Energy · United States · May 2021
Colonial Pipeline Ransomware Attack
In May 2021, a ransomware attack on Colonial Pipeline forced the shutdown of the largest fuel pipeline in the United States, triggering fuel shortages and panic-buying across the East Coast and becoming a landmark critical-infrastructure incident.
What happened
On May 7, 2021, Colonial Pipeline — the operator of the largest fuel pipeline in the United States, carrying gasoline and jet fuel from Texas to much of the East Coast — discovered it had been hit by ransomware. The attack, attributed in reporting to the DarkSide group, would become one of the most consequential critical-infrastructure cyber incidents in history, precisely because of what the company did next.
Colonial made the decision to proactively shut down its pipeline operations to contain the threat and prevent it from spreading to the operational technology that controls fuel flow. That single, cautious decision — halting the physical pipeline as a precaution against a mostly IT-side attack — is what turned a corporate breach into a national event.
Reporting later indicated that the attackers gained entry through a single compromised VPN account password, for an account that reportedly did not have multi-factor authentication enabled — a stark reminder that the largest consequences can flow from the smallest gaps.
The impact
The pipeline shutdown lasted several days, and the effect on the US East Coast was immediate and dramatic. Fuel supplies tightened, gas stations ran dry across multiple states, and images of long lines and panic-buying dominated the news. The disruption rippled through transportation and prompted emergency measures from federal and state authorities.
Colonial reportedly paid a ransom of roughly 75 Bitcoin — about US$4.4 million at the time — to obtain a decryption tool, though the company relied heavily on its own backups for recovery. In a notable development, US authorities later recovered a significant portion of the ransom, an early demonstration of law-enforcement pressure on the ransomware economy.
The strategic impact outweighed even the operational one. Colonial Pipeline transformed ransomware from an IT problem into a national-security priority, driving new US pipeline cybersecurity directives and a far more aggressive government posture toward ransomware groups.
How the attack unfolded
- Initial access: attackers used a compromised VPN account password, reportedly for an account without multi-factor authentication.
- Impact on IT: ransomware was deployed against Colonial's business IT systems.
- Precautionary shutdown: Colonial halted pipeline operations to prevent any spread to operational technology, converting an IT incident into a physical supply disruption.
- Extortion: a ransom was reportedly paid for a decryptor, though backups were central to recovery.
The recovery
Colonial restarted pipeline operations after several days, relying substantially on its own backups alongside the purchased decryption tool, and worked to normalize fuel distribution across the affected region over the following days.
The incident became the definitive case study in why the line between IT and operational technology matters — and why containment and recovery capability, not just prevention, determine how bad an attack becomes.
How this attack could have been contained
The reported entry point — a single credential on an account without multi-factor authentication — is the scenario continuous access verification is built to catch. Immune scores behavior on every request, so a credential reaching unusual systems is flagged even when the login appears valid and MFA is absent.
The defining decision in this incident was a precautionary shutdown because the operator could not be certain the attack was contained. Immune's automated, targeted containment and microsegmentation are designed to isolate an intrusion precisely, giving operators the confidence to contain the threat without halting the entire operation.
And Colonial's reliance on backups to recover mirrors Immune's core principle: fast, validated recovery from immutable backups is what removes an attacker's leverage. Immune builds that recovery into an automated, ordered, self-healing loop rather than a manual scramble.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
Beginning in May 2023, the Cl0p group exploited a zero-day flaw in the widely-used MOVEit file-transfer software to steal data from thousands of organizations worldwide — one of the largest supply-chain extortion campaigns ever recorded.
In September 2023, a ransomware attack on MGM Resorts — enabled by a phone call to the IT help desk — disrupted hotels and casinos across Las Vegas and beyond for around ten days, at a reported cost near US$100 million.
Protect against attacks like this
How to defend against energy ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
