HOME

TheInfoList



OR:

On May 7, 2021,
Colonial Pipeline The Colonial Pipeline is the largest pipeline system for refined oil products in the U.S.oil pipeline Pipeline transport is the long-distance transportation of a liquid or gas through a system of pipes—a pipeline—typically to a market area for consumption. The latest data from 2014 gives a total of slightly less than of pipeline in 120 countr ...
system that originates in Houston, Texas, and carries
gasoline Gasoline (; ) or petrol (; ) (see ) is a transparent, petroleum-derived flammable liquid that is used primarily as a fuel in most spark-ignited internal combustion engines (also known as petrol engines). It consists mostly of organic ...
and
jet fuel Jet fuel or aviation turbine fuel (ATF, also abbreviated avtur) is a type of aviation fuel designed for use in aircraft powered by gas-turbine engines. It is colorless to straw-colored in appearance. The most commonly used fuels for commercial a ...
mainly to the
Southeastern United States The Southeastern United States, also referred to as the American Southeast or simply the Southeast, is a geographical region of the United States. It is located broadly on the eastern portion of the southern United States and the southern po ...
, suffered a
ransomware Ransomware is a type of malware from cryptovirology that threatens to publish the victim's personal data or permanently block access to it unless a ransom is paid off. While some simple ransomware may lock the system without damaging any files, m ...
cyberattack A cyberattack is any offensive maneuver that targets computer information systems, computer networks, infrastructures, or personal computer devices. An attacker is a person or process that attempts to access data, functions, or other restricted ...
that impacted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75
bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public di ...
or $4.4 million) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool had a very long processing time to help get the system back up in time. The
Federal Motor Carrier Safety Administration The Federal Motor Carrier Safety Administration (FMCSA) is an agency in the United States Department of Transportation that regulates the trucking industry in the United States. The primary mission of the FMCSA is to reduce crashes, injuries and f ...
issued a regional emergency declaration for 17 states and Washington, D.C., to keep fuel supply lines open on May 9. It was the largest cyberattack on an oil infrastructure target in the history of the United States. The FBI and various media sources identified the criminal hacking group
DarkSide Dark side, Dark Side, or Darkside may refer to: Popular culture * Dark side (''Star Wars''), the dark side of the Force in the ''Star Wars'' universe * ''Dark Side'' (video game), a 1988 video game from Incentive Software * ''The Dark Side'' (b ...
as the responsible party. The same group is believed to have stolen 100 gigabytes of data from company servers the day before the malware attack. On June 7, the
Department of Justice A justice ministry, ministry of justice, or department of justice is a ministry or other government agency in charge of the administration of justice. The ministry or department is often headed by a minister of justice (minister for justice in a ...
announced that it had recovered 63.7 of the bitcoins (approximately $2.3 million) from the ransom payment.DOJ seizes millions in ransom paid by Colonial Pipeline
ABC News ABC News is the journalism, news division of the American broadcast network American Broadcasting Company, ABC. Its flagship program is the daily evening newscast ''ABC World News Tonight, ABC World News Tonight with David Muir''; other progra ...
This was one of first high profile corporate cyber attacks which started from a breached employee personal password likely found on the dark web rather than a direct attack on the company's systems.


Background

The Colonial Pipeline carries gasoline, diesel and jet fuel from
Texas Texas (, ; Spanish language, Spanish: ''Texas'', ''Tejas'') is a state in the South Central United States, South Central region of the United States. At 268,596 square miles (695,662 km2), and with more than 29.1 million residents in 2 ...
to as far away as
New York New York most commonly refers to: * New York City, the most populous city in the United States, located in the state of New York * New York (state), a state in the northeastern United States New York may also refer to: Film and television * '' ...
. About 45% of all fuel consumed on the East Coast arrives via the pipeline system. The attack came amid growing concerns over the vulnerability of infrastructure (including
critical infrastructure Critical infrastructure (or critical national infrastructure (CNI) in the UK) is a term used by governments to describe assets that are essential for the functioning of a society and economy – the infrastructure. Most commonly associated wi ...
) to cyberattacks after several high-profile attacks, including the 2020 SolarWinds hack that hit multiple federal government agencies, including the Defense, Treasury, State, and Homeland Security departments.


Impact

The primary target of the attack was the billing infrastructure of the company. The actual oil pumping systems were still able to work. According to CNN sources in the company, the inability to bill the customers was the reason for halting the pipeline operation. Colonial Pipeline reported that it shut down the pipeline as a precaution due to a concern that the hackers might have obtained information allowing them to carry out further attacks on vulnerable parts of the pipeline. The day after the attack, Colonial could not confirm at that time when the pipeline would resume normal functions. The attackers also stole nearly 100 gigabytes of data and threatened to release it on the internet if the ransom was not paid. It was reported that within hours after the attack the company paid a ransom of nearly 75 Bitcoins ($5 million) to the hackers in exchange for a decryption tool, which proved so slow that the company's business continuity planning tools were more effective in bringing back operational capacity. On May 9, Colonial stated they planned to substantially repair and restore the pipeline's operations by the end of the week. In response to fuel shortages at
Charlotte Douglas International Airport Charlotte Douglas International Airport (IATA: CLT, ICAO: KCLT, FAA LID: CLT), typically referred to as Charlotte Douglas, Douglas Airport, or simply CLT, is an international airport in Charlotte, North Carolina, located roughly six miles we ...
caused by the pipeline shutdown,
American Airlines American Airlines is a major US-based airline headquartered in Fort Worth, Texas, within the Dallas–Fort Worth metroplex. It is the largest airline in the world when measured by fleet size, scheduled passengers carried, and revenue passenge ...
changed flight schedules temporarily. At least two flights (to
Honolulu Honolulu (; ) is the capital and largest city of the U.S. state of Hawaii, which is in the Pacific Ocean. It is an unincorporated county seat of the consolidated City and County of Honolulu, situated along the southeast coast of the islan ...
and
London London is the capital and List of urban areas in the United Kingdom, largest city of England and the United Kingdom, with a population of just under 9 million. It stands on the River Thames in south-east England at the head of a estuary dow ...
) had fuel stops or plane changes added to their schedules for a four-day period. The shortage also required
Hartsfield–Jackson Atlanta International Airport Hartsfield–Jackson Atlanta International Airport , also known as Atlanta Hartsfield–Jackson International Airport, Atlanta Airport, Hartsfield, Hartsfield–Jackson and, formerly, as the Atlanta Municipal Airport, is the primary internatio ...
to use other fuel suppliers, and there are at least five other airports directly serviced by the pipeline. Fuel shortages began to occur at
filling station A filling station, also known as a gas station () or petrol station (), is a facility that sells fuel and engine lubricants for motor vehicles. The most common fuels sold in the 2010s were gasoline (or petrol) and diesel fuel. Gasol ...
s amid
panic buying Panic buying (alternatively hyphenated as panic-buying; also known as panic purchasing) occurs when consumers buy unusually large amounts of a product in anticipation of, or after, a disaster or perceived disaster, or in anticipation of a large ...
as the pipeline shutdown entered its fourth day.
Alabama (We dare defend our rights) , anthem = " Alabama" , image_map = Alabama in United States.svg , seat = Montgomery , LargestCity = Huntsville , LargestCounty = Baldwin County , LargestMetro = Greater Birmingham , area_total_km2 = 135,7 ...
,
Florida Florida is a state located in the Southeastern region of the United States. Florida is bordered to the west by the Gulf of Mexico, to the northwest by Alabama, to the north by Georgia, to the east by the Bahamas and Atlantic Ocean, a ...
,
Georgia Georgia most commonly refers to: * Georgia (country), a country in the Caucasus region of Eurasia * Georgia (U.S. state), a state in the Southeast United States Georgia may also refer to: Places Historical states and entities * Related to t ...
,
North Carolina North Carolina () is a state in the Southeastern region of the United States. The state is the 28th largest and 9th-most populous of the United States. It is bordered by Virginia to the north, the Atlantic Ocean to the east, Georgia a ...
, and
South Carolina )'' Animis opibusque parati'' ( for, , Latin, Prepared in mind and resources, links=no) , anthem = "Carolina";" South Carolina On My Mind" , Former = Province of South Carolina , seat = Columbia , LargestCity = Charleston , LargestMetro = G ...
all reported shortages. Areas from northern South Carolina to southern Virginia were hardest hit, with 71% of filling stations running out of fuel in
Charlotte Charlotte ( ) is the List of municipalities in North Carolina, most populous city in the U.S. state of North Carolina. Located in the Piedmont (United States), Piedmont region, it is the county seat of Mecklenburg County, North Carolina, Meckl ...
on May 11 and 87 percent of stations out in
Washington, D.C. ) , image_skyline = , image_caption = Clockwise from top left: the Washington Monument and Lincoln Memorial on the National Mall, United States Capitol, Logan Circle, Jefferson Memorial, White House, Adams Morgan, ...
on May 14. Average fuel prices rose to their highest since 2014, reaching more than $3 a gallon.


Responses

U.S. President Joe Biden declared a
state of emergency A state of emergency is a situation in which a government is empowered to be able to put through policies that it would normally not be permitted to do, for the safety and protection of its citizens. A government can declare such a state du ...
on May 9, 2021. During regular times there were limits on the amount of petroleum products that could be transported by road, rail, etc., domestically within the U.S. mainland. However, with the declaration in place, these were temporarily suspended. On May 10, Georgia Governor
Brian Kemp Brian Porter Kemp (born November 2, 1963) is an American businessman and politician serving as the 83rd governor of Georgia since January 2019. A member of the Republican Party, Kemp served as the 27th secretary of state of Georgia from 2010 to ...
declared a state of emergency, and temporarily waived collection of the state's taxes on motor fuels (diesel and gasoline). In response to
panic buying Panic buying (alternatively hyphenated as panic-buying; also known as panic purchasing) occurs when consumers buy unusually large amounts of a product in anticipation of, or after, a disaster or perceived disaster, or in anticipation of a large ...
in the Southeast, U.S. Transportation Secretary
Pete Buttigieg Peter Paul Montgomery Buttigieg ( ; ; Sometimes pronounced or , but not by Buttigieg himself. born January 19, 1982) is an American politician and former military officer who is currently serving as the United States secretary of trans ...
and U.S. Energy Secretary
Jennifer Granholm Jennifer Mulhern Granholm (born February 5, 1959) is a Canadian-American lawyer, educator, author, political commentator, and politician serving as the 16th United States secretary of energy since 2021. A member of the Democratic Party, she prev ...
on May 12 both cautioned against gasoline hoarding, reiterating that the United States was undergoing a "supply crunch" rather than a gas shortage. On May 12, the
U.S. Consumer Product Safety Commission The United States Consumer Product Safety Commission (USCPSC, CPSC, or commission) is an independent agency of the United States government. The CPSC seeks to promote the safety of consumer products by addressing “unreasonable risks” of in ...
advised people to "not fill
plastic bag A plastic bag, poly bag, or pouch is a type of container made of thin, flexible, plastic film, nonwoven fabric, or plastic textile. Plastic bags are used for containing and transporting goods such as foods, produce, powders, ice, magazines ...
s with gasoline" or to use any containers not meant for fuel. Biden signed Executive Order 14028 on May 12, increasing software security standards for sales to the government, tighten detection and security on existing systems, improve information sharing and training, establish a Cyber Safety Review Board, and improve incident response. The
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the United States government tasked with the enforcement of federal law and a ...
also convened a cybersecurity task force to increase prosecutions. The Department of State issued a statement that a $10,000,000 reward would be given out in case of information leading to the arrest of DarkSide members.


Perpetrators

DarkSide released a statement on May 9 that did not directly mention the attack, but claimed that "our goal is to make money, and not creating problems for society."


Pipeline restart

The restart of pipeline operations began at 5 p.m. on May 12, ending a six-day shutdown, although Colonial Pipeline Company warned that it could take several more days for service to return to normal. The pipeline company stated that several markets that are served by the pipeline may experience, or continue to experience, intermittent service interruptions during the restart. The company also stated that they would move as much gasoline, diesel and jet fuel as safely possible until markets return to normal. All Colonial Pipeline systems and operations had returned to normal by May 15. After the shutdown, the average national price of gasoline rose to the highest it had been in over six years, to about an average of
US$ The United States dollar (symbol: $; code: USD; also abbreviated US$ or U.S. Dollar, to distinguish it from other dollar-denominated currencies; referred to as the dollar, U.S. dollar, American dollar, or colloquially buck) is the official ...
3.04 a gallon on May 18. The price increase was more pronounced in the southern states, with prices rising between 9 and 16 cents in the Carolinas, Tennessee, Virginia, and Georgia. Around 10,600 gas stations were still without gas as of May 18. In a May 19, 2021, interview with ''
The Wall Street Journal ''The Wall Street Journal'' is an American business-focused, international daily newspaper based in New York City, with international editions also available in Chinese and Japanese. The ''Journal'', along with its Asian editions, is published ...
'', Joseph Blount said why he ultimately decided to pay a $4.4 million ransom to hackers who breached the company's systems; "It was the right thing to do for the country." He also said, "I know that's a highly controversial decision".


Investigations

Biden said on May 10 that though there was no evidence that the Russian government was responsible for the attack, there was evidence that the
DarkSide Dark side, Dark Side, or Darkside may refer to: Popular culture * Dark side (''Star Wars''), the dark side of the Force in the ''Star Wars'' universe * ''Dark Side'' (video game), a 1988 video game from Incentive Software * ''The Dark Side'' (b ...
group is in Russia, and that thus, Russian authorities "have some responsibility to deal with this". Independent cybersecurity researchers have also stated the hacking group is Russian as their malware avoids encrypting files in a system where the language is set to Russian. In the aftermath of the attack, it was revealed at a Senate Armed Services cyber subcommittee hearing that the
Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior or home ministries of other countries. Its stated missions involve anti-te ...
was not alerted to the ransomware attack and that the Justice Department was not alerted to the ransom type or amount, prompting discussion about the numerous
information silo An information silo, or a group of such silos, is an insular management system in which one information system or subsystem is incapable of reciprocal operation with others that are, or should be, related. Thus information is not adequately shared ...
s in the government and difficulties of sharing. Blockchain analytics firm Elliptic published a
bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public di ...
wallet report showing $90 million in bitcoin ransom payments were made to DarkSide or DarkSide affiliates over the last year, originating from 47 distinct wallets. According to a DarkTracer release of 2226 victim organizations since May 2019, 99 organizations have been infected with the DarkSide malware – suggesting that approximately 47% of victims paid a ransom and that the average payment was $1.9 million. The DarkSide developer had received bitcoins worth $15.5 million (17%), with the remaining $74.7 million (83%) going to the various affiliates.


Partial ransom recovery

The U.S. Department of Justice issued a press release on June 7, 2021, stating that it had seized 63.7 Bitcoins from the original ransom payment. The value of the recovered Bitcoins was only $2.3 million, because the trading price of Bitcoin had fallen since the date of the ransom payment. Through possession of the private key of the ransom account, the FBI was able to retrieve the Bitcoin, though it did not disclose how it obtained the private key.


See also

*
2020 Colonial Pipeline oil spill The 2020 Colonial Pipeline oil spill was a major release of gasoline from the Colonial Pipeline in a nature reserve near Huntersville, North Carolina, in the United States. The spill, which began on July 27, resulted in approximately of gas ...
*
Steamship Authority cyberattack The Woods Hole, Martha's Vineyard and Nantucket Steamship Authority, doing business as The Steamship Authority (''SSA''), is the statutory regulatory body for all ferry operations between mainland Massachusetts and The Islands (Massachusetts), the ...
* Health Service Executive cyberattack


References


External links

* {{Hacking in the 2020s, state=autocollapse Cyberattacks on energy sector Data breaches in the United States Hacking in the 2020s May 2021 crimes in the United States Ransomware