Recent Iranian cyber operations against American water utilities and a British power plant have made headlines, but a new Lawfare article argues these attacks were relatively unsophisticated, relying on default passwords, unpatched systems, and exposed internet connections. The more consequential threat, it says, comes from China, whose Volt Typhoon hackers maintained dormant access to U.S. critical infrastructure for at least five years before being discovered in 2023.
The article, drawn from a Council on Foreign Relations report by Adam Segal and Rush Doshi, acknowledges that the Trump administration has taken steps such as an executive order promoting AI-enabled defenses and a Texas-led pilot called Project Watershed 250. But it argues these efforts will likely fall short given the scale of the problem, particularly the lack of shared visibility across cloud providers, telecoms, and private security firms into adversary campaigns.
The authors recommend that Congress impose information-sharing requirements and that the United States adopt a strategy combining disruption of Chinese operations with political, diplomatic, and economic pressure. They also emphasize fixing systemic issues: insecure default settings in hardware, under-resourced utilities that fail to implement multifactor authentication and network segmentation, and supply chain risks from shared products and services.