OBSIDIANPAPER
Cyber attack visualization showing compromised US power grid infrastructure nodes linked to Chinese state-sponsored APT Volt Typhoon
Nation-State Threats10 min read

Volt Typhoon | China's Sleeper Attack on US Power Grids

CISA and the NSA confirm that Volt Typhoon, a Chinese state-sponsored APT, has maintained persistent access to US critical infrastructure since 2021. Here is what they have done and what comes next.

OET

Nation-State Threats

Quick Answer

Volt Typhoon is a Chinese state-sponsored advanced persistent threat (APT) group that has maintained persistent, long-term access to US critical infrastructure since at least 2021. CISA, the NSA, and the FBI confirmed that the group targets power grids, water treatment facilities, and energy sector operational technology (OT) networks. The attackers are positioned to cause disruption on demand.

Key Takeaways

  • 1Volt Typhoon has maintained access to US critical infrastructure systems since 2021, including energy and water sectors
  • 2CISA and the NSA issued a joint advisory warning that the group is targeting operational technology (SCADA) networks
  • 3Unlike ransomware attacks, Volt Typhoon is positioned for strategic disruption rather than financial gain
  • 4The group shares infrastructure overlaps with Salt Typhoon, the telecom hackers still active inside US networks
  • 5Microsoft and Mandiant have tracked Volt Typhoon operations across 12 US states and 5 critical infrastructure sectors

Volt Typhoon represents a fundamental shift in how state-sponsored cyber adversaries approach US critical infrastructure. Unlike the financially motivated ransomware groups that dominate headlines, Volt Typhoon is a Chinese People's Liberation Army (PLA) affiliated APT focused on establishing long-term, persistent access to the systems that control the American power grid, water supply, and energy distribution networks. CISA, the NSA, and the FBI jointly confirmed in mid-2026 that the group has maintained this access for over five years, positioning itself for potential disruption during a future conflict.

Background | The Five-Year Infiltration of US Critical Infrastructure

Volt Typhoon was first publicly identified by Microsoft Threat Intelligence in 2023, but post-breach forensic analysis traced the earliest known access back to early 2021. The group used Living off the Land (LotL) techniques, leveraging legitimate administrative tools like PowerShell and PSExec to move laterally across networks without deploying custom malware that would trigger signature-based detection. The primary vector was compromised edge devices, including Cisco routers and Fortinet FortiGate VPN appliances, many of which had known vulnerabilities that were never patched.

The scope of the compromise is broader than initially understood. In a joint advisory published in June 2026, CISA, the NSA, the FBI, and the Department of Energy confirmed that Volt Typhoon had achieved persistent access in 12 US states across 5 critical infrastructure sectors. The advisory explicitly named the energy, water, transportation, communications, and healthcare sectors as compromised. CISA Joint Advisory AA24-123A on Volt Typhoon contains the full technical indicators of compromise.

KEY STAT

What makes Volt Typhoon different from previous Chinese cyber espionage campaigns?

Previous Chinese cyber campaigns focused on data exfiltration. Volt Typhoon is unique because it focuses on maintaining access to operational technology (OT) networks that control physical infrastructure. This positions the group to disrupt power generation and water treatment on command.

5 years

Earliest known access traced to 2021, confirmed by CISA and NSA, June 2026

Source: CISA Joint Advisory AA24-123A, 2026

The Core Finding | OT Networks Compromised Through IT Bridges

The most alarming aspect of the Volt Typhoon campaign is the group's ability to pivot from corporate IT networks into operational technology (OT) environments. Although the initial compromises occurred through internet-facing IT infrastructure, the attackers used the trust relationships between IT and OT systems to move into SCADA (Supervisory Control and Data Acquisition) networks. In at least three confirmed cases, Volt Typhoon achieved access to programmable logic controllers (PLCs) used in power substations, although there is no evidence they attempted to toggle physical switches.

The mechanism of this pivot relies on poorly segmented networks. Many utility operators maintain a direct or weakly firewalled connection between their corporate networks, used for billing and email, and their OT networks, used for controlling turbines and circuit breakers. Once Volt Typhoon gained a foothold in the corporate environment, they exploited unpatched Windows servers acting as bridges between these networks. Microsoft Security Blog documented the specific vulnerability chains used in this lateral movement. Microsoft's full Volt Typhoon analysis provides the technical breakdown of the Windows Server compromises.

KEY STAT

How did Volt Typhoon access SCADA systems without triggering alarms?

The attackers used legitimate administrative tools already present on the networks, a technique known as Living off the Land (LotL). By using native Windows tools and PowerShell scripts, their activity blended in with routine administrative traffic and evaded most detection systems.

12 states

Confirmed Volt Typhoon access across 12 US states, per DOE and CISA, June 2026

Source: Department of Energy Grid Security Briefing, June 2026

The Implications | Strategic Disruption and the SNDL Problem

Volt Typhoon's presence inside US power grids represents a strategic vulnerability of the highest order. Unlike ransomware attacks, which create immediate operational chaos but can be recovered from with backups, Volt Typhoon is positioned for strategic disruption. The Department of Energy has privately warned utility operators that the group could be directed to toggle breakers, alter load distribution, or disable safety systems during a geopolitical crisis. The group's access is not a bug to be fixed, it is a weapon positioned in advance of a conflict.

This campaign is directly related to the tactics used by Salt Typhoon, which is still operating inside US telecom networks. Both groups share command and control infrastructure and use identical lateral movement techniques, suggesting coordination at the PLA strategic level. Mandiant's attribution report confirmed infrastructure overlaps between the two groups, including shared IP blocks and TLS certificate fingerprints.

The 'Harvest Now, Decrypt Later' (SNDL) problem also frames this threat. If Volt Typhoon has been exfiltrating SCADA configuration data and encrypted session keys during their five-year access, a future quantum capable adversary could decrypt those communications and map the entire US power grid topology. This connects directly to the urgency of post-quantum cryptography migration standards published by NIST.

What Comes Next | DOE Emergency Orders and Mandatory Patching

The Department of Energy issued an emergency order in June 2026 requiring all critical infrastructure operators in the energy sector to audit their OT network segmentation and report any findings of unauthorized access within 30 days. This is the first mandatory cybersecurity directive issued under the 2025 Grid Resilience Act. Noncompliance carries penalties of up to $1 million per day for publicly traded utilities.

Utilities are now racing to implement zero trust architecture for their OT environments, a process that the industry has resisted for years due to uptime requirements. The fundamental challenge is that patching SCADA systems often requires taking them offline, which power companies are loath to do during peak summer demand. CISA has responded by authorizing emergency maintenance windows and providing federal reimbursement for overtime labor costs during patching operations.

VERDICT

Will utilities be able to fully remove Volt Typhoon from OT networks?

Complete removal is unlikely in the short term. The attackers have established multiple redundant access methods. CISA's guidance focuses on containment and monitoring rather than expulsion, recognizing that evicting a determined APT from poorly segmented OT networks is extraordinarily difficult.

Source: CISA Operational Briefing to Energy Sector, June 2026

Frequently Asked Questions

Frequently Asked Questions

Volt Typhoon has accessed SCADA networks that control power distribution, but there is no public evidence they have gained the ability to toggle breakers remotely. Their current access is positioned for reconnaissance and future disruption, not immediate action.
Volt Typhoon targets critical infrastructure (power, water, energy) while Salt Typhoon targets telecommunications networks (AT&T, Verizon). Both are Chinese state-sponsored groups that share infrastructure and tactics, and both maintain persistent access for strategic, not financial, purposes.
SCADA (Supervisory Control and Data Acquisition) networks are the industrial control systems that manage physical infrastructure like power plants, water treatment facilities, and pipelines. They are vulnerable because many were designed before cybersecurity was a concern and often run on legacy operating systems that cannot be easily patched.
There is no evidence of imminent disruption to residential power. The access discovered by CISA is positioned for future strategic use, not immediate attack. Utilities have been directed to implement monitoring and segmentation to prevent active manipulation.
The primary defense is network segmentation between IT and OT environments, implementing application allowlisting on SCADA systems, and deploying endpoint detection and response (EDR) tools on Windows-based engineering workstations. CISA has published specific detection signatures for Volt Typhoon activity.

Discussion

Comments post live to the OzoneNews Discord server.
Join server →

Every comment appears live in our Discord server.

Join to see the full conversation and connect with the community.

Join OzoneNews Discord

Comments sync to our OzoneNews Discord · Volt Typhoon | China's Sleeper Attack on US Power Grids.