Historic Colonial Pipeline Ransomware Attack Halts US Fuel Supply
The largest cyberattack on US oil infrastructure forces Colonial Pipeline to shut down operations and pay a multi-million dollar ransom to the DarkSide hacking group.
The Colonial Pipeline, a major American oil pipeline system carrying gasoline and jet fuel to the Southeastern United States, suffers a devastating ransomware cyberattack. The criminal hacking group DarkSide targets the computerized equipment that manages the pipeline, forcing the Colonial Pipeline Company to halt all pipeline operations entirely to contain the threat. This event stands as the largest cyberattack on an oil infrastructure target in the history of the United States.
Under the oversight of the FBI, the company pays the demanded ransom of 75 bitcoin, equivalent to $4.4 million USD, within hours of the attack. DarkSide provides an IT tool to restore the system upon receiving the payment, but the software requires a very long processing time to return the infrastructure to a working state. In response to the resulting fuel supply disruptions, the Federal Motor Carrier Safety Administration issues a regional emergency declaration for 17 states and Washington, D.C.
Investigators reveal that DarkSide steals 100 gigabytes of data from the company servers the day before the actual malware attack occurs. In a subsequent law enforcement action, the Department of Justice recovers 63.7 of the bitcoins, which represents about 84 percent of the original payment. However, a crash in the value of Bitcoin in late May means the recovered cryptocurrency is worth only around $2.3 million USD, roughly half of its original value at the time of the ransom payment.