Skip to content

Major Cyber Incident: Volt Typhoon

Other incident names: VANGUARD PANDA, BRONZE SILHOUETTE, Redfly, Insidious Taurus, Dev-0391, Storm-0391, UNC3236, or VOLTZITE

About Volt Typhoon

The Director of the United States Federal Bureau of Investigation (FBI), Christopher Wray, once linked it to “the defining threat of our generation:” the Chinese state-sponsored hacking group Volt Typhoon gained access to a variety of critical infrastructure organisations on Guam and the US mainland beginning in mid-2021. A technical report from Microsoft, published alongside a Joint Cybersecurity Advisory by the Five Eyes intelligence alliance on 24 May 2023, concluded with medium confidence that the group intended to build capabilities that could disrupt critical communications infrastructure between the United States and Asia in future crises or conflicts. The affected organisations are active in the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors.

Timeframe

Mid-2021 to present

Incident Type

Data Theft, Hijacking with Misuse

Initiator

Chinese state-sponsored hacking group Volt Typhoon

Affected Target

Government/Ministries, Critical Infrastructure (Energy, Water, Transportation, Telecommunications) in Guam and the United States

More Major Cyber Incidents (MaCIs)

  • Research and Analysis
Major Cyber Incident: Volt Typhoon

21.09.2026
In this MaCI, Louis Bamber and Callahan Shelley analyse the case of Volt Typhoon: a long-running espionage campaign targeting the US mainland and Guam, which was assessed to be prepositioning to disrupt vital services in the event of conflict over Taiwan.
Major Cyber Incident: SolarWinds

26 September 2024
In this detailed analysis, Linda Liang and Mika Kerttunen discuss the hack on SolarWinds, a costly supply chain attack by a Russian state-integrated hacking group which led to dozens of entities being compromised worldwide.
Major Cyber Incident: KA-SAT 9A

4 October 2023
In this detailed analysis, Mika Kerttunen, Kim Schuck, and Jonas Hemmelskamp discuss the hack on the KA-SAT networks in Ukraine and Western Europe in the initial stages of the Russian war against Ukraine.

Welcome to our Cyber Incident Dashboard!

For best results, please view on a desktop device.