Signal The Escalating Cyber Risk Landscape / CISA at 40%
Summary
On 7 February 2024, CISA, the NSA and the FBI, joined by Five Eyes partners, released a joint advisory assessing that PRC state-sponsored actors, tracked as Volt Typhoon, were pre-positioning on IT networks in the communications, energy, transportation and water/wastewater sectors — including in Guam — to enable disruptive or destructive attacks in the event of a major crisis or conflict with the United States. The agencies determined the group's targeting pattern was inconsistent with traditional espionage, assessing with high confidence that Volt Typhoon aims to enable lateral movement into operational-technology assets. Guam's exposure first surfaced in 2023 when Microsoft formally identified and linked the group to campaigns there, a finding later supported by NSA, FBI and CISA; separately, CISA has stated Volt Typhoon had access to some US targets for as long as five years, with early activity dating to at least 2021. The group is likely affiliated with the PLA or China's Ministry of State Security. In response, CISA's Joint Cyber Defense Collaborative has become a central hub for public-private threat-intelligence sharing, while ODNI has reclassified the activity as 'strategic pre-positioning' and CISA was operating with 60% of its staff furloughed during a DHS shutdown at the time of the reassessment.
Classification
Evidence 1
- EclecticIQ / SecurityBoulevard 2026-06-11 accessed 2026-07-28T13:59:36+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-1726e79280c8