The Colonial Pipeline ransomware attack occurred on May 7, 2021, when the Colonial Pipeline Company, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a catastrophic cyberattack. The attack targeted the company's computerized equipment managing the pipeline.
The hack was executed by DarkSide, a cybercriminal hacking group believed to be based in Eastern Europe or Russia. In response to the breach, Colonial Pipeline preemptively halted all pipeline operations to contain the threat. This unprecedented shutdown interrupted the flow of approximately 45% of all fuel consumed on the U.S. East Coast. The resulting disruption caused localized fuel shortages, widespread panic buying, price spikes, and led President Joe Biden to declare a state of emergency across 17 states and Washington, D.C. It remains the largest and most disruptive publicly disclosed cyberattack on critical infrastructure in U.S. history.
Background
The Colonial Pipeline is the largest pipeline system for refined oil products in the United States. Spanning over 5,500 miles (8,900 km), the pipeline transports more than 100 million gallons (2.5 million barrels) of fuel daily from refineries in the Gulf Coast to markets throughout the Southern and Eastern U.S., terminating in Linden, New Jersey. The system supplies gasoline, diesel, home heating oil, and aviation fuel to several major airports, including Hartsfield–Jackson Atlanta International Airport.
The attack and entry vector
The intrusion began in late April 2021 but culminated on May 7, 2021. According to cybersecurity firm Mandiant, which investigated the breach, the DarkSide hackers gained access to the Colonial Pipeline network through a single, compromised password tied to a virtual private network (VPN) account.
The specific VPN profile had been created years earlier and was no longer in active use, yet the account remained active in the system. Crucially, the account did not use multi-factor authentication (MFA), allowing the hackers to breach the corporate network using only a username and a leaked password that was reportedly found in a batch of stolen credentials on the dark web.
Once inside the IT network, DarkSide operators exfiltrated roughly 100 gigabytes of corporate data within a two-hour window. After successfully stealing the data for double-extortion leverage, they deployed their ransomware payload, encrypting Colonial's corporate servers and billing systems.
Impact, shutdown, and panic buying
Upon discovering the ransomware note on the morning of May 7, Colonial Pipeline executives faced a critical dilemma. While the ransomware had only infected the business IT network (used for billing and internal operations) and had not technically breached the operational technology (OT) network that physically controls the pipeline pumps and valves, the company could not be certain the malware wouldn't spread.
Furthermore, without their billing systems, Colonial had no way to track how much fuel was being delivered to which customers, or how to bill for it. As a sweeping precaution, CEO Joseph Blount ordered the physical shutdown of the entire pipeline system.
Panic Buying in Virginia
Out-of-service gas pumps at a Wawa in Fairfax County, Virginia, wrapped in bags due to widespread panic buying and fuel depletion following the pipeline shutdown.
Station Closures
A Sunoco gas station entirely devoid of fuel. At the peak of the crisis, over 70% of gas stations in regions of North Carolina and Virginia were completely dry.
The shutdown triggered immediate logistical nightmares across the U.S. Southeast and Eastern seaboard. Fearing prolonged shortages, motorists engaged in severe panic buying. Within days, thousands of gas stations ran entirely out of fuel. In North Carolina, up to 71% of all gas stations reported being completely dry. Airlines, including American Airlines, were forced to alter flight schedules and implement fuel stops on long-haul routes due to kerosene shortages at major hubs.
On May 9, 2021, the Federal Motor Carrier Safety Administration issued a regional emergency declaration for 17 states and Washington D.C., lifting weight limits and hours-of-service regulations for truck drivers transporting fuel to ease the crisis.
The ransom payment
Despite long-standing FBI and government advice against negotiating with terrorists or paying cyber ransoms, Colonial Pipeline CEO Joseph Blount authorized the payment. Believing it was the only way to quickly restore the critical infrastructure of the United States, Colonial paid the DarkSide group a ransom of 75 Bitcoin (valued at approximately $4.4 million USD at the time) on May 8, just one day after the attack was discovered.
Upon receiving the payment, DarkSide provided Colonial Pipeline with a software decryption tool. However, the tool proved to be so slow and cumbersome that Colonial primarily relied on its own data backups to restore the system anyway. The pipeline finally began the process of restarting operations on May 12, though it took several more days for the supply chain to normalize.
DOJ intervention and Bitcoin recovery
The attack brought national attention to the vulnerability of Operational Technology (OT) and critical infrastructure to modern cyber-extortion schemes.
In a stunning and highly publicized victory for U.S. law enforcement, the Department of Justice (DOJ) announced on June 7, 2021, that it had successfully seized a significant portion of the ransom payment.
Agents from the FBI tracked the flow of the Bitcoin through multiple anonymous cryptocurrency wallets. Ultimately, the FBI managed to obtain the private key to a specific wallet where the DarkSide affiliates had deposited the funds. The DOJ executed a seizure warrant and recovered 63.7 Bitcoins. Due to a crash in the price of Bitcoin in the intervening weeks, the recovered amount was valued at roughly $2.3 million—about half the total dollar value Colonial had paid, but representing the vast majority of the cryptocurrency itself.
Aftermath and legacy
The Colonial Pipeline attack was a watershed moment for U.S. critical infrastructure security. Following the intense political and media backlash, the DarkSide hacking group claimed they were "apolitical" and only wanted to make money, not cause societal problems. Shortly after the attack, their dark web infrastructure was allegedly seized, and the group ceased operations (though many of its members likely rebranded under different syndicate names, such as BlackMatter).
In the wake of the crisis, the Transportation Security Administration (TSA), which regulates U.S. pipelines, issued highly restrictive and mandatory cybersecurity directives for the pipeline industry. These directives required pipeline owners to report confirmed cyber incidents to CISA within 12 hours, designate a cybersecurity coordinator, and implement specific, sweeping network mitigations to prevent future outages.