iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The joint advisory published on February 7, 2024, reported confirmed Volt Typhoon access to IT networks at U.S. critical-infrastructure organizations and assessed with high confidence that the actors were positioning themselves for possible disruption of operational technology. It did not report widespread operational-technology disruption. For operators, the priorities are to secure exposed appliances, strengthen authentication, centralize logging, and hunt for suspicious use of legitimate accounts and administrative tools.
What the alert says—and when it was issued
The advisory, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A), was initially published on February 7, 2024. CISA led it with the NSA, FBI, other U.S. agencies, and Five Eyes cyber partners. It is a 2024 alert, not evidence by itself of a newly issued warning in 2026.
U.S. agencies said they had confirmed Volt Typhoon compromises in the IT networks of communications, energy, transportation, and water and wastewater organizations. The affected organizations were in continental and non-continental U.S. locations, including Guam. Some were smaller service providers with limited cybersecurity capability.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The agencies assessed with high confidence that Volt Typhoon was pre-positioning in IT networks to enable potential disruption of operational technology (OT)—the systems that monitor or control physical processes. That is an assessment of purpose and possible future effects, distinct from the confirmed IT compromises. The advisory did not document widespread OT disruption.
How Volt Typhoon operated in the reported compromises
The advisory describes activity designed to gain access, move through networks, and blend in with ordinary administration rather than rely only on conspicuous malware.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
- Finding a way in: The actors conducted extensive reconnaissance and exploited known or zero-day vulnerabilities in internet-facing network appliances, including routers, VPNs, and firewalls.
- Using valid access: They acquired credentials and used valid administrator accounts for lateral movement between systems.
- Blending into normal operations: They relied on native system and network tools, a “living off the land” approach that can make malicious activity harder to distinguish from legitimate administration.
- Learning the environment: The agencies said the actors gathered information about network architecture, security measures, normal behavior, and key IT staff. The advisory also describes Active Directory data extraction and attempts to access OT assets.
- Reducing visibility: The actors selectively deleted logs, complicating investigation.
CISA, NSA, and FBI reported indicators that actors had maintained access and footholds in some victim IT environments for at least five years. That observation applies to some environments; it does not establish a typical compromise duration or how many victims experienced access that long.
What critical-infrastructure operators should do
The advisory’s defensive guidance emphasizes reducing exposed entry points, strengthening account security, and preserving evidence that supports detection and response.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
- Patch exposed systems. Prioritize internet-facing systems and critical vulnerabilities in appliances known to be exploited by Volt Typhoon, including relevant routers, VPNs, and firewalls.
- Require phishing-resistant MFA. Apply phishing-resistant multifactor authentication to protect access to accounts and services, especially privileged access.
- Enable and centralize logs. Turn on application, access, and security logging, and store logs centrally so an intruder cannot erase every useful record by accessing an individual system.
- Hunt using the advisory’s technical guidance. Look for suspicious account behavior, lateral movement, use of administrative tools, exposed-appliance compromise, and signs of log tampering. Interpret findings in the context of how your organization’s IT and OT environments are normally administered.
- Use the incident-response recommendations if you find activity. Follow the advisory’s response guidance and report incidents to the relevant agencies.
Why malware-only detection is not enough
An attacker using a legitimate administrator account and built-in tools may produce activity that resembles routine IT work. A search for known malware alone can therefore miss important signs of access. Detection and investigation should also consider which accounts are being used, whether their activity fits their usual roles, how access moves between systems, and whether expected logs remain intact.
Network appliances deserve attention alongside endpoints: they may be exposed to the internet, and the advisory describes exploitation of these devices as an access method. Response decisions should account for the organization’s IT and OT dependencies; abrupt changes to systems connected to physical operations can have consequences beyond the IT network. The advisory supports a combination of patching, phishing-resistant MFA, centralized logging, hunting, and incident response—not reliance on a single product.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
What the agencies said about the threat
The joint advisory states: “Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations.” This is the assessment of the U.S. authoring agencies, not a quotation attributed to an individual speaker.
In the NSA’s February 7, 2024 announcement, NSA Director of Cybersecurity and Deputy National Manager for National Security Systems Rob Joyce said: “This is something we have been addressing for a long time.”
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
What the alert does not establish
The reviewed official material does not provide a population-level breach rate, a sector-by-sector victim count, or a comparable statistic for estimating an individual organization’s probability of compromise. The report of footholds lasting at least five years concerns some victim environments, not a general average. The advisory describes confirmed IT compromises and attempted OT access alongside an assessment of possible future disruption; those facts should not be recast as proof that widespread OT disruption already occurred.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

