Tech

Volt Typhoon war game exposes US insurance sector’s cyber vulnerability

A closed-door exercise simulating a mass cyberattack on water utilities suggests the industry lacks the financial capacity to handle a national-scale crisis without government backstops.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · View original source
China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?
Markets & Finance

A recent closed-door war game involving approximately 30 insurance executives has revealed significant gaps in the sector’s ability to manage a large-scale cyber crisis in the United States. The exercise, designed by former Cybersecurity and Infrastructure Security Agency strategist Joshua Corman, simulated a scenario set in July 2027 where the Chinese state-sponsored hacking group Volt Typhoon simultaneously knocks out 5,000 US water utilities. The scenario was discussed in a recent episode of WIRED’s “Uncanny Valley” podcast, featuring senior correspondent Andy Greenberg and executive editor Brian Barrett.

The simulation explored the cascading consequences of such an attack, including burst water mains, data centre cooling failures, and manufacturing disruptions that led to insulin shortages. Hospitals faced particular strain, with air conditioning outages forcing potential evacuations in hot regions. The exercise highlighted that insurance companies are often the first point of contact for businesses after a cyberattack, effectively controlling the initial response by unlocking pre-approved legal and incident response resources.

Despite this pivotal role, the war game suggested the industry is ill-prepared for a national security event of this magnitude. When tasked with prioritising claims under resource scarcity, executives initially considered prioritising by revenue, a response identified as potentially disastrous. As the scenario progressed, participants faced competing demands from the public, the Treasury Department, and the US military, forcing difficult choices between protecting human life, economic stability, and military infrastructure.

A key takeaway from post-game discussions was that the event was effectively “uninsurable.” The industry reportedly lacked the financial capacity to cover such a large-scale loss without seeking “act of war” exclusions or government backstops similar to the Terrorism Risk Insurance Act. This finding echoes debates following the 2017 NotPetya cyberattack, which caused over $10 billion in damage and sparked legal disputes over insurance policy exclusions.

Volt Typhoon has been pre-positioning malware in US critical infrastructure for approximately three years. While initially thought to target military facilities in preparation for a potential Taiwan invasion, the group has also infiltrated civilian infrastructure, including utilities in small towns such as Littleton, Massachusetts. Incident response sources have confirmed that the group, or its evolved form, is still actively pre-positioning malware in US networks, despite some intrusions being detected and evicted.

The exercise underscores the growing financial risk posed by state-sponsored cyber threats. As the US government and private sector grapple with the possibility of a coordinated attack on civilian infrastructure, the insurance industry’s limited capacity to absorb such losses raises questions about the need for new regulatory frameworks or government-backed funds to ensure national resilience.

Continue reading

More from Tech

Read next: AppleCare One bundles protection for up to three devices, Engadget says
Read next: Apple reportedly developing iPhone game controllers under Beats brand
Read next: Tesla-linked DNS setup allegedly sends Assetnote scans to volunteer NTP server