What Was the Colonial Pipeline Attack? One Password, No Second Factor

The pipeline was never touched. They shut it off themselves.

On 7 May 2021 Colonial Pipeline, which runs roughly 5,500 miles of pipe and carries about 45% of the fuel consumed on the US East Coast, learned it had been hit by ransomware. Within about an hour it shut the entire pipeline down. Not because the fuel systems were compromised, but because the billing and business systems were, and a pipeline that cannot bill is a pipeline that cannot run.

What was the Colonial Pipeline attack?

A ransomware intrusion by a Russian-speaking crew called DarkSide, who encrypted Colonial's IT systems and stole about 100 gigabytes of data to extort against. Colonial took the operational pipeline offline as a precaution, and the result was a fuel-supply crisis down the Eastern Seaboard: panic-buying, dry filling stations from Virginia to Florida, and emergency declarations in more than a dozen states.

How they got in

Not with a zero-day. Not with anything clever. The attackers logged in through a legacy virtual private network account that was still active, still valid, and no longer meant to be in use. Its password later turned up in a batch of leaked credentials, which is the likeliest way it was obtained, and it did not have multi-factor authentication. One account, one password, no second factor.

That is the whole entry. An old remote-access login that nobody had switched off, protected by a single reusable secret, on a network that fuels the East Coast.

Why shut the pipeline if the pipeline was fine?

Because the systems that meter and bill the fuel were on the IT side that DarkSide had encrypted, and Colonial could not confirm where the intrusion stopped. You do not keep pumping product you can no longer measure, invoice or account for, and you do not assume a network you have just found an intruder in is clean everywhere else. So the operational technology was shut off out of caution, not because it had been breached.

That distinction is the whole lesson. The critical infrastructure held. The thing that failed was an ordinary corporate login, and the physical shutdown was a business decision forced by an IT compromise.

The ransom

Colonial paid. Seventy-five bitcoin, about $4.4 million at the time, handed over the day after the attack. The CEO, Joseph Blount, defended the decision to the Senate Homeland Security Committee on 8 June 2021: with the pipeline down and the East Coast queueing, he was not willing to bet the country on how long recovery would take. He also acknowledged the account that let them in had lacked multi-factor authentication.

On 7 June 2021 the Department of Justice announced it had recovered 63.7 of the 75 bitcoin by seizing the wallet the ransom had moved to. Because the bitcoin price had fallen, the dollars recovered were worth about $2.3 million, less than paid, but most of the coins came back.

What it changed

The Colonial attack is the moment ransomware stopped being an IT-department problem and became a national-security one in the public mind. It produced the TSA's first cybersecurity directives for pipelines, a renewed push for multi-factor authentication on remote access across critical infrastructure, and a sharp increase in attention to the boundary between corporate IT and operational technology.

DarkSide itself went dark within days, its infrastructure seized and its affiliates scattered, the usual life cycle of a ransomware brand that draws too much heat.

The most secure part of the whole operation was the pipeline. The hole was an account it had forgotten it had.

Further reading

  • Joseph Blount, written testimony to the US Senate Committee on Homeland Security and Governmental Affairs, 8 June 2021.
  • US Department of Justice — Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside, 7 June 2021.
  • Mandiant / FireEye — analyses of DarkSide ransomware-as-a-service, 2021.
  • US Government Accountability Office — reports on pipeline cybersecurity following the incident.

EXHIBIT 0031 — COLONIAL PIPELINE

We put it on a shirt. A heavy industrial pipeline gate valve, drawn as an engraving, cast handwheel and bolted flanges on thick welded pipe.

Callouts: ONE LEAKED VPN PASSWORD. NO SECOND FACTOR. THE PIPE WAS FINE. THE BILLING WAS NOT. 75 BITCOIN, PAID IN A DAY.

One password. No second factor.

That's the whole idea.

View the Colonial Pipeline shirt — EXHIBIT 0031

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.