What was the Colonial Pipeline attack?
The Colonial Pipeline attack was a ransomware attack on 7 May 2021 that brought the largest fuel pipeline in the United States to a halt for six days, causing fuel shortages along the East Coast. The attack only hit the IT network; the pipeline’s operational control systems were not infected. Even so, the company shut the pipeline down as a precaution. That made Colonial Pipeline the textbook example of how an IT incident leads to physical consequences through the dependency between IT and OT.
🗓️ How did the attack unfold?
| Date | Event |
|---|---|
| 29 April 2021 | Attackers log in through a VPN account with a leaked password |
| 7 May 2021 | Ransomware from the DarkSide group encrypts IT systems; the pipeline is shut down |
| 7–8 May 2021 | Colonial pays a ransom of 75 bitcoin, around 4.4 million dollars at the time |
| 12 May 2021 | Pipeline restarted; normal deliveries resume a few days later |
| 7 June 2021 | The US Department of Justice recovers 63.7 bitcoin of the ransom |
🔧 How did the attackers get in?
- An unused VPN account that was still active, without multi-factor authentication
- A reused password that had leaked in an earlier data breach
- Exfiltration first — around 100 GB of data was stolen before encryption (double extortion)
No sophisticated OT attack was needed: a single weakly protected account at the network edge was enough.
🏭 Why did the pipeline stop if OT was not infected?
| Reason | Explanation |
|---|---|
| Uncertainty about the scope | It was not immediately clear whether the ransomware could reach OT |
| Dependency on IT | Billing and recording of delivered fuel ran on IT systems |
| Precautionary principle | Stopping was safer than continuing with potentially infected systems |
The pipeline runs over 8,800 km from Texas to New York and carries around 45% of the fuel for the US East Coast. The shutdown led to panic buying and empty filling stations.
🎯 What lessons can you draw from Colonial Pipeline?
- MFA on all remote access and removing unused accounts (identity management)
- Network segmentation between IT and OT, with an IDMZ and clear dependencies
- Map OT’s dependencies on IT — which business processes must run for production to continue?
- Business continuity — plans to keep OT running if IT fails
- Immutable backups and rehearsed recovery
- An incident response plan with pre-agreed criteria for whether or not to shut down OT
In the US the attack led to binding security directives from the TSA for pipeline operators, and in Europe it added to the urgency of NIS2.
🛠️ When do you shut down OT during an IT incident?
The key question Colonial Pipeline raised: should production stop if only IT is affected? A decision framework prepared in advance avoids having to make that choice under time pressure:
| Question | If the answer is “yes” |
|---|---|
| Is there a connection between the affected IT part and OT? | Break the connection, isolate OT |
| Are OT systems demonstrably clean? | Continuing in island mode is an option |
| Can OT run safely without IT (planning, billing, recording)? | Continue with manual recording |
| Are there legal or contractual metering obligations that require IT? | An alternative recording process is needed |
| Is the safety of people or the environment at stake? | A controlled shutdown takes priority |
A good incident response plan describes this in advance, including who makes the decision and how OT can keep running without IT. Rehearse this scenario regularly with both IT and OT at the table.
❓ Frequently asked questions
Who was behind the Colonial Pipeline attack?
The attack on Colonial Pipeline was carried out with ransomware from DarkSide, a criminal group believed to operate from Russia that rented its ransomware out to other criminals as a service. Shortly after the attack, DarkSide announced it was shutting down. It was not a state attack, but financially motivated crime.
Did Colonial Pipeline pay the ransom?
Yes, Colonial Pipeline paid a ransom of 75 bitcoin, around 4.4 million dollars at the time, to obtain a decryption tool. The tool was so slow that the company relied largely on its own backups for recovery. The FBI later recovered 63.7 bitcoin, worth about 2.3 million dollars at that point because the price had fallen.
Was Colonial Pipeline’s OT hacked?
No, according to Colonial Pipeline and the US authorities, only the IT network was affected. The pipeline’s operational control systems were not infected. The company shut down the pipeline as a precaution, because the scope was unclear and business processes such as billing depended on IT systems.
Which measure could have prevented the attack?
Multi-factor authentication on the VPN account would probably have prevented the attack on Colonial Pipeline. The attackers logged in with a leaked password of an account that was no longer in use. Promptly removing unused accounts and mandatory MFA are therefore basic measures.
What changed after the Colonial Pipeline attack?
After the attack, the US TSA issued binding security directives for pipeline operators, with requirements for segmentation between IT and OT, incident reporting and access control. President Biden also signed an executive order to improve the cybersecurity of the federal government and its suppliers.
📌 In summary
The ransomware attack on Colonial Pipeline (May 2021) only hit IT, yet shut down the largest fuel pipeline in the US for six days. A VPN account without MFA was enough; the lesson is that IT security and the dependencies between IT and OT matter just as much as securing the control systems themselves.
