‘Cyber 9/11' Could Make US Cities ‘Uninhabitable in Hours’: Cyber Expert Gives Chilling Warning

A cybersecurity expert has warned that China poses a serious threat to critical US infrastructure

Cyberattack
(This is a representational image) In a recent report, a cybersecurity expert warned of a threat to America's critical infrastructure that would be far worse than stolen data or offline websites Wikimedia Commons

A cyberattack on America's critical infrastructure, dubbed 'Cyber 9/11' by an expert, could cause damage far beyond stolen data or disrupted websites, potentially knocking out electricity, water, communications and healthcare across major US cities, a cybersecurity expert has warned.

Annie Fixler, a cybersecurity expert at the Foundation for Defense of Democracies (FDD), told The Daily Mail that a successful attack could turn major cities 'uninhabitable in a matter of hours.' The reason is modern cities rely on interconnected systems for everything from electricity and water to communications, healthcare and wastewater treatment.

A prolonged disruption to electricity could affect water pumps, communications networks, payment systems, traffic controls and medical equipment. A simultaneous failure across several services could therefore create problems far beyond the original cyberattack.

'Can you ship in enough bottles of water for a large city by road? Probably not,' she said.

Why Are Power and Water Systems Vulnerable?

Much of America's critical infrastructure relies on operational technology (OT) and industrial control systems that were not originally designed for today's highly connected environment.

The Atlantic Council has previously warned that the cyber-physical systems underpinning America's 16 critical infrastructure sectors create complex dependencies between technology, private companies and government agencies.

That means an attack does not necessarily need to take down every system in a city. Disrupting a relatively small number of important systems could potentially create knock-on effects elsewhere.

Recent government warnings show that these concerns are not purely theoretical. US agencies have previously warned about Iran-affiliated cyber actors targeting programmable logic controllers used in critical infrastructure.

The US Cybersecurity and Infrastructure Security Agency also warned that Chinese state-sponsored hackers have compromised networks around the world, including telecommunications, government, transportation and military infrastructure.

'There are the threats that really keep people awake at night because they know they have vulnerabilities that they don't know about,' Fixler told the Daily Mail.

Could a Cyberattack Cause a US-Wide Blackout?

A major cyberattack could potentially disrupt sections of the electricity grid, but a nationwide blackout should not be treated as the inevitable result of a successful intrusion.

The US power system is made up of numerous operators, networks and control environments. The potential impact of an attack would depend on what systems were compromised, how long attackers retained access and how quickly operators could isolate affected networks. The more immediate concern for cybersecurity experts is the possibility of cascading failures.

For example, a disruption to electricity could affect water treatment and pumping. Telecommunications problems could make it harder for emergency services to communicate. Hospitals could be forced to rely on backup systems while pharmacies, banks and retailers face their own disruptions.

How China and Its Allies Could Threaten US Critical Infrastructure

Fixler warned that China could pose a particularly serious threat to US critical infrastructure, arguing that Beijing could potentially seek to disrupt key systems ahead of a military operation against Taiwan.

Her warning comes as several of her FDD colleagues examine the growing cooperation between China, Russia, Iran and North Korea in their book Axis of Aggressors, published in June.

The book's authors also highlighted comments made by Chairman of the Joint Chiefs of Staff Gen. Dan Caine, who told Congress in June 2025 that Beijing, Moscow, Tehran and Pyongyang were 'pursuing unprecedented levels of cooperation.'

There is already evidence that state-linked actors have been targeting critical infrastructure and probing the systems that underpin essential services.

A 2026 report from the Foundation for Defense of Democracies argued that China, Russia, Iran and North Korea have expanded cooperation across cyber, technology and military areas. The report, based on research covering 2019 through 2025, identified hundreds of instances of security cooperation between the four countries.

'I couldn't agree more with the underlying findings the authors present regarding the rapid military modernisation unfolding across multiple domains — air, sea, land, space and cyber — emanating from China, Russia, Iran and North Korea,' Retired Air Force Lt. Gen. Richard Newton told Fox News Digital in July.

Russia Already Linked to Critical Infrastructure Cyber Threats

Meanwhile, NATO has repeatedly warned about malicious cyber activity and threats to critical infrastructure. The alliance has described Russian cyber activity as part of a broader pattern of hybrid activity, alongside infrastructure sabotage, electronic interference and disinformation.

'We strongly condemn Russia's persistent malicious cyber activities, leveraging its cyber ecosystem to target Allies and NATO partners. These activities constitute a threat to Allied security,' NATO said in a statement in July.

That does not mean every major cyberattack is directed by a government. Criminal ransomware groups, hacktivists and other independent actors can also cause serious disruption.

NATO currently describes cyberattacks and critical infrastructure sabotage as part of a broader security challenge facing Europe and North America.

While a 'Cyber 9/11' remains a worst-case scenario, the vulnerabilities behind the warning are real. The risk is not necessarily one dramatic attack that shuts down an entire country overnight, but potentially a chain of disruptions spreading from one interconnected system to another.