
Major Cyber Incident: Volt Typhoon
Other incident names: VANGUARD PANDA, BRONZE SILHOUETTE, Redfly, Insidious Taurus, Dev-0391, Storm-0391, UNC3236, or VOLTZITE
- 21.09.2026
- Shelley, Callahan; Bamber, Louis
- EN
About Volt Typhoon
The Director of the United States Federal Bureau of Investigation (FBI), Christopher Wray, once linked it to “the defining threat of our generation:” the Chinese state-sponsored hacking group Volt Typhoon gained access to a variety of critical infrastructure organisations on Guam and the US mainland beginning in mid-2021. A technical report from Microsoft, published alongside a Joint Cybersecurity Advisory by the Five Eyes intelligence alliance on 24 May 2023, concluded with medium confidence that the group intended to build capabilities that could disrupt critical communications infrastructure between the United States and Asia in future crises or conflicts. The affected organisations are active in the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors.
Timeframe
Mid-2021 to present
Incident Type
Data Theft, Hijacking with Misuse
Initiator
Chinese state-sponsored hacking group Volt Typhoon
Affected Target
Government/Ministries, Critical Infrastructure (Energy, Water, Transportation, Telecommunications) in Guam and the United States
More Major Cyber Incidents (MaCIs)
- Research and Analysis


