Skip to content
Longterm Wiki

Colonial Pipeline (2021)

On May 7, 2021, Colonial Pipeline — operator of the largest refined-petroleum pipeline on the U.S. East Coast — was hit with ransomware by DarkSide affiliates. Colonial proactively shut down operations, triggering fuel shortages, panic buying, and price spikes across the eastern seaboard. The shutdown lasted six days. The incident drove binding cybersecurity directives for U.S. pipeline operators (TSA Security Directives Pipeline-2021-01 and -02) and remains the canonical example of cyber-induced critical-infrastructure cascade in the U.S.

Details

Date

May 7, 2021

Attribution

DarkSide ransomware-as-a-service (Russia-based affiliates)

AI involvement

none

Initial vector

Compromised legacy VPN credential (no MFA)

Ransom paid

$4.4M (75 BTC); $2.3M later recovered by FBI

Direct damage estimate

~$5B+ including operational disruption, fuel-supply impact (medium confidence)

Notable impact

5,500-mile US East Coast fuel pipeline shutdown for 6 days; emergency declarations in 17 states + DC

Related Wiki Pages

Top Related Pages

Historical

NotPetya (2017)

Tags

cyber-incidentransomwarecritical-infrastructureenergydarkside