A secret war game simulating a large-scale Chinese cyberattack on U.S. water utilities exposed the cascading, catastrophic effects that such an event would have on critical infrastructure and supply chains. According to WIRED, the scenario was set in April 2027, with hackers disrupting 5,000 water utilities across the country. The exercise, organized by former Cybersecurity and Infrastructure Security Agency (CISA) strategist Joshua Corman, involved a few dozen insurance executives divided into six teams.
The Escalating Crisis
Within 24 hours of in-game time, second-order effects began to cascade. Food refrigeration systems failed at cold storage warehouses, water-dependent drug and chemical manufacturing bottlenecked leading to insulin shortages, data center cooling systems failed causing cloud service outages, and 2,000 hospitals lost water, hampering patient care and forcing evacuations as HVAC systems shut down in July heat. Worse, the hackers triggered physical destruction of water mains, causing burst pipes that disabled water pressure for entire downstream areas. Corman warned participants: "You ready? It's about to get harder. I'm going to share a few things, and it's going to hurt." To maintain realism, Corman denied restroom breaks: "There are no breaks in real incident response. If you have to go to the bathroom, go to the bathroom. But you might miss something vital."
Key Second-Order Effects
| Sector | Impact |
|---|---|
| Food supply | Refrigeration failure at cold storage warehouses |
| Pharmaceutical | Insulin shortages due to manufacturing bottlenecks |
| Technology | Cloud service outages from failed data center cooling |
| Healthcare | 2,000 hospitals without water; evacuations and HVAC shutdown |
| Civil infrastructure | Burst water mains causing loss of water pressure downstream |
The Attacker: Volt Typhoon
The attack scenario was rooted in real-world threats. In May 2023, Microsoft, the National Security Agency (NSA), and CISA announced the discovery of Volt Typhoon, a group of hackers working in service of the Chinese military. According to WIRED, the intruders had already broken into networks of critical infrastructure facilities across the continental United States and the territory of Guam, hitting targets from manufacturing to other sectors. The war game assumed the attack was carried out to hamper a U.S. response to a Chinese invasion of Taiwan.
Insurers Forced to Choose
The 15-minute decision round tasked insurance teams with allocating contracted cybersecurity incident responders and money to clients. They had to balance business relationships against minimizing overall harm, and consider whether to prioritize military facilities. Left unspoken was whether the catastrophe would bankrupt insurers or if they would invoke an "act of war" exclusion — a standard clause exempting carriers from liability during armed conflict — potentially making them the villains of the story.
Implications for Supply Chain and Critical Infrastructure
For enterprise technology leaders, the exercise underscores the fragility of interdependent systems. A single point of failure — water utilities — can trigger cascading breakdowns in food cold chains, drug manufacturing, and data center operations. The simulation highlights the need for robust cybersecurity, contingency planning, and insurance frameworks that cover state-backed attacks without triggering exclusion clauses. The fact that such attacks are already being pre-positioned by Volt Typhoon, as reported by Microsoft, NSA, and CISA in 2023, makes this not a hypothetical threat but an active risk.