MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Colonial Pipeline ransomware halts East Coast fuel flow

On 07/05/2021, COLONIAL PIPELINE shut pipeline operations to contain a DarkSide ransomware intrusion in its IT network. The FBI publicly confirmed DarkSide on 10/05/2021. Huntress reports attackers used stolen VPN credentials lacking MFA and exfiltrated ~100 GB of data before encryption. Colonial restarted the pipeline on 12/05/2021 after a six‑day shutdown and paid a $4.4 million ransom, with fuel shortages and emergency measures across the U.S. East Coast and Southeast.

95

Estimated severity

95 / 100

98

Source reliability

98 / 100

Approximate Date

07/05/2021

Targeted Company

COLONIAL PIPELINE

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

East Coast · United StatesSoutheast · United States

Operational Impact

Duration

6 days

Financial impact (USD M)

$4.4M

Impact types

Transportation disruptionService unavailabilityOperational disruptionLogistics delay

Affected sectors

Energy & UtilitiesTransportation

Affected departments

Information TechnologyFacilities & Physical Operations

Attack Profile

Attack types

RansomwareUse of stolen credentialsData exfiltration

Attributed threat actors

DARKSIDE

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.