event
Confidence100%
A simulated cyberattack war game on US water utilities took place in an office tower above Times Square.
Relevance: primary · Type: action
Confidence100%
Joshua Corman served as the facilitator of the war game.
Relevance: supporting · Type: background
Confidence100%
Joshua Corman is a former Cybersecurity and Infrastructure Security Agency strategist.
Relevance: supporting · Type: background
Confidence100%
Participants in the war game included insurance executives divided into six teams.
Relevance: primary · Type: event
Confidence100%
The war game scenario involved hackers disrupting 5,000 water utilities across the United States.
Relevance: supporting · Type: event
Confidence100%
The war game scenario depicted food refrigeration systems failing at cold storage warehouses due to water outages.
Relevance: supporting · Type: event
Confidence100%
The war game scenario depicted water-dependent drug and chemical manufacturing bottlenecks leading to insulin shortages.
Relevance: supporting · Type: event
Confidence100%
The war game scenario depicted data center cooling system failures causing cloud service outages.
Relevance: supporting · Type: event
Confidence100%
The war game scenario depicted 2,000 hospitals without water, hampering patient care and causing evacuations.
Relevance: supporting · Type: event
Confidence100%
The war game scenario depicted hackers triggering physical destruction, such as burst water mains.
Relevance: supporting · Type: background
Confidence100%
The war game scenario was set in July 2027, just before Independence Day.
Relevance: primary · Type: action
Confidence100%
War game participants were tasked with deciding how to allocate cybersecurity incident responders and money.
Relevance: primary · Type: background
Confidence100%
The war game scenario suggested the cyberattack was carried out by the Chinese military to hamper a US response to an invasion of Taiwan.
Relevance: primary · Type: event
Confidence100%
In May 2023, Microsoft, the National Security Agency, and CISA announced the discovery of Volt Typhoon.
Relevance: primary · Type: background
Confidence100%
Volt Typhoon is a group of hackers working in service of the Chinese military.
Source: Microsoft
Relevance: primary · Type: event
Confidence100%
Volt Typhoon intruders breached networks of critical infrastructure facilities across the continental United States and Guam.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon targets included manufacturing, telecommunications, and the electric grid.
Relevance: primary · Type: quote
Confidence100%
Microsoft stated Volt Typhoon was pursuing development of capabilities to disrupt critical communications infrastructure between the United States and the Asia region during future crises.
Source: Microsoft
Relevance: primary · Type: background
Confidence100%
A CISA and NSA advisory in early 2024 described Volt Typhoon activities as pre-positioning for broad cyberattacks.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon target lists included the IT systems of a water utility in Hawaii.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon target lists included multiple US ports.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon target lists included at least one oil and gas pipeline.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon target lists included hundreds of other entities, including the Littleton Electric Light & Water Departments in Littleton, Massachusetts.
Relevance: supporting · Type: background
Confidence100%
Littleton, Massachusetts has a population of just under 10,500 residents.
Relevance: supporting · Type: background
Confidence100%
Brandon Wales is the former executive director of CISA.
Brandon Wales, former executive director of CISA
Relevance: primary · Type: quote
Confidence100%
"The only reason to target that sort of entity is to cause societal chaos in the United States."
Relevance: supporting · Type: background
Confidence100%
Joe Slowik is a former Los Alamos National Labs cybersecurity researcher.
Relevance: supporting · Type: background
Confidence100%
Joe Slowik works on contract for the Department of Energy.
Relevance: supporting · Type: background
Confidence100%
Joe Slowik leads threat research at cybersecurity firm Dataminr.
Relevance: primary · Type: background
Confidence100%
Volt Typhoon or a related hacker group continues to target the US electric grid and water utilities.
Relevance: supporting · Type: background
Confidence100%
Some Volt Typhoon intrusions go undetected due to minimal security budgets of municipal utilities and stealthy operating modes.
Relevance: supporting · Type: background
Confidence100%
Volt Typhoon uses a mode of operating known as "living off the land" that hijacks legitimate functions in a network instead of planting malware.
Joe Slowik, threat research lead at Dataminr
Relevance: supporting · Type: quote
Confidence100%
"It’s pretty good tradecraft."
Joe Slowik, threat research lead at Dataminr
Relevance: supporting · Type: quote
Confidence100%
"But it’s also applying that tradecraft to areas that really don’t have the capacity to identify it."
Relevance: supporting · Type: background
Confidence100%
Jen Easterly served as director of the Cybersecurity and Infrastructure Security Agency when the Volt Typhoon hacking campaign was first discovered.
Relevance: supporting · Type: background
Confidence100%
Jen Easterly is the CEO of the RSA cybersecurity conference.
Relevance: primary · Type: background
Confidence100%
Jen Easterly stated that AI could make mass-sabotage hypotheticals far more plausible in the coming years.
Jen Easterly, CEO of the RSA cybersecurity conference
Relevance: primary · Type: quote
Confidence100%
"What we found was really just the tip of the iceberg."
Jen Easterly, CEO of the RSA cybersecurity conference
Relevance: primary · Type: quote
Confidence100%
"Do I believe there’s any change to China’s very deliberate strategy to create access points in our most important civilian infrastructure, to be able to launch disruptive attacks in the event of a crisis in the Taiwan Strait?"
forum Comments (0)
No comments yet. Be the first to comment.