United States
USA
On 07/05/2021, COLONIAL PIPELINE shut pipeline operations to contain a DarkSide ransomware intrusion in its IT network. The FBI publicly confirmed DarkSide on 10/05/2021. Huntress reports attackers used stolen VPN credentials lacking MFA and exfiltrated ~100 GB of data before encryption. Colonial restarted the pipeline on 12/05/2021 after a six‑day shutdown and paid a $4.4 million ransom, with fuel shortages and emergency measures across the U.S. East Coast and Southeast.
Estimated severity
95 / 100
Source reliability
98 / 100
Approximate Date
07/05/2021
Targeted Company
COLONIAL PIPELINE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
Duration
6 days
Financial impact (USD M)
$4.4M
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone