Pipeline

Colonial Pipeline — ransomware attack and shutdown

7–13 May 2021

Southeastern United States (pipeline system originating in Houston, Texas)

What happened

The DarkSide criminal group compromised Colonial Pipeline's IT systems using stolen VPN credentials, prompting the company to proactively shut down its entire fuel pipeline network — the largest refined-products pipeline in the US, supplying roughly 45% of East Coast fuel — as a precaution, though operational control systems were not directly compromised. The shutdown triggered panic buying and localised fuel shortages across the southeastern US; Colonial paid DarkSide a $4.4 million ransom and restarted the pipeline on 13 May. CISA and the FBI issued a joint advisory on the DarkSide ransomware-as-a-service variant.

Evidence
Documented
Confidence
High
Infrastructure
Pipeline
Latitude
29.7000°
Longitude
-95.2000°

Attribution

Attributed to DarkSide (criminal ransomware group)

Sources

  1. The Attack on Colonial Pipeline: What We've Learned & What We've Done Over the Past Two YearsCybersecurity and Infrastructure Security Agency (CISA) · Incident reporting