Free tools Windows power users keep installed
One-click scans. No signup required.
U.S. agencies reported that Volt Typhoon actors collected and staged files containing operational technology (OT) diagrams and documentation, including material related to SCADA systems, relays, and switchgear. That is evidence of interest in OT-related information—not proof that the actors stole live process telemetry, changed control settings, or disrupted industrial operations.
What OT information did Volt Typhoon collect?
A February 7, 2024 joint advisory from CISA, NSA, FBI, and partner agencies describes files with diagrams and documentation related to OT equipment, including supervisory control and data acquisition (SCADA) systems, relays, and switchgear. The advisory says the actors staged files for exfiltration. It does not publish a total volume of data or establish that the collected files included live operating data. Read the joint advisory, AA24-038A.
These documents can be sensitive because they may reveal how equipment and processes are arranged. But the reported file collection should not be conflated with access to, or manipulation of, the equipment itself.
What was observed—and what agencies assessed
The public reporting distinguishes activity described in the advisory from the agencies’ assessment of its purpose:
#1 Best Overall
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
| Category | What the sources say |
|---|---|
| Reported activity | Actors accessed IT networks, collected OT-related diagrams and documentation, and staged files for exfiltration. The sources do not establish an OT outage or altered control settings. CISA advisory. |
| Agency assessment | U.S. agencies assessed that Volt Typhoon was pre-positioning in IT networks to enable possible disruptive or destructive action against critical infrastructure during a major crisis or conflict with the United States. This is a warning about potential future action, not a report that such an attack occurred. NSA summary. |
Did Volt Typhoon access or control SCADA systems?
The cited public accounts report collection of documentation related to SCADA and other OT equipment, alongside activity in IT networks. They do not establish that Volt Typhoon compromised SCADA controllers, manipulated industrial controls, or disrupted OT functions in the described activity. NSA said that access to OT systems could enable disruption, but that possibility is not evidence that disruption took place.
Which organizations were in scope?
The NSA’s February 7, 2024 summary names communications, energy, transportation, water, and wastewater organizations in the United States and its territories. It does not provide a complete public list of affected organizations, so the public reporting does not support attributing the activity to a specific utility or facility. The NSA also said that in some cases the actors had been inside IT networks for years; that duration applies to some cases, not necessarily every organization. NSA’s sector and access-duration summary.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the KV Botnet disruption means
In a separate action, the Department of Justice said a court-authorized operation in December 2023 disrupted the KV Botnet, a network of compromised small-office and home-office (SOHO) routers used to conceal further hacking. DOJ’s January 31, 2024 account said hundreds of U.S.-based routers were affected and that most botnet routers were unsupported end-of-life Cisco and Netgear devices. It urged owners to remove and replace end-of-life SOHO routers. The operation addressed that botnet; DOJ did not describe it as ending Volt Typhoon’s broader activity. DOJ’s account of the disruption.
Quick Recap
Rank #4
What infrastructure operators can do
CISA, NSA, FBI, and partners published leader-focused guidance on actions to prioritize in response to Volt Typhoon risk. The agencies describe living-off-the-land techniques and pre-positioning on IT networks; operators should use the official guidance for technical recommendations rather than infer a complete defense checklist from the public summaries. CISA’s announcement of the leader fact sheet.
- Review router lifecycle. Replace unsupported end-of-life SOHO routers, following DOJ’s recommendation. This reduces exposure to risks associated with unsupported devices; it is not a substitute for an OT security assessment or broader incident response.
- Use the agency guidance for the technical response. Consult the joint fact sheet and advisory for the actions agencies recommend to infrastructure leaders and defenders.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

