Historic DarkSide Ransomware Attack Halts Major US Fuel Pipeline
The DarkSide hacking group launches a devastating ransomware attack on the Colonial Pipeline, forcing the company to halt operations and pay a multi-million dollar ransom. This unprecedented cyberevent highlights the severe vulnerabilities in American oil infrastructure.
The Colonial Pipeline, a crucial oil pipeline system carrying gasoline and jet fuel from Texas to the Southeastern United States, suffers a massive ransomware cyberattack. The malicious software targets the computerized equipment that manages the pipeline, forcing the Colonial Pipeline Company to halt all pipeline operations entirely to contain the threat. This unprecedented event stands as the largest cyberattack on an oil infrastructure target in United States history.
The FBI identifies the criminal hacking group DarkSide as the responsible party, noting that the group steals 100 gigabytes of data from company servers just one day before deploying the malware. Under the oversight of the FBI, Colonial Pipeline pays the demanded ransom of 75 bitcoin, equivalent to $4.4 million USD, within hours to receive a decryption tool. However, this provided IT tool requires a very long processing time to restore the system to a functional state.
The attack causes significant supply chain disruptions, prompting the Federal Motor Carrier Safety Administration to issue a regional emergency declaration for 17 states and Washington, D.C. to keep fuel supply lines open. In a subsequent development, the Department of Justice announces the recovery of 63.7 bitcoins, or about 84 percent of the original ransom payment. Due to a crash in the value of Bitcoin, the recovered funds are worth only around $2.3 million USD, which is roughly half of their original value at the time of payment.