Colonial Pipeline Cyberattack
   HOME

TheInfoList



OR:

On May 7, 2021, Colonial Pipeline, an American
oil pipeline A pipeline is a system of pipes for long-distance transportation of a liquid or gas, typically to a market area for consumption. The latest data from 2014 gives a total of slightly less than of pipeline in 120 countries around the world. The Un ...
system that originates in
Houston Houston ( ) is the List of cities in Texas by population, most populous city in the U.S. state of Texas and in the Southern United States. Located in Southeast Texas near Galveston Bay and the Gulf of Mexico, it is the county seat, seat of ...
, Texas, and carries
gasoline Gasoline ( North American English) or petrol ( Commonwealth English) is a petrochemical product characterized as a transparent, yellowish, and flammable liquid normally used as a fuel for spark-ignited internal combustion engines. When for ...
and
jet fuel Jet fuel or aviation turbine fuel (ATF, also abbreviated avtur) is a type of aviation fuel designed for use in aircraft powered by Gas turbine, gas-turbine engines. It is colorless to straw-colored in appearance. The most commonly used fuels for ...
mainly to the
Southeastern United States The Southeastern United States, also known as the American Southeast or simply the Southeast, is a geographical List of regions in the United States, region of the United States located in the eastern portion of the Southern United States and t ...
, suffered a
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
that afflicted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75
bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
or $4.4 million USD) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool required a very long processing time to restore the system to a working state. The
Federal Motor Carrier Safety Administration The Federal Motor Carrier Safety Administration (FMCSA) is an agency in the United States Department of Transportation that regulates the trucking industry in the United States. The primary mission of the FMCSA is to reduce crashes, injuries, an ...
issued a regional emergency declaration for 17 states and Washington, D.C., to keep fuel supply lines open on May 9. It was the largest cyberattack on an oil infrastructure target in the history of the United States. The
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
and various media sources identified the criminal hacking group DarkSide as the responsible party. The same group is believed to have stolen 100 gigabytes of data from company servers the day before the malware attack. On June 7, the
Department of Justice A justice ministry, ministry of justice, or department of justice, is a ministry or other government agency in charge of the administration of justice. The ministry or department is often headed by a minister of justice (minister for justice in a ...
announced that it had recovered 63.7 of the bitcoins (about 84% of the original payment) from the ransom payment, but due to a crash in the value of Bitcoin in late May, the recovered bitcoins were worth only around $2.3 million USD, roughly half of their original value. This was one of the first high profile corporate cyber attacks which started from a breached employee personal password likely found on the dark web rather than a direct attack on the company's systems.


Background

The pipeline network operated by Colonial Pipeline carries gasoline, diesel, and jet fuel from
Texas Texas ( , ; or ) is the most populous U.S. state, state in the South Central United States, South Central region of the United States. It borders Louisiana to the east, Arkansas to the northeast, Oklahoma to the north, New Mexico to the we ...
to
New York New York most commonly refers to: * New York (state), a state in the northeastern United States * New York City, the most populous city in the United States, located in the state of New York New York may also refer to: Places United Kingdom * ...
. About 45% of all fuel consumed on the East Coast arrives via the pipeline system. The attack occurred amid rising concerns about the vulnerability of
critical infrastructure Critical infrastructure, or critical national infrastructure (CNI) in the UK, describes infrastructure considered essential by governments for the functioning of a society and economy and deserving of special protection for national security. ...
to cyberattacks, following several high-profile incidents, such as the 2020 SolarWinds hack, which affected multiple U.S. federal government agencies, including the Departments of Defense, Treasury, State, and
Homeland Security Homeland security is an American national security term for "the national effort to ensure a homeland that is safe, secure, and resilient against terrorism and other hazards where American interests, aspirations, and ways of life can thrive" to ...
.


Attack

The attackers gained access to the system using a compromised password for an inactive
virtual private network Virtual private network (VPN) is a network architecture for virtually extending a private network (i.e. any computer network which is not the public Internet) across one or multiple other networks which are either untrusted (as they are not con ...
(VPN) account, which did not have
multi-factor authentication Multi-factor authentication (MFA; two-factor authentication, or 2FA) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more distinct types of evidence ...
enabled.


Consequences

The attack primarily targeted the company's billing infrastructure. However, the oil pumping systems remained operational. According to CNN sources within the company, the inability to bill customers was cited as the reason for halting pipeline operations. Colonial Pipeline reported shutting down the pipeline as a precaution, citing concerns that hackers might have accessed information enabling further attacks on vulnerable infrastructure. The day after the attack, Colonial Pipeline stated it could not confirm when the pipeline would resume normal operations. The attackers stole nearly 100 gigabytes of data and threatened to release it online if the ransom was not paid. Reports indicated that within hours of the attack, the company paid a ransom of nearly 75
Bitcoins Bitcoin (abbreviation: BTC; sign: ₿) is the first decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under the pseudonym of Satoshi Nakamoto. Use o ...
($4.4 million USD) in exchange for a decryption tool. However, the tool was reportedly slow, and the company's business continuity measures proved more effective in restoring operations. On May 9, Colonial stated they planned to substantially repair and restore the pipeline's operations by the end of the week. In response to fuel shortages at
Charlotte Douglas International Airport Charlotte Douglas International Airport is an international airport serving Charlotte, North Carolina, United States, located roughly west of the city's central business district. Charlotte Douglas is the primary airport for commercial and m ...
following the pipeline shutdown,
American Airlines American Airlines, Inc. is a major airlines of the United States, major airline in the United States headquartered in Fort Worth, Texas, within the Dallas–Fort Worth metroplex, and is the Largest airlines in the world, largest airline in the ...
temporarily adjusted its flight schedules. At least two flights, to
Honolulu Honolulu ( ; ) is the List of capitals in the United States, capital and most populous city of the U.S. state of Hawaii, located in the Pacific Ocean. It is the county seat of the Consolidated city-county, consolidated City and County of Honol ...
and
London London is the Capital city, capital and List of urban areas in the United Kingdom, largest city of both England and the United Kingdom, with a population of in . London metropolitan area, Its wider metropolitan area is the largest in Wester ...
, required additional fuel stops or plane changes over a four-day period. The shortage also led
Hartsfield–Jackson Atlanta International Airport Hartsfield–Jackson Atlanta International Airport is the primary international airport serving Atlanta and its Metro Atlanta, surrounding metropolitan area, in the U.S. state of Georgia (U.S. state), Georgia. It is located south of the Down ...
to rely on alternative fuel suppliers. At least five other airports were also directly affected by the pipeline shutdown. Fuel shortages emerged at
filling stations A filling station (also known as a gas station [] or petrol station []) is a facility that sells fuel and engine lubricants for motor vehicles. The most common fuels sold are gasoline (or petrol) and diesel fuel. Fuel dispensers are used to ...
, exacerbated by
panic buying Panic buying (alternatively hyphenated as panic-buying; also known as panic purchasing) occurs when consumers buy unusually large amounts of a product in anticipation of, or after, a disaster or perceived disaster, or in anticipation of a large p ...
, as the pipeline shutdown entered its fourth day. Fuel shortages were reported in
Alabama Alabama ( ) is a U.S. state, state in the Southeastern United States, Southeastern and Deep South, Deep Southern regions of the United States. It borders Tennessee to the north, Georgia (U.S. state), Georgia to the east, Florida and the Gu ...
,
Florida Florida ( ; ) is a U.S. state, state in the Southeastern United States, Southeastern region of the United States. It borders the Gulf of Mexico to the west, Alabama to the northwest, Georgia (U.S. state), Georgia to the north, the Atlantic ...
,
Georgia Georgia most commonly refers to: * Georgia (country), a country in the South Caucasus * Georgia (U.S. state), a state in the southeastern United States Georgia may also refer to: People and fictional characters * Georgia (name), a list of pe ...
,
North Carolina North Carolina ( ) is a U.S. state, state in the Southeastern United States, Southeastern region of the United States. It is bordered by Virginia to the north, the Atlantic Ocean to the east, South Carolina to the south, Georgia (U.S. stat ...
, and
South Carolina South Carolina ( ) is a U.S. state, state in the Southeastern United States, Southeastern region of the United States. It borders North Carolina to the north and northeast, the Atlantic Ocean to the southeast, and Georgia (U.S. state), Georg ...
. The most affected areas ranged from northern South Carolina to southern Virginia. In Charlotte, 71% of filling stations were out of fuel by May 11, while in
Washington D.C. Washington, D.C., formally the District of Columbia and commonly known as Washington or D.C., is the capital city and federal district of the United States. The city is on the Potomac River, across from Virginia, and shares land borders with ...
, 87% of stations had run out by May 14. Average fuel prices rose to their highest level since 2014, exceeding $3 per gallon. Experts have stated that the attacks were preventable but that essential protective measures were not in place. Although the East Coast gasoline shortage and Darkside's receipt of the ransom had significant consequences, they were not the most critical implications of the incident. The broader concern was the cybersecurity vulnerabilities and their potential impact on critical infrastructure in the United States.


Responses

U.S. President
Joe Biden Joseph Robinette Biden Jr. (born November 20, 1942) is an American politician who was the 46th president of the United States from 2021 to 2025. A member of the Democratic Party (United States), Democratic Party, he served as the 47th vice p ...
declared a
state of emergency A state of emergency is a situation in which a government is empowered to put through policies that it would normally not be permitted to do, for the safety and protection of its citizens. A government can declare such a state before, during, o ...
on May 9, 2021. During regular times there were limits on the amount of petroleum products that could be transported by road, rail, etc., domestically within the U.S. mainland. However, with the declaration in place, these were temporarily suspended. On May 10, Georgia Governor
Brian Kemp Brian Porter Kemp (born November 2, 1963) is an American politician serving as the 83rd governor of Georgia since 2019. A member of the Republican Party (United States), Republican Party, Kemp served as the state's 27th Georgia Secretary of Sta ...
declared a state of emergency, and temporarily waived collection of the state's taxes on motor fuels (diesel and gasoline). In response to
panic buying Panic buying (alternatively hyphenated as panic-buying; also known as panic purchasing) occurs when consumers buy unusually large amounts of a product in anticipation of, or after, a disaster or perceived disaster, or in anticipation of a large p ...
in the Southeast, U.S. Transportation Secretary
Pete Buttigieg Peter Paul Montgomery Buttigieg ( ; born January 19, 1982) is an American politician and former naval officer who served as the 19th United States Secretary of Transportation, United States secretary of transportation from 2021 to 2025. A me ...
and U.S. Energy Secretary
Jennifer Granholm Jennifer Mulhern Granholm (born February 5, 1959) is an American politician who was the 16th United States secretary of energy from 2021 to 2025. A member of the Democratic Party (United States), Democratic Party, she previously served as the 47t ...
on May 12 both cautioned against gasoline hoarding, reiterating that the United States was undergoing a "supply crunch" rather than a gas shortage. On May 12, the
U.S. Consumer Product Safety Commission The United States Consumer Product Safety Commission (USCPSC, CPSC, or commission) is an independent agency of the United States government. The CPSC seeks to promote the safety of consumer products by addressing "unreasonable risks" of injury ...
advised people to "not fill
plastic bag A plastic bag, poly bag, or pouch is a type of container made of thin, flexible, plastic film, nonwoven fabric, or plastic textile. Plastic bags are used for containing and transporting goods such as foods, produce, Powder (substance), powders, ...
s with gasoline" or to use any containers not meant for fuel. Biden signed Executive Order 14028 on May 12, increasing software security standards for sales to the government, tighten detection and security on existing systems, improve information sharing and training, establish a Cyber Safety Review Board, and improve incident response. The
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
also convened a cybersecurity task force to increase prosecutions. The Department of State issued a statement that a $10,000,000 reward would be given out in case of information leading to the arrest of DarkSide members.


Perpetrators

DarkSide released a statement on May 9 that did not directly mention the attack, but claimed that "our goal is to make money, and not creating problems for society."


Pipeline restart

The restart of pipeline operations began at 5 p.m. on May 12, ending a six-day shutdown, although Colonial Pipeline Company warned that it could take several more days for service to return to normal. The pipeline company stated that several markets that are served by the pipeline may experience, or continue to experience, intermittent service interruptions during the restart. The company also stated that they would move as much gasoline, diesel and jet fuel as safely possible until markets return to normal. All Colonial Pipeline systems and operations had returned to normal by May 15. After the shutdown, the average national price of gasoline rose to the highest it had been in over six years, to about an average of
US$ The United States dollar (Currency symbol, symbol: Dollar sign, $; ISO 4217, currency code: USD) is the official currency of the United States and International use of the U.S. dollar, several other countries. The Coinage Act of 1792 introdu ...
3.04 a gallon on May 18. The price increase was more pronounced in the southern states, with prices rising between 9 and 16 cents in the Carolinas, Tennessee, Virginia, and Georgia. Around 10,600 gas stations were still without gas as of May 18. In a May 19, 2021, interview with ''
The Wall Street Journal ''The Wall Street Journal'' (''WSJ''), also referred to simply as the ''Journal,'' is an American newspaper based in New York City. The newspaper provides extensive coverage of news, especially business and finance. It operates on a subscriptio ...
'', Joseph Blount said why he ultimately decided to pay a $4.4 million ransom to hackers who breached the company's systems; "It was the right thing to do for the country." He also said, "I know that's a highly controversial decision".


Investigations

Biden said on May 10 that though there was no evidence that the Russian government was responsible for the attack, there was evidence that the DarkSide group is in Russia, and that thus, Russian authorities "have some responsibility to deal with this". Independent cybersecurity researchers have also stated the hacking group is Russian as their malware avoids encrypting files in a system where the language is set to Russian. In the aftermath of the attack, it was revealed at a Senate Armed Services cyber subcommittee hearing that the
Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior, home, or public security ministries in other countries. Its missions invol ...
was not alerted to the ransomware attack and that the Justice Department was not alerted to the ransom type or amount, prompting discussion about the numerous
information silo An information silo, or a group of such silos, is an insular management system in which one information system or subsystem is incapable of reciprocal operation with others that are, or should be, related. Thus information is not adequately shared ...
s in the government and difficulties of sharing. Blockchain analytics firm Elliptic published a
bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
wallet report showing $90 million in bitcoin ransom payments were made to DarkSide or DarkSide affiliates over the last year, originating from 47 distinct wallets. According to a DarkTracer release of 2226 victim organizations since May 2019, 99 organizations have been infected with the DarkSide malware – suggesting that approximately 47% of victims paid a ransom and that the average payment was $1.9 million. The DarkSide developer had received bitcoins worth $15.5 million (17%), with the remaining $74.7 million (83%) going to the various affiliates.


Partial ransom recovery

The U.S. Department of Justice issued a press release on June 7, 2021, stating that it had seized 63.7 Bitcoins from the original ransom payment. The value of the recovered Bitcoins was only $2.3 million, because the trading price of Bitcoin had fallen since the date of the ransom payment. Through possession of the private key of the ransom account, the FBI was able to retrieve the Bitcoin, though it did not disclose how it obtained the private key.


See also

*
2020 Colonial Pipeline oil spill A major oil spill from the Colonial Pipeline in a nature reserve near Huntersville, North Carolina, United States, began on July 27, 2020. The spill resulted in approximately of gasoline discharge and led to a cleanup effort that is still o ...
* Steamship Authority cyberattack * Health Service Executive cyberattack


References


External links

* {{Hacking in the 2020s, state=autocollapse Cyberattacks on energy sector Data breaches in the United States Hacking in the 2020s May 2021 crimes in the United States Ransomware