Warnings of a coordinated cyberattack on America’s critical infrastructure have intensified, with experts fearing that power, water, transport and communications systems could be disrupted simultaneously by hostile states and their proxies.
Such an assault could combine concealed malware with physical attacks, including drones targeting electrical equipment. The consequences could spread rapidly: blackouts would affect hospitals, payments and communications, while water and sewage pumps stopped functioning.
Within days, officials could face depleted emergency supplies, emptying shops and increasingly desperate communities. Some security specialists have described the prospect as a modern “cyber 9/11”, although the threat would be less visible than the attacks of 25 years ago.
Annie Fixler, a cyber expert at the Foundation for Defense of Democracies, said the repeated warnings could no longer be ignored. She identified major cities including New York and Los Angeles as particularly exposed to attacks on power and water supplies.
“Can you ship in enough bottles of water for a large city by road? Probably not,” she said.
Fixler warned that a failure to remove wastewater could make a city uninhabitable within hours. Hospitals, she said, could also shut down within days if essential services were disrupted.
Warnings over China-linked infrastructure attacks
Fixler and other analysts believe China presents the most serious long-term danger, particularly if Beijing were to attack infrastructure before a military operation against Taiwan. Research by her colleagues argues that China could potentially draw on hackers from Russia, Iran and North Korea.
Investigators have already documented a series of attacks on American water and wastewater utilities. During July and August, hackers targeted the small computer systems used to control pumps and pressure valves in at least a dozen states.
Minnesota was the worst affected, with more than 30 municipal water systems compromised over several weeks. In Braham, the town’s entire municipal water supply was briefly taken offline.
US intelligence agencies and federal investigators strongly suspect Iran was behind those incidents, which experts said offered Tehran a relatively cheap way to retaliate against Washington.
China, meanwhile, has been accused of infiltrating electricity, water and transport networks through a hacking operation known as Volt Typhoon. Rather than deploying conspicuous viruses, the group is said to have stolen passwords and adopted the appearance of legitimate network administrators.
Microsoft and the Cybersecurity and Infrastructure Security Agency publicly identified the group. Kevin Mandia, a leading cyber-security expert, told Congress that many of its American targets “won’t even know they’re impacted”.
Beijing has denied involvement in infrastructure hacking campaigns, describing the accusations as an unfounded and politically motivated Western conspiracy.
Analysts fear the hidden access could eventually be used in an “Everything, Everywhere, All at Once” assault, disrupting systems across the country at the same time.
Power grid vulnerability
America’s power network has already demonstrated how attacks on a small number of sites can affect large numbers of people. In 2013, snipers fired more than 100 rounds at a substation in California, damaging 17 transformers and narrowly avoiding a blackout in Silicon Valley.
In 2022, two substations in North Carolina were attacked with high-powered rifles, leaving 45,000 residents in freezing darkness for several days.
Jon Wellinghoff, a former chairman of the Federal Energy Regulatory Commission, has warned that the electricity grid could be vulnerable to a domino effect. He said saboteurs would need to disable only nine critical high-voltage substations to cause a cascading nationwide blackout lasting as long as 18 months.
“It’s probably something that a bunch of 12-year-olds with the internet could do pretty easily,” Wellinghoff told The New York Times in August.
Cyberattacks have also caused major disruption without any physical damage. Russian ransomware hackers shut down the Colonial Pipeline in May 2021, affecting a 5,500-mile fuel network that supplied 45 per cent of the US East Coast’s fuel.
More than 10,000 petrol stations across the south-eastern United States ran dry before the operator paid a $4.4 million ransom in Bitcoin to regain control.
Fixler said America’s fragmented infrastructure left it especially exposed. The country has nearly 150,000 public water systems, many of them small organisations operating on limited budgets and unable to afford substantial security upgrades.
She added that regulators were not prepared for a co-ordinated campaign involving small drones attacking energy substations across the country.
Experts call for basic security measures
Former CISA director Jen Easterly has said the United States remains fundamentally unprepared for the attacks hackers could unleash. Experts argue that technology companies have spent decades prioritising speed and convenience over basic cyber-security protections.
That has left insecure software and connected equipment vulnerable to manipulation by foreign military and intelligence services. Fixler said executives in the water and power sectors were aware of weaknesses that had accumulated after years of putting off upgrades.
“There are the threats that really keep people awake at night because they know they have vulnerabilities that they don’t know about,” she said.
Warnings have also focused on the growing capabilities provided by artificial intelligence. The FBI, National Security Agency and CISA have documented how the technology is increasing the ability of malicious actors to carry out digital attacks.
A coalition of 116 technology, cyber-security and financial companies, led by OpenAI, warned in August that organisations had only a narrow window of several months to strengthen their defences before autonomous threats could outpace existing human security measures.
The US Justice Department and FBI have stepped up action against foreign state-backed hacking networks. In late August, court documents were unsealed against QTFY, a Chinese state-linked group accused of attacking NASA, the Federal Reserve and the Department of Energy.
President Donald Trump has also signed executive actions addressing technology threats, including an emergency declaration targeting cyber-security backdoors in the US power grid.
Fixler said some of the most effective protections were straightforward, including removing internet connections where they were unnecessary and replacing default or missing passwords.
“We’ve left systems connected to the internet with default passwords or no passwords in place,” she said. “Let’s fix those things, and then we can worry about the apocalypse.”
