Key Judgments
- [CONFIRMED] – The US electrical grid comprises more than 7,300 power plants and nearly 160,000 miles of high-voltage transmission lines, operated by more than 3,000 distinct utilities and cooperatives – a fragmentation pattern structurally similar to the water sector examined in this series’ prior installment, with the same consequence: security investment and incident-response capability vary enormously between well-resourced metropolitan utilities and small rural cooperatives.
- [CONFIRMED] – Physical attacks and threats against grid infrastructure have risen sharply and are independently tracked by two separate federal bodies: the Department of Energy recorded at least 175 physical attacks or threats in 2023, following a 71% increase from 2021 to 2022; the North American Electric Reliability Corporation separately recorded 101 confirmed physical security incidents in 2022, the highest since NERC began tracking in 2012.
- [CONFIRMED] – A China-linked advanced persistent threat group tracked as Volt Typhoon has maintained a documented, multi-year pre-positioning presence inside US electric utility operational technology networks, including nearly a full year of unauthorized access (February-November 2024) inside a Massachusetts public power utility’s OT network. As of 2026, no US agency has confirmed complete eradication of Volt Typhoon’s persistence from critical infrastructure networks nationally.
- [CONFIRMED] – In August 2026, the Department of Energy and CISA issued a joint assessment warning that the grid’s rapid digitization – internet-connected solar inverters, residential battery storage, and EV chargers now numbering in the millions – has created a novel attack surface distinct from traditional substation or transmission targeting: the theoretical ability for an attacker to trigger simultaneous, coordinated shutoff or surge across a large number of internet-connected residential devices, producing physical grid instability from the demand side rather than the generation or transmission side.
- [ASSESSED] – CommandEleven Intelligence assesses the grid faces two analytically distinct threat categories requiring different responses: domestic accelerationist physical and drone-based attacks on substations, examined in this series’ companion US Domestic Threat Landscape series, and nation-state cyber pre-positioning by actors like Volt Typhoon, whose documented objective – per FBI Director Christopher Wray’s own public characterization – is prepositioning for disruption during a future geopolitical crisis, not current sabotage or espionage in the conventional sense.
The Threat Surface: Scale and Fragmentation

The grid’s scale is itself a security challenge: more than 7,300 power plants, nearly 160,000 miles of high-voltage transmission line, and millions of miles of lower-voltage distribution infrastructure, operated by a fragmented base of over 3,000 distinct utilities and cooperatives. As with the water sector examined in this series’ prior installment, this fragmentation means security posture varies enormously – large investor-owned utilities serving major metropolitan areas typically maintain dedicated security operations centers and compliance staff, while small rural cooperatives frequently lack the budget for equivalent capability, even though both operate infrastructure whose failure carries comparable downstream consequences for the communities they serve.
Physical Attacks: A Rising, Confirmed Trend
Unlike water infrastructure, where this series’ prior installment found risk concentrated almost entirely in a single cyber vector, grid security faces a well-documented and rising physical threat alongside its cyber exposure. Two independent federal tracking sources confirm the trend: the Department of Energy recorded at least 175 physical attacks or threats against grid infrastructure in 2023, following a 71% increase between 2021 and 2022 (from roughly 95 to 163 documented events); NERC separately recorded 101 confirmed physical security incidents in 2022, the highest total since its tracking began in 2012.
The landmark case remains unsolved: on April 16, 2013, unidentified attackers fired approximately 120 rifle rounds into Pacific Gas & Electric’s Metcalf transmission substation near San Jose, California, from roughly 60 yards outside the perimeter fence, damaging 17 high-voltage transformers with precision shots targeting cooling systems and insulators – an attack sophisticated enough that it has shaped federal grid-security doctrine for over a decade without a confirmed attribution ever being made public. More recently, the December 2022 Moore County, North Carolina substation attack – gunfire that knocked out power to tens of thousands of residents for days – prompted officials to publicly acknowledge concern that violent extremist actors specifically view the grid as a symbolic, high-disruption target. This series’ companion Domestic Threat Landscape examined this pattern in greater depth, including the Brandon Russell Baltimore-area energy facility conspiracy and the Skyler Philippi Nashville grid drone attack, both tied to accelerationist ideology; this dossier treats that material as established and does not repeat it here, referring readers to that installment for the domestic-extremism dimension specifically.
Volt Typhoon: The Pre-Positioning Threat
The grid’s cyber threat picture is dominated by a single, well-documented, and unresolved actor: Volt Typhoon, a China Ministry of State Security-linked advanced persistent threat group active since at least 2021. Volt Typhoon’s tactics are distinctive and specifically difficult to counter – “living off the land” techniques that exploit legitimate administrative tools and valid credentials rather than deploying detectable malware, allowing the group to blend into normal network activity for extended periods. Dragos researchers uncovered the clearest documented case: Volt Typhoon maintained unauthorized access to the operational technology network of Littleton Electric Light and Water Departments, a small Massachusetts public power utility, for nearly a full year, from February to November 2024, before the FBI notified the utility directly.
FBI Director Christopher Wray’s own public characterization of Volt Typhoon’s objective is the clearest available statement of the threat’s actual nature: Chinese state-sponsored hackers are “targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict.” This distinguishes Volt Typhoon analytically from more familiar cybercriminal ransomware actors (the 2021 Colonial Pipeline attack being the most-cited comparison): Volt Typhoon’s assessed objective is not financial extortion but the establishment of a standing capability to disrupt US infrastructure during a future crisis – most directly discussed in the context of a potential conflict over Taiwan, where degrading domestic US infrastructure could complicate military logistics and divert political attention. As of 2026, following the January 2024 disruption of an associated botnet, threat-intelligence firms continue to track renewed Volt Typhoon-linked activity (Dragos’s designation “Voltzite”) against US electric utilities, and no agency has confirmed the group’s complete removal from affected networks nationally.
- [DATA DEFICIT] – This dossier does not have visibility into the full scope of Volt Typhoon’s current access across the US grid. The Littleton case is the most thoroughly documented public example; CISA’s own assessment characterizes discovered intrusions as likely “the tip of the iceberg,” a characterization this dossier reports as the government’s own stated position rather than an independently verified extent.
The New Digital Attack Surface
An August 2026 joint DOE/CISA assessment identifies a threat vector distinct from both the physical attacks in Section II and Volt Typhoon’s OT pre-positioning in Section III: the grid’s own rapid digitization. Millions of solar inverters, residential battery storage systems, and EV chargers now communicate continuously over the internet to help balance power flows in real time – infrastructure that did not exist at meaningful scale a decade ago, and which the DOE/CISA assessment characterizes as creating an unprecedented new vulnerability. The specific scenario officials have flagged: a coordinated attack commanding a large number of these internet-connected residential devices to shut off or surge simultaneously, creating demand-side physical instability capable of cascading into a multi-state blackout – a fundamentally different attack pattern than a substation shooting or a traditional OT intrusion, exploiting the grid’s own modernization rather than its aging infrastructure.
The Government Response
Federal response operates across several tracks without a single unifying framework. NERC’s Critical Infrastructure Protection (CIP) standards set mandatory cybersecurity and physical security requirements for bulk power system operators, with compliance audited and enforceable through financial penalties – a meaningfully stronger regulatory tool than exists in the water sector’s largely voluntary framework. CISA and the FBI have issued multiple joint advisories specifically naming Volt Typhoon and detailing its tactics (including AA24-038A) to help network defenders hunt for the group’s specific technique signatures. The August 2026 DOE/CISA assessment on distributed-device attack surface signals the government’s response is beginning to extend beyond traditional grid-operator security toward device-manufacturer standards for the solar, battery, and EV-charging equipment increasingly integrated into the grid – though this dossier’s sourcing does not indicate binding requirements have yet been finalized for that category specifically.
Assessment: Two Threats, One Sector
[ASSESSED] – This dossier assesses the grid genuinely faces two analytically separate threat categories that happen to share a target. Domestic accelerationist actors pursue physical and drone-based attacks on substations for symbolic, cost-imposing disruption – examined in depth in this series’ companion Domestic Threat Landscape series. Volt Typhoon and similar state-linked actors pursue patient, long-duration cyber pre-positioning for a contingency that may never be activated, but whose existence alone constitutes a standing strategic vulnerability regardless of whether it is ever triggered. Grid security policy that treats these as a single undifferentiated “grid threat” risks misallocating resources between a NERC CIP compliance framework built for one problem and a domestic-extremism intelligence-sharing framework built for the other, when both require sustained, separate investment simultaneously.
Series Continuity
The next installment in this series examines natural gas infrastructure – a sector whose pipeline network interacts directly with the electrical grid examined here, given natural gas’s role generating a substantial share of US electricity, while facing its own distinct physical and cyber vulnerability profile.
Sourcing Base (Confidence-Tiered, with Links)
CONFIRMED – Primary/Official Record & Direct Reporting:
- CISA, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure” (AA24-038A)
- Daily Security Review, “Volt Typhoon Energy Grid Cyberattack Exposes US Infrastructure Vulnerabilities” (Littleton, MA case detail, Dragos research)
- Grokipedia, “Electrical grid security in the United States” (DOE/NERC physical attack statistics, Metcalf attack detail)
- Wikipedia, “Moore County substation attack”
- Energy Solutions, “US Power Grid Cyber Risk 2026” (August 2026 DOE/CISA distributed-device assessment)
- CommandEleven Intelligence, US Domestic Threat Landscape series, Part I (Brandon Russell, Skyler Philippi cases)
ASSESSED – Credible Secondary Reporting:
- DeepStrike, “Volt Typhoon Explained: Tactics, Targets & 2026 Threat“
- CybelAngel, “Volt Typhoon 2026: Still Active in US Critical Infrastructure“
- AMAROK, “Power Grid Security: Physical Threats and Defenses“
- ATCorp, “Cybersecurity, Volt Typhoon, and the Grid”
Excluded from this dossier: Specific technical detail on Volt Typhoon’s living-off-the-land methodology or specific detection-evasion techniques beyond what is necessary to establish the general threat pattern. This dossier treats such detail as more useful to replicating the technique than to public understanding of the threat.
Protecting Your Household from Grid Disruption: A $500 Baseline
This section is general emergency-preparedness guidance, modeled on standard FEMA and Ready.gov household-resilience recommendations. It is not specific to any threat actor or incident, and does not depend on or respond to classified or sensitive information.
- Battery-based backup power (≈$150-250): A portable power station (not a gas generator, which carries carbon monoxide risk if used indoors or improperly ventilated) sized to run a refrigerator, phone chargers, and basic lighting for 12-24 hours covers the large majority of documented outage durations from both physical-attack and weather-related events.
- Surge protection (≈$40-75): A whole-home or major-appliance surge protector reduces damage risk from the kind of grid instability events described in Section IV, where demand-side attacks are designed to create voltage irregularities rather than simple outages.
- Manual-backup lighting and communication (≈$50-100): Battery or hand-crank flashlights and a battery/crank-powered NOAA weather radio, since prolonged outages typically also affect cell tower backup power within 24-72 hours.
- A basic non-perishable food supply (≈$75-100): FEMA’s standard three-day household food supply recommendation applies equally to grid-outage scenarios as to any other emergency; this overlaps directly with general household emergency preparedness rather than requiring grid-specific purchases.
- Know your utility’s outage-reporting and restoration-priority system: Most utilities publish outage maps and estimated restoration times online; knowing how to access this in advance (bookmarked, or saved for offline access) is a zero-cost preparedness step.
CommandEleven Intelligence is not a licensed emergency-preparedness authority; this guidance reflects publicly available FEMA/Ready.gov recommendations and general good practice, not a CommandEleven Intelligence-specific assessment of any household’s individual risk.