The encyclopedia · Software & IT · Operational decision · 2021
Colonial Pipeline paid $4.4M in ransom — because it couldn't find the backup
A ransomware attack shut down the US East Coast's largest fuel pipeline for 6 days in 2021. Colonial paid $4.4M in Bitcoin. The FBI later recovered most of it.
Colonial Pipeline · 2021-05
What happened
In May 2021, the Colonial Pipeline — the largest refined fuel pipeline in the US, carrying 45% of the East Coast's gasoline, diesel and jet fuel — was shut down after a ransomware attack by the DarkSide criminal group. The attackers encrypted Colonial's billing and IT systems, and the company took the pipeline offline as a precaution.
The shutdown lasted six days, causing fuel shortages, panic buying and price spikes across the US East Coast. Colonial paid approximately $4.4 million in Bitcoin ransom to obtain the decryption key. The FBI later recovered approximately $2.3 million of the ransom by tracing the Bitcoin transaction.
The case exposed the vulnerability of critical infrastructure to cyberattack and the danger of inadequate backup and recovery systems. Colonial's decision to pay the ransom was controversial: it restored operations faster but funded criminal activity and set a precedent. The attack prompted the US government to elevate cybersecurity for critical infrastructure and to treat ransomware as a national security threat.
Why it happened
- DarkSide ransomware encrypted Colonial's billing and IT systems, forcing the pipeline offline.
- The shutdown lasted 6 days, causing fuel shortages and panic buying across the US East Coast.
- Colonial paid $4.4M in Bitcoin ransom; the FBI later recovered ~$2.3M.
- The attack exposed critical infrastructure's vulnerability to cyberattack and inadequate backup systems.
The lesson
Critical infrastructure that runs on software can be held hostage. Colonial paid $4.4M because its backup couldn't restore operations without the attacker's key. The backup is the product.
Aftermath
The FBI recovered ~$2.3M of the ransom. The US government issued executive orders on pipeline cybersecurity. Colonial overhauled its security architecture. The case prompted the TSA to issue mandatory cybersecurity directives for pipeline operators.
Sources
- Colonial Pipeline ransomware attack — Wikipedia
- GAO-21-105263, July 2021 — Critical Infrastructure Protection: TSA Is Taking Steps to Address Some Pipeline Security Program Weaknesses (May 2021 Colonial Pipeline DarkSide ransomware attack; TSA cybersecurity directives)
spotted an error? The club wants to know.
More like this
Nikola's truck rolled downhill — and the $1B fraud rolled into court
A software change took Verizon's 5G core down 10 hrs — 2M lost calling, texting and 911
Meta's 'designed for privacy' glasses shipped users' intimate footage to Kenya reviewers
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.