Volt Typhoon Hack Inside a Small-Town Utility

Volt Typhoon breach at small-town U.S. utility highlights CI targeting

A Volt Typhoon hack inside a small-town Massachusetts utility offers a rare view of how state-linked attackers can quietly enter critical infrastructure networks. The intrusion came to light only after the FBI contacted the utility’s manager in 2023.

The case involved a utility run by Nick Lawler in Littleton, Massachusetts. According to the report, Chinese state-linked hackers had somehow established access to its network before federal investigators raised the alarm.

How the Volt Typhoon hack was discovered

Lawler reportedly received a call from the FBI one day in 2023. Officials told him that Chinese state hackers had found their way into the network of the small-town utility he managed.

This sequence is significant because the initial warning came from outside the organisation. The available account does not indicate that the utility first detected the attackers through an internal security alert, operational failure or disruption to services.

The report does not provide the exact date of the FBI call, when the intrusion began or how long the actors remained in the environment before discovery. It also does not identify the initial access route, affected accounts, compromised devices or individual software products.

No specific product names, hardware models, operating systems or software versions are disclosed. Consequently, the case should not be interpreted as evidence of a vulnerability affecting one named technology. It is an account of a network compromise associated with Volt Typhoon, rather than a conventional vulnerability disclosure with a patchable CVE.

Who was affected

The direct victim was a utility in Littleton, Massachusetts, managed by Nick Lawler. The source describes it as a small-town utility but does not state which services, systems or operational functions were accessed.

There is also no confirmation in the available report that customers lost access to utility services, that operational technology was manipulated or that physical equipment was damaged. The central fact is that an actor linked by US officials to China was present inside the utility’s network.

The case is being revisited as US officials warn that Iran-linked hackers are targeting water utilities across the country. Those warnings concern a different alleged threat source, and the report does not claim that the Iranian activity formed part of the Volt Typhoon hack.

How the Volt Typhoon hack could remain hidden

The incident illustrates the threat posed by living-off-the-land techniques. Rather than relying entirely on conspicuous malware, an intruder using this approach can exploit legitimate tools, built-in system functions and valid credentials already present in an environment.

Normal administrative capabilities may be used to inspect systems, move between devices, execute commands or maintain access. Because administrators and automated processes use many of the same functions, malicious activity can blend into routine network traffic and system records.

This does not establish which commands or tools were used in Littleton. The published account does not include forensic evidence, indicators of compromise or a technical breakdown of attacker activity. It nevertheless places the case within the broader concern about stealthy access and pre-positioning against critical infrastructure.

Pre-positioning rather than immediate disruption

Pre-positioning means establishing access that could potentially be used later. The immediate objective may be persistence, reconnaissance and an understanding of the target’s network, rather than theft, encryption or visible service disruption.

In a utility environment, this creates uncertainty about what an attacker has seen and which routes might lead towards more sensitive systems. Access to an ordinary business network can also matter if identity services, remote administration tools, backup infrastructure or supplier connections cross security boundaries.

The report does not say that Volt Typhoon reached operational control systems at the Littleton utility. It also does not report any command to interrupt services. Distinguishing confirmed network access from unverified operational impact is essential when assessing the incident.

Timeline and current Volt Typhoon hack status

The publicly available timeline is limited. The confirmed sequence described by the source is:

  • Before the FBI notification, Chinese state-linked actors had obtained access to the utility’s network.
  • On an unspecified day in 2023, the FBI contacted Nick Lawler and informed him of the intrusion.
  • On 8 September 2026, the report revisited the incident while discussing current US warnings about separate Iran-linked targeting of water utilities.

The source does not state when investigators first observed the actors, whether access was removed immediately after the call or when remediation was completed. It also provides no evidence that Volt Typhoon remains inside the Littleton utility’s environment as of 8 September 2026.

Similarly, the report does not confirm a new Volt Typhoon campaign beginning on the publication date. Its current relevance comes from renewed attention to state-linked targeting of utilities, not from a disclosed recurrence at the same organisation.

No patches, vendor advisories or affected-version lists accompany the report. Organisations should therefore avoid treating this as a single-product incident. The practical detection challenge is to identify suspicious use of legitimate access and administrative functions across a network.

Why the Massachusetts utility intrusion matters

The Volt Typhoon hack demonstrates that a relatively small utility can attract the attention of a sophisticated state-linked actor. Critical infrastructure risk is not confined to major national operators or the largest metropolitan providers.

The FBI notification also highlights the visibility gap that stealthy activity can create. If attackers use valid credentials and familiar tools, an organisation may not recognise the intrusion without intelligence from government agencies, technology providers or external monitoring partners.

Although the incident occurred in the United States, its lessons are relevant to UK utilities and organisations in their supply chains. Smaller operators, managed service providers and technology suppliers may hold trusted connections that increase the wider value of an otherwise modest target.

Actions tied to the Volt Typhoon hack

Utilities and connected suppliers should focus on finding the types of quiet, legitimate-looking activity illustrated by this case. Priority actions include:

  • Review remote access, administrative accounts and service accounts for unexplained use, unusual locations or access outside expected hours.
  • Check whether business systems, operational environments and supplier connections are separated by enforced controls rather than assumed boundaries.
  • Retain and centralise authentication, endpoint and network logs so investigators can reconstruct activity that predates an external warning.
  • Establish a process for rapidly validating and escalating notifications from government agencies and trusted security partners.
  • Investigate unusual use of built-in administration tools, even when antivirus systems report no malware.

These measures address the specific visibility and persistence issues raised by the incident. They are particularly important where a compromise could remain operationally quiet while preserving access for possible future use.

Originally reported by play.prx.org.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins
Category
Data Breaches
Published
Sep 8 - 2026
Post Tags
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call