---
title: "US Modeled the Worst-Case Scenario: A Cyberattack on 5,000 Water Utilities Would Collapse Infrastructure and Insurers"
description: "Closed exercises in New York showed: in the event of a simultaneous cyberattack on thousands of U.S. water utilities, infrastructure and insurers would not withstand the cascading failure. The Volt Typhoon group continues to entrench itself in city networks."
date: 2026-08-28T14:40:01.000Z
lang: en
url: https://xab.info/en/posts/us-modeled-worst-case-cyberattack-on-water-utilities
tags: [cyberattack, volt-typhoon, us-infrastructure, water-utilities, insurance, cisa]
publisher: "XAB.info"
---

# US Modeled the Worst-Case Scenario: A Cyberattack on 5,000 Water Utilities Would Collapse Infrastructure and Insurers

![Laptop displaying CYBER SECURITY on screen: visualizing the cyberattack threat on US water utilities](https://xab.info/media/2026/08/28/ssha-smodelirovali-kiberataku-na-vodokanaly/ssha-smodelirovali-kiberataku-na-vodokanaly-1.webp)

## 🎯 Key Points

- A closed simulation for insurance companies revealed the unpreparedness of U.S. infrastructure and the insurance market for a simultaneous cyberattack on thousands of water utilities.
- Exercise scenario: July 2027, an attack on 5,000 water utilities amid tensions around Taiwan, causing physical damage to equipment and ruptured pipes.
- On the second day of the simulation, a cascading failure began: data center shutdowns, loss of HVAC in hospitals, and an insulin shortage due to the halt of pharmaceutical production.
- The organizer was former CISA strategist Joshua Korman; prioritizing clients by revenue proved unsuitable, and such attacks are effectively uninsurable.
- The Chinese group Volt Typhoon has been entrenched in U.S. civilian and military networks for more than three years; no active destructive actions yet, but the sabotage potential remains.

Closed exercises conducted for insurance companies in New York showed that American critical infrastructure and the insurance market are not ready for a cyberattack that simultaneously knocks out thousands of water utilities. The simulation, which placed a hypothetical July 2027 at the center of the scenario, demonstrated how a "digital bomb" planted in life-support systems could trigger cascading destruction — from power grids and telecommunications to hospitals and pharmaceutical production. The exercise was organized by Joshua Korman, a former strategist at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), who deliberately created a condition of resource scarcity to test how insurance algorithms, which are usually the first to finance the remediation of cyber incidents, perform under conditions of a national emergency.

### The "Digital Bomb" Scenario: What Was Modeled in New York

The simulation was based on a scenario in which, against the backdrop of rising geopolitical tensions around Taiwan, hackers simultaneously attack 5,000 U.S. water utilities. By the organizers' design, this leads not to a simple shutdown of pumps, but to physical damage to equipment and ruptured water mains — that is, to consequences that cannot be reversed by a simple software restart. This approach reflects the tactics that, according to security experts, are used by the Chinese hacker group Volt Typhoon: unlike classic espionage, the goal here is not to steal data, but to covertly plant malicious software in a system so that, at the right moment, it can simultaneously undermine the operation of power grids, water utilities, and telecommunications.

### Cascading Failure: From Water Utilities to Hospitals

By the second day of the simulated conflict, adjacent industries began to fail, vividly illustrating the chain-reaction effect. The shutdown of water-cooling systems led to mass failures of data centers and cloud services. In healthcare, thousands of hospitals were left without functioning heating, ventilation, and air conditioning (HVAC) systems, which, amid the summer heat, required the immediate evacuation of patients. In parallel, the halt in water supply froze the production of pharmaceuticals and led to a shortage of life-saving drugs, notably insulin. When allocating a limited number of incident-response specialists, participants faced a choice between saving human lives, supporting the economy, and meeting military needs.

### The Insurance Market Was Unprepared

The key takeaway from the exercises — the initial attempt to prioritize clients by revenue size demonstrated the unsuitability of standard commercial approaches during a national emergency. Moreover, the exercises highlighted the main legal and financial problem: such large-scale cyberattacks are effectively uninsurable. This means that even with policies in place, coverage for cascading losses affecting multiple industries and regions at once may prove insufficient or entirely unavailable, shifting the burden of consequences onto the state and the private sector, which, by the end of the simulation, proved unprepared for such a scenario.

### Volt Typhoon: A Hidden Threat Without Active Sabotage

Despite the fact that no active destructive actions by Volt Typhoon have been recorded to date, security experts confirm: the group has been penetrating American civilian and military facilities for more than three years and continues to quietly entrench itself in the networks of both small and large U.S. cities, retaining the potential for large-scale destabilization. It is precisely this "quiet" presence, rather than the hypothetical 2027 scenario, that is, in essence, the main subject of concern: the bomb has already been planted, and the exercises merely showed how vulnerable response and insurance mechanisms are when it is triggered.

## 🔍 Fact-Check Verification

- [Global Cyberterrorism Is Approaching: US Modeled the Worst-Case Attack Scenario](https://www.rbc.ua/ukr/news/globalniy-kiberterorizm-nablizhaetsya-ssha-1787914140.html) - Подтверждает проведение закрытой симуляции худшего сценария кибератаки на инфраструктуру США и каскадные последствия; оговорка — сценарий гипотетический (2027).
- [Cyberattack on U.S. Water Utilities: Results of Modeling the Worst-Case Scenario](https://novosti.ua/tech/ssha-smodelirovali-katastroficheskiy-stsenariy-kiberataki-na-vodokanaly) - Подтверждает фокус моделирования на водоканалах и неготовность инфраструктуры/страхового рынка; согласуется с описанием каскадного сбоя.

## ❓ FAQ

### Q: What exactly was modeled in the New York exercises?
**A:** The simulation reproduced a hypothetical July 2027, in which, against the backdrop of tensions around Taiwan, hackers simultaneously attack 5,000 U.S. water utilities, causing physical damage to equipment and ruptured pipes.

### Q: Who organized these exercises and why?
**A:** The organizer was Joshua Korman, a former CISA strategist. He deliberately created a condition of resource scarcity to test how insurance algorithms, which are usually the first to finance the remediation of cyberattacks, perform under conditions of a national emergency.

### Q: Which industries failed on the second day of the simulation?
**A:** Data centers shut down due to water-cooling failures, thousands of hospitals lost their HVAC systems, and the halt in water supply froze pharmaceutical production and caused an insulin shortage.

### Q: Is Volt Typhoon currently carrying out active destructive actions?
**A:** No, no active destructive actions have been recorded to date. However, experts confirm that the group has been entrenched in U.S. civilian and military networks for more than three years and retains the potential for large-scale destabilization.