A foreign adversary launches a coordinated assault on America’s critical infrastructure, planting stealthy malware to disrupt water and electricity networks while drones strike vital power equipment.
The consequences quickly spread. Blackouts knock out communications, payment systems and hospital services, while pumps stop transporting clean water and processing sewage. Supermarket shelves empty as supplies of food and medicine dwindle.
Within days, officials are confronted with a fast-moving emergency: infrastructure is failing, stockpiled supplies are running low and communities are becoming increasingly desperate.
Some now describe the scenario as a ‘cyber 9/11’—a long-feared threat receiving renewed attention 25 years after the September 11 attacks killed roughly 3,000 people in New York City, Washington DC and Pennsylvania.
In recent weeks, warnings have come from figures ranging from national security leaders to Silicon Valley’s most prominent artificial intelligence executives. They say the United States’ infrastructure is dangerously exposed to a coordinated attack capable of causing widespread, debilitating disruption.
Annie Fixler, a cybersecurity specialist at the Foundation for Defense of Democracies (FDD), told Our News Outlet that the “steady drumbeat” of increasingly serious warnings can no longer be dismissed.
Fixler considers major cities including New York and Los Angeles especially vulnerable to attacks targeting electricity and water networks. Such an assault, she said, could leave taps running dry within hours.
“Can you ship in enough bottled water for a large city by road? Probably not,” she said, offering a stark illustration of how quickly a critical infrastructure crisis could escalate.

Experts warn that the next 9/11 may be less visible than the attack on the World Trade Center 25 years ago, yet potentially more devastating

Chinese hackers have already placed “digital land mines” inside critical infrastructure across the US
“If you don’t have systems that remove wastewater, you can make a city uninhabitable in a matter of hours,” she warned, describing a threat few Americans have been forced to consider seriously.
Fixler believes China poses the most serious danger. She and other experts argue that Beijing is quietly positioning itself to disable US infrastructure ahead of a potential military operation to seize Taiwan, the self-governing island China claims as its territory.
Fresh research from her FDD colleagues, published under the title Axis of Aggressors, suggests Beijing could enlist hackers from Russia, Iran and North Korea to help pull it off.
Much of the groundwork has already been documented by investigators.
In July and August, a coordinated wave of cyber-physical attacks struck water and wastewater utilities across at least a dozen American states without warning.
Hackers targeted the small computers that control water pumps and pressure valves.
Minnesota was hit hardest, with more than 30 municipal water systems compromised by hackers in a matter of weeks.
In the small town of Braham, the entire municipal water supply was briefly knocked offline by the intruders.
US intelligence and federal investigators strongly suspect Iran is responsible, as retaliation for the conflict between Washington and Tehran that shows no signs of cooling down.
Cyber offers Tehran a cheap, asymmetric way to punch back at its mighty enemy, experts say.
Meanwhile, China has separately been exposed for covertly infecting America’s electricity, water and transport networks through a shadowy hacking group called Volt Typhoon.
Instead of using obvious computer viruses, these high-tech commandos steal passwords to blend in as normal network managers.
Traditional security systems are blind to the threat.

Within hours of an attack, sewage treatment plants would overflow, unleashing waterborne diseases into communities

Within days of an attack on power and transport networks, grocery store shelves would be empty

Saboteurs in 2022 used high-powered rifles to blast two Duke Energy substations in North Carolina, plunging 45,000 residents into freezing darkness for days
Analysts fear Beijing could ultimately trigger its hidden digital land mines in what is dubbed an ‘Everything, Everywhere, All at Once’ assault designed to paralyze the entire nation simultaneously.
The group was uncovered and publicly named by Microsoft alongside the Cybersecurity and Infrastructure Security Agency (CISA), sending shockwaves through Washington’s national security establishment.
In chilling testimony to Congress, Kevin Mandia, a top cybersecurity expert, warned that Volt Typhoon’s hackers were so stealthy that many of their American targets ‘won’t even know they’re impacted.’
Beijing has categorically denied involvement in infrastructure hacking campaigns, dismissing the accusations as an unfounded and politically motivated Western conspiracy.
Still, the devastating effectiveness of similar attacks has already been laid bare for the country to witness firsthand.
Russian ransomware hackers struck the Colonial Pipeline in May 2021, shutting down the massive 5,500-mile pipeline supplying 45 percent of the East Coast’s fuel supply for six agonizing days.
More than 10,000 gas stations across the Southeast ran dry, forcing the private operator to pay a $4.4 million ransom in Bitcoin to regain control.
Physical sabotage poses an equally terrifying threat, experts warn, and requires far less sophistication than a cyberattack does.
In April 2013, snipers fired more than 100 rounds into California’s Metcalf substation, destroying 17 transformers and narrowly avoiding a Silicon Valley blackout.
Nearly a decade later, saboteurs used high-powered rifles to blast two Duke Energy substations in North Carolina, plunging 45,000 residents into freezing darkness for days.
Jon Wellinghoff, a former chairman of the Federal Energy Regulatory Commission, warns that these attacks expose the grid as a fragile, domino-like system remarkably easy to topple.
Saboteurs need to only disable nine critical high-voltage substations to trigger a cascading nationwide blackout lasting up to 18 months, potentially causing societal collapse.
Identifying which substations to target is disturbingly simple, the veteran regulator turned whistleblower says.

Experts have warned that ransomware attacks can be more destructive than explosions

In a chilling omen of a future attack on power relays, San Francisco went dark during a grid disruption in December 2025
‘It’s probably something that a bunch of 12-year-olds with the internet could do pretty easily,’ he told The New York Times in August.
Wellinghoff is not the only one sounding the alarm about America’s crumbling digital defenses.
Jen Easterly, the US Army veteran who led CISA until last year, says the country remains fundamentally unprepared for what hackers could soon unleash.
For decades, technology vendors prioritized speed-to-market and consumer convenience over basic cybersecurity safeguards, experts say.
The result is inherently insecure, defective code forming a dangerous ‘soft underbelly’ exposed to foreign military manipulation.

Annie Fixler, a cyber expert at the Foundation for Defense of Democracies
The US is, of course, not alone in this regard. American allies such as Britain, Australia and Taiwan are also targeted.
But the US is seen as the primary threat for such actors as Iran and China, and is especially vulnerable due to its fragmented water districts and local power grids.
Fixler told Our News Outlet that water and power grid executives she speaks with are painfully aware of their vulnerabilities.
They know about them because they’ve spent decades penny-pinching, avoiding upgrades that seemed unnecessary on any given ordinary day.
‘There are the threats that really keep people awake at night because they know they have vulnerabilities that they don’t know about,’ Fixler said grimly.
America operates nearly 150,000 public water systems, and many are tiny and run on shoestring budgets, unequipped to fend off sophisticated attacks from Chinese state hackers.
Regulators, she added, remain unprepared for a coordinated wave of enemy operatives unleashing small drones against energy substations nationwide.
Worse still, she said, the public has grown so numb to constant AI warnings that genuine dangers are increasingly dismissed with a shrug and an eye roll.
‘It’s the fault of policy experts writ large. We don’t explain why it matters to the average person,’ said Fixler, who heads FDD’s Center on Cyber and Technology Innovation.
The threat will only intensify, according to the FBI, National Security Agency and CISA, which have jointly documented how artificial intelligence is turbocharging the capabilities of malicious digital attackers worldwide.

Annie Fixler, a cyber expert at the Foundation for Defense of Democracies, says hospitals could shut down within a few days
Major technology companies issued an urgent joint warning in August that time is rapidly running out to fortify global networks against sophisticated, AI-driven cyber threats.
A coalition of 116 major technology, cybersecurity and financial firms, led by OpenAI, warned that organizations have only a narrow ‘defenders’ window’ of mere months to act.
After that window closes, they cautioned, autonomous AI-driven cyber threats would swiftly outpace existing human security measures.
The Justice Department and FBI have dramatically accelerated offensive legal and technical action against foreign state-sponsored hacking networks in recent months.
Officials in late August unsealed court documents targeting QTFY, a Chinese state-linked group accused of digital raids on NASA, the Federal Reserve and the Department of Energy.
President Donald Trump has signed multiple executive actions on technology threats, including a sweeping August 2026 emergency declaration targeting cybersecurity backdoors buried inside the US power grid.
Experts insist today’s danger looks nothing like the threat that emerged 25 years ago, when Al Qaeda terrorists hijacked passenger planes and flew them into the Pentagon and World Trade Center.
Back then, Osama bin Laden commanded a band of radicalized militants operating out of Afghanistan, a world away from today’s alleged culprit.
Beijing, by contrast, is the planet’s manufacturing powerhouse, its second-largest economy, and an increasingly formidable top-tier military superpower.
Yet the parallels remain unmistakable, experts say, since both threats exploited glaring blind spots that American security chiefs failed to see coming in time.

Experts believe the danger posed in 2026 is very different to the Al-Qaeda threat around 9/11
Al Qaeda realized hijacked planes could become deadly missiles; today’s adversaries have realized the nation’s water and power systems are society’s overlooked soft targets.
Just as locking cockpit doors might have derailed the September 11 hijackers, Fixler insists simple fixes today could dramatically shrink America’s exposure to a modern cyber 9/11.
‘We’ve left systems connected to the internet with default passwords or no passwords in place,’ she said, before delivering her blunt final verdict. ‘Let’s fix those things, and then we can worry about the apocalypse.’