
Major Cyber Incident: Volt Typhoon
Other incident names: VANGUARD PANDA, BRONZE SILHOUETTE, Redfly, Insidious Taurus, Dev-0391, Storm-0391, UNC3236, or VOLTZITE
- 21.09.2026
- Shelley, Callahan; Bamber, Louis
- EN
About Volt Typhoon
The Director of the United States Federal Bureau of Investigation (FBI), Christopher Wray,
once linked it to “the defining threat of our generation:” the Chinese state-sponsored
hacking group Volt Typhoon gained access to a variety of critical infrastructure
organisations on Guam and the US mainland beginning in mid-2021. A technical report
from Microsoft, published alongside a Joint Cybersecurity Advisory by the Five Eyes
intelligence alliance on 24 May 2023, concluded with medium confidence that the group
intended to build capabilities that could disrupt critical communications infrastructure
between the United States and Asia in future crises or conflicts. The affected
organisations are active in the communications, manufacturing, utility, transportation,
construction, maritime, government, information technology, and education sectors.
Timeframe
Mid-2021 — present
Incident Type
Data Theft, Hijacking with Misuse
Initiator
Chinese state–sponsored group „Volt Typhoon„
Affected Target
Government/Ministries, Critical Infrastructure (Energy, Water, Transportation, Telecommunications) in Guam and the United States
More Major Cyber Incidents (MaCIs)
- Research and Analysis



