How the Colonial Pipeline hack happened: one unused VPN account and no MFA
One of the biggest fuel pipelines in the United States was shut down by a single password on an old remote-access account that nobody was supposed to be using anymore. The account had no second login step, so the password alone opened the door.[1][2] This case file covers what happened in May 2021, how the attackers got in, what it cost, and the one control that would have stopped it.
What happened
Shortly before 5 a.m. on May 7, 2021, an employee at Colonial Pipeline found a ransom note on a system in the company's business IT network. Within about an hour the company began shutting down its entire pipeline, all 5,500 miles of it, and the shutdown was complete by roughly 6:10 a.m. The goal was to keep the malicious software from spreading toward the systems that actually move fuel. The company contacted the FBI the same day.[1][2]
On May 8, Colonial paid the attackers about 75 bitcoin, worth roughly $4.4 million at the time.[2][4] Chief executive Joseph Blount later told senators it was one of the hardest decisions of his life, made to get critical infrastructure running again as fast as possible.[2]
On May 10, the FBI publicly confirmed that DarkSide ransomware was responsible for the compromise.[3] Meanwhile the pipeline, which carries about 45% of the East Coast's gasoline, diesel and jet fuel, stayed dark. Drivers across the Southeast rushed to fill tanks and extra containers, and the rush itself emptied stations. At the worst point, at least 40% of stations in Virginia, Georgia, North Carolina and South Carolina were out of fuel, and the national average price topped $3 a gallon for the first time in seven years.[5]
Colonial began restarting around 5 p.m. on May 12, and by May 13 product deliveries had resumed to all markets.[5][6] In between, federal agencies loosened trucking-hour limits, fuel-blend rules and shipping restrictions to get fuel moving by other routes.[6]
How they got in
At a Senate Homeland Security and Governmental Affairs Committee hearing on June 8, 2021, Blount explained the entry point. The attackers logged in through a legacy virtual private network (VPN) profile. A VPN is the secure tunnel employees use to reach the company network from outside the office. This particular profile was no longer meant to be in use, but it had never been switched off.[1][2]
The account was protected by a password alone. Blount said the password was a complicated one, but that did not matter: once someone had it, there was no second check, such as a code on a phone, standing between them and the network.[1][2] How the attackers obtained the password was not established in the testimony covered here.
Once inside, the attackers deployed ransomware, software that scrambles files and demands payment to unscramble them. It hit the business side of the company. Colonial shut down the operational side as a precaution because it could not yet be sure how far the intrusion reached.[1]
What it cost
- Ransom: about 75 bitcoin, roughly $4.4 million, paid on May 8, 2021.[2][4]
- Downtime: a shutdown of about six days, with full recovery of business systems taking far longer.[2][6]
- Public impact: widespread station outages and price spikes across the Southeast, plus emergency federal waivers to move fuel by truck and ship.[5][6]
There was one partial recovery. On June 7, 2021, the Justice Department announced it had seized about 63.7 bitcoin, then worth roughly $2.3 million, of the ransom paid to DarkSide. Investigators followed the payment across the public bitcoin ledger to a specific address and, with a seizure warrant approved by a federal magistrate judge in the Northern District of California, took control of the funds. Because bitcoin's price had fallen after the payment, the 63.7 coins were worth only about half of what Colonial originally paid.[4] Deputy Attorney General Lisa Monaco described ransom payments as the fuel that keeps digital extortion running.[4]
The missing control
The missing control: multifactor authentication on every remote-access account, together with removing accounts that are no longer used.
Multifactor authentication (MFA) means a login needs something besides the password, usually a code from an app or a tap on a phone. With MFA on that VPN profile, a stolen or guessed password would have been only half a key, and the attackers would have hit a locked door. Removing the account entirely would have been even better: an account that does not exist cannot be abused.
A strong password was not enough on its own. Passwords leak, get reused, and get phished, and a complicated one is still just one secret. The lesson from this case is less about sophisticated hacking and more about housekeeping: one forgotten login, with one layer of protection, put fuel for much of the East Coast on hold.
What to do in your business
- Turn on MFA for every way in from outside. That includes VPN, remote desktop, email, cloud file storage and any vendor portal. If a system cannot do MFA, put it behind something that can.
- List every remote-access account this week. Pull the user list from your VPN, remote-access tool and email system and match each name to a current person with a current need.
- Disable old accounts the day someone leaves or a project ends. Make shutting off access part of your offboarding checklist, and review the list at least every quarter.
- Keep business systems and critical operations separate. If your office network gets hit, you want the equipment, point-of-sale or production systems to keep running on their own.
- Know who you will call before you need to. Write down your IT contact, your cyber insurance carrier and your local FBI field office, and keep offline backups so paying a ransom is never your only option.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- CNBC: Colonial Pipeline CEO testifies on first hours of ransomware attack
- Ohio Capital Journal: Colonial Pipeline CEO: 'One of the toughest decisions I have had to make' to pay a $4.4M ransom
- FBI: FBI Statement on Compromise of Colonial Pipeline Networks
- U.S. Department of Justice: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside
- NPR: Colonial Restarts Operations After Cyberattack As Panic-Buying Mounts In Southeast
- U.S. Department of Energy: Colonial Pipeline Cyber Incident