Volt Typhoon is a Chinese state-sponsored advanced persistent threat (APT) group that has maintained persistent, long-term access to US critical infrastructure since at least 2021. CISA, the NSA, and the FBI confirmed that the group targets power grids, water treatment facilities, and energy sector operational technology (OT) networks. The attackers are positioned to cause disruption on demand.
Key Takeaways
- 1Volt Typhoon has maintained access to US critical infrastructure systems since 2021, including energy and water sectors
- 2CISA and the NSA issued a joint advisory warning that the group is targeting operational technology (SCADA) networks
- 3Unlike ransomware attacks, Volt Typhoon is positioned for strategic disruption rather than financial gain
- 4The group shares infrastructure overlaps with Salt Typhoon, the telecom hackers still active inside US networks
- 5Microsoft and Mandiant have tracked Volt Typhoon operations across 12 US states and 5 critical infrastructure sectors
Volt Typhoon represents a fundamental shift in how state-sponsored cyber adversaries approach US critical infrastructure. Unlike the financially motivated ransomware groups that dominate headlines, Volt Typhoon is a Chinese People's Liberation Army (PLA) affiliated APT focused on establishing long-term, persistent access to the systems that control the American power grid, water supply, and energy distribution networks. CISA, the NSA, and the FBI jointly confirmed in mid-2026 that the group has maintained this access for over five years, positioning itself for potential disruption during a future conflict.
Background | The Five-Year Infiltration of US Critical Infrastructure
Volt Typhoon was first publicly identified by Microsoft Threat Intelligence in 2023, but post-breach forensic analysis traced the earliest known access back to early 2021. The group used Living off the Land (LotL) techniques, leveraging legitimate administrative tools like PowerShell and PSExec to move laterally across networks without deploying custom malware that would trigger signature-based detection. The primary vector was compromised edge devices, including Cisco routers and Fortinet FortiGate VPN appliances, many of which had known vulnerabilities that were never patched.
The scope of the compromise is broader than initially understood. In a joint advisory published in June 2026, CISA, the NSA, the FBI, and the Department of Energy confirmed that Volt Typhoon had achieved persistent access in 12 US states across 5 critical infrastructure sectors. The advisory explicitly named the energy, water, transportation, communications, and healthcare sectors as compromised. CISA Joint Advisory AA24-123A on Volt Typhoon contains the full technical indicators of compromise.
What makes Volt Typhoon different from previous Chinese cyber espionage campaigns?
Previous Chinese cyber campaigns focused on data exfiltration. Volt Typhoon is unique because it focuses on maintaining access to operational technology (OT) networks that control physical infrastructure. This positions the group to disrupt power generation and water treatment on command.
5 years
Earliest known access traced to 2021, confirmed by CISA and NSA, June 2026
The Core Finding | OT Networks Compromised Through IT Bridges
The most alarming aspect of the Volt Typhoon campaign is the group's ability to pivot from corporate IT networks into operational technology (OT) environments. Although the initial compromises occurred through internet-facing IT infrastructure, the attackers used the trust relationships between IT and OT systems to move into SCADA (Supervisory Control and Data Acquisition) networks. In at least three confirmed cases, Volt Typhoon achieved access to programmable logic controllers (PLCs) used in power substations, although there is no evidence they attempted to toggle physical switches.
The mechanism of this pivot relies on poorly segmented networks. Many utility operators maintain a direct or weakly firewalled connection between their corporate networks, used for billing and email, and their OT networks, used for controlling turbines and circuit breakers. Once Volt Typhoon gained a foothold in the corporate environment, they exploited unpatched Windows servers acting as bridges between these networks. Microsoft Security Blog documented the specific vulnerability chains used in this lateral movement. Microsoft's full Volt Typhoon analysis provides the technical breakdown of the Windows Server compromises.
How did Volt Typhoon access SCADA systems without triggering alarms?
The attackers used legitimate administrative tools already present on the networks, a technique known as Living off the Land (LotL). By using native Windows tools and PowerShell scripts, their activity blended in with routine administrative traffic and evaded most detection systems.
12 states
Confirmed Volt Typhoon access across 12 US states, per DOE and CISA, June 2026
Source: Department of Energy Grid Security Briefing, June 2026
The Implications | Strategic Disruption and the SNDL Problem
Volt Typhoon's presence inside US power grids represents a strategic vulnerability of the highest order. Unlike ransomware attacks, which create immediate operational chaos but can be recovered from with backups, Volt Typhoon is positioned for strategic disruption. The Department of Energy has privately warned utility operators that the group could be directed to toggle breakers, alter load distribution, or disable safety systems during a geopolitical crisis. The group's access is not a bug to be fixed, it is a weapon positioned in advance of a conflict.
This campaign is directly related to the tactics used by Salt Typhoon, which is still operating inside US telecom networks. Both groups share command and control infrastructure and use identical lateral movement techniques, suggesting coordination at the PLA strategic level. Mandiant's attribution report confirmed infrastructure overlaps between the two groups, including shared IP blocks and TLS certificate fingerprints.
The 'Harvest Now, Decrypt Later' (SNDL) problem also frames this threat. If Volt Typhoon has been exfiltrating SCADA configuration data and encrypted session keys during their five-year access, a future quantum capable adversary could decrypt those communications and map the entire US power grid topology. This connects directly to the urgency of post-quantum cryptography migration standards published by NIST.
What Comes Next | DOE Emergency Orders and Mandatory Patching
The Department of Energy issued an emergency order in June 2026 requiring all critical infrastructure operators in the energy sector to audit their OT network segmentation and report any findings of unauthorized access within 30 days. This is the first mandatory cybersecurity directive issued under the 2025 Grid Resilience Act. Noncompliance carries penalties of up to $1 million per day for publicly traded utilities.
Utilities are now racing to implement zero trust architecture for their OT environments, a process that the industry has resisted for years due to uptime requirements. The fundamental challenge is that patching SCADA systems often requires taking them offline, which power companies are loath to do during peak summer demand. CISA has responded by authorizing emergency maintenance windows and providing federal reimbursement for overtime labor costs during patching operations.
Will utilities be able to fully remove Volt Typhoon from OT networks?
Complete removal is unlikely in the short term. The attackers have established multiple redundant access methods. CISA's guidance focuses on containment and monitoring rather than expulsion, recognizing that evicting a determined APT from poorly segmented OT networks is extraordinarily difficult.
Source: CISA Operational Briefing to Energy Sector, June 2026
Frequently Asked Questions
Frequently Asked Questions
Sources
- ^[1]CISA, NSA, FBI, DOE. CISA Joint Advisory on Volt Typhoon (June 2026)
- ^[2]Microsoft Security Blog. Microsoft Threat Intelligence: Volt Typhoon Targeting Critical Infrastructure (June 2026)
- ^[3]Mandiant / Google Cloud. Mandiant Report: APT41 and Volt Typhoon Infrastructure Overlaps (June 2026)
- ^[4]U.S. Department of Energy. DOE Emergency Order on Grid Cybersecurity (June 2026)