The primary targets hardened. So Volt Typhoon moved one step back.
Updated intelligence confirms that the group’s pre-positioning operations have extended beyond the main DESNZ-regulated energy companies and OFWAT water utilities into the Tier 2 supplier networks (managed service providers, facilities contractors, specialist engineering firms) that hold persistent administrative access to central government and defence environments. The NCSC has been working with affected suppliers under its Active Cyber Defence programme. No public advisory names specific companies.
The architectural logic here is straightforward. Primary CNI operators have, over the last 18 months, made real investments in detection and response following sustained regulatory and NCSC pressure. Volt Typhoon’s pivot to Tier 2 suppliers is a rational response: find the organisations with equivalent access but lower security investment and less regulatory scrutiny, and go through them instead.
The Problem With Outsourced Government IT
A mid-sized MSP can hold persistent administrative access to ten or more public sector bodies simultaneously. One compromised service account with the right delegated permissions is functionally equivalent to a direct foothold in each of those environments, and may be considerably easier to obtain.
Volt Typhoon’s technique set is almost perfectly matched to this context. Living-off-the-land operations using native Windows utilities, blending with legitimate administrator activity, no custom malware that might trigger endpoint detection. A compromised MSP admin account using standard RMM tooling does not stand out in environments where alert volumes are already high and analyst capacity is already stretched. Access can persist for months. In some cases, it has.
Confirmed indicators in recent intelligence include suspicious authentication patterns on service accounts at UK MSPs with government contracts, lateral movement from MSP management infrastructure toward government end-client environments using legitimate remote access tools, and staging of LOtL tooling consistent with the Volt Typhoon playbook on supplier nodes.
Who This Actually Affects
The scope is broader than companies that appear on a government supplier register. Volt Typhoon’s access requirements are about network trust relationships and credential reach, not branding.
MSPs and IT service providers managing government cloud tenants, endpoints, or network infrastructure. If your engineers hold delegated admin credentials into government environments, you are in scope. Full stop.
Facilities and building management contractors are a pattern that keeps appearing at the OT/IT boundary. HVAC systems, physical access control, and building security are routinely managed by third-party contractors whose IT security sits significantly below the primary organisation’s. In government estate contexts, this is a known and largely unaddressed attack surface.
Specialist technical and engineering contractors servicing defence or nuclear facilities often have deep technical access arranged informally, outside standard IT governance frameworks. These relationships are valuable from a targeting perspective precisely because they’re less visible.
Software and data suppliers providing SaaS platforms or data tooling to government departments sit in a different risk category: supply chain software attacks of the SolarWinds and MOVEit variety give simultaneous access to every end-client. That’s not a theoretical risk.
What Pre-Positioning Actually Means
Volt Typhoon is not here to cause disruption today. The Five Eyes assessment, confirmed by CISA, NCSC, FBI, and partners, is that this infrastructure is being placed to enable disruptive action at a moment of geopolitical confrontation. A conflict scenario involving Taiwan. Economic escalation with a significant sanctions dimension. Some other trigger that hasn’t happened yet.
That changes what detection and eradication means. Finding and removing a Volt Typhoon intrusion is necessary. But living-off-the-land techniques are specifically designed to obscure what happened before detection. The operational question after finding a confirmed intrusion is not just “how do we remove this” but “what did they establish that we haven’t found?”
Most organisations won’t be able to answer that confidently from their existing log coverage.
What Government Suppliers Need to Do
Audit your privileged access. Every service account, contractor account, and remote access credential that can reach a government customer environment. Not the ones you think are active, but the ones that actually are. Check whether they all need to exist, whether they have MFA, whether they’re being monitored.
Segment customer environments from each other at the network level. A compromised MSP that can reach all its government clients from a single management plane is giving Volt Typhoon everything it needs. Customer isolation is a baseline control. It is also, in practice, frequently absent.
LOtL attacks are not detected by signature matching. Behavioural analysis of privileged account activity (timing anomalies, volume spikes, access to targets outside normal support patterns) is what surfaces this activity. If you’re not doing that analysis, you’re not looking for it.
If you hold government contracts and haven’t engaged with the NCSC’s managed services information-sharing programme, that should change. The Cyber Security and Resilience Bill moving through Parliament extends mandatory incident reporting to suppliers of regulated sectors. The procurement pressure is coming regardless. Getting ahead of it is better than being reactive when a government client starts asking hard questions.