Not Safe at Home
Asymmetrical technologies threaten to bring war to America. Are we ready?
By James B. Meigs
The next war might not start with Chinese troops landing on Taiwan’s beaches or Russian tanks rolling through the Baltics. It could start in your own kitchen when you turn on the stove and no gas comes out. Or on your roof when your new solar panels stop producing power even though the sun is shining. Soon, your water taps go dry as well. By nightfall, the U.S. is slipping into chaos with blackouts spreading, communications networks collapsing, and trains, ports and airports shutting down.
The next morning, the president delivers the grim news: Our country has been hit by a massive cyberattack. It will take weeks to restore power grids, repair infrastructure and reopen ports and airports. That’s when China’s boats hit the beaches or Russia’s tanks start to roll. By the time the U.S. stumbles back onto its feet, our enemies believe, they’ll have cruised to victory.
This is the kind of scenario that keeps Pentagon planners up at night.
For well over a century, Americans fought wars exclusively overseas. It’s not a coincidence that the signature pop song of World War I was called “Over There.” With its forces deployed an ocean away, the U.S. could keep its civilians safe and home-front factories humming. Today technology is eroding that protective barrier. As military reporter Wes O’Donnell writes on Substack, “the battlefield is coming home.”
Americans got a hint of these risks last month when the Federal Bureau of Investigation and the Environmental Protection Agency reported cyberattacks against water and wastewater facilities in multiple states. The hackers changed passwords and tinkered with digital control systems. In most cases, the damage was minor. But the level of access the hackers achieved suggests their ability to inflict far more serious harm. U.S. officials believe Iran is behind these attacks, though China and Russia are suspected of having made similar incursions in the past.
Why would enemy hackers go after humble water facilities instead of, say, the Pentagon or the U.S. air-traffic control system? One reason, I suspect, is that these facilities are soft targets. Like chemical plants and pipelines, municipal water plants use digital control systems to operate pumps, valves and the like. These systems are typically connected to the internet, which can give hackers a way in. But cash-strapped municipal facilities are less likely to have security experts on staff and more likely to rely on aging equipment and software. I don’t believe the hackers who infiltrated these plants were trying to trigger a mass water crisis. I think they were practicing for something bigger.
Iran has a long history of anti-U.S. cyber attacks. But China is the world leader in the hacking game. “China has been probing U.S. critical infrastructure networks for vulnerabilities since the Obama administration,” wrote analyst James A. Lewis of the Center for Strategic and International Studies in a 2023 report. China’s military doctrine seeks the ability to “disrupt, paralyze, or destroy an opponent’s operational capabilities,” the report notes.
Obviously, a war over Taiwan would be fought in the Western Pacific. But America’s ability to fight—or simply to deter—such a conflict depends on having a robust supply chain at home. In the event of war, the CSIS report predicts, China might make a point of hitting our electric grid, pipelines, railroads and communications networks. Such an attack would distract U.S. leadership and soak up resources at home while degrading our ability to deliver troops and weapons to a war zone.
For two centuries, the U.S. enjoyed what the authors of an article in the Army Sustainment Professional Bulletin call “strategic sanctuary.” But in the dawning era of asymmetrical weapons, “the U.S. can no longer rely on natural geography to prevent attacks on the homeland,” the authors conclude. Cyberattacks aren’t the only threat. Last year, Ukraine managed to destroy Russian bombers thousands of miles from its borders using drones surreptitiously launched from inside Russia. There’s no reason to think our bombers—not to mention refineries, power lines and other infrastructure—are safe from similar attacks. The undersea data cables connecting the U.S. and its allies are also vulnerable to sabotage. Then there’s America’s satellite fleet, which is vital to both military operations and our civilian economy. Naturally, China and Russia are both fielding antisatellite weapons.
But China also has a unique advantage in the cyber realm: It makes much of the digital hardware on which our critical infrastructure runs. “Engineers recently found ‘kill switches’ in Chinese-made solar components,” security consultant Rob Joyce reported last year. The Chinese hacking group Volt Typhoon is also known for this patient approach, “pre-positioning” malware in critical networks, including the software systems running some U.S ports. “They want to slow the U.S. military’s ability to mobilize,” Mr. Joyce told Congress in 2024, “and they want to sow societal panic at the time of their choosing.”
The U.S. isn’t helpless in the face of these challenges. We can’t eliminate every homeland threat, but industry and government can both continue beefing up security and preparing for worst-case scenarios. We need to keep banishing Chinese components from our most sensitive tech. Above all, we need to revive a culture of resilience. Every family should be able to survive a few days without power and internet. Every business needs a backup plan for when the world goes dark. In the end, being able to bounce back from an attack may be the best way to deter one.
Mr. Meigs is a Free Expression columnist at WSJ Opinion.



Excellent article! You neglected to mention, North Korea, which I believe should not be underestimated in the hacking world.
Over the past 2 months, Microsoft has issued close to 1000 patches for bugs found in Windows! Other vendors are issue huge patch drops also. Humans are just not good at programming compared to AIs. We miss to many problems leading to security holes.
All these public utilities need to apply system OS and network updates immediately, not months form now. Those using unsupported OS versions need to be forced to step-up to supported versions, regardless of the cost.