Case file · COLONIAL PIPELINE 2021

How the Colonial Pipeline hack happened: one unused VPN account and no MFA

Published 2026-09-26 · 4 min read

One of the biggest fuel pipelines in the United States was shut down by a single password on an old remote-access account that nobody was supposed to be using anymore. The account had no second login step, so the password alone opened the door.[1][2] This case file covers what happened in May 2021, how the attackers got in, what it cost, and the one control that would have stopped it.

What happened

Shortly before 5 a.m. on May 7, 2021, an employee at Colonial Pipeline found a ransom note on a system in the company's business IT network. Within about an hour the company began shutting down its entire pipeline, all 5,500 miles of it, and the shutdown was complete by roughly 6:10 a.m. The goal was to keep the malicious software from spreading toward the systems that actually move fuel. The company contacted the FBI the same day.[1][2]

On May 8, Colonial paid the attackers about 75 bitcoin, worth roughly $4.4 million at the time.[2][4] Chief executive Joseph Blount later told senators it was one of the hardest decisions of his life, made to get critical infrastructure running again as fast as possible.[2]

On May 10, the FBI publicly confirmed that DarkSide ransomware was responsible for the compromise.[3] Meanwhile the pipeline, which carries about 45% of the East Coast's gasoline, diesel and jet fuel, stayed dark. Drivers across the Southeast rushed to fill tanks and extra containers, and the rush itself emptied stations. At the worst point, at least 40% of stations in Virginia, Georgia, North Carolina and South Carolina were out of fuel, and the national average price topped $3 a gallon for the first time in seven years.[5]

Colonial began restarting around 5 p.m. on May 12, and by May 13 product deliveries had resumed to all markets.[5][6] In between, federal agencies loosened trucking-hour limits, fuel-blend rules and shipping restrictions to get fuel moving by other routes.[6]

How they got in

At a Senate Homeland Security and Governmental Affairs Committee hearing on June 8, 2021, Blount explained the entry point. The attackers logged in through a legacy virtual private network (VPN) profile. A VPN is the secure tunnel employees use to reach the company network from outside the office. This particular profile was no longer meant to be in use, but it had never been switched off.[1][2]

The account was protected by a password alone. Blount said the password was a complicated one, but that did not matter: once someone had it, there was no second check, such as a code on a phone, standing between them and the network.[1][2] How the attackers obtained the password was not established in the testimony covered here.

Once inside, the attackers deployed ransomware, software that scrambles files and demands payment to unscramble them. It hit the business side of the company. Colonial shut down the operational side as a precaution because it could not yet be sure how far the intrusion reached.[1]

What it cost

There was one partial recovery. On June 7, 2021, the Justice Department announced it had seized about 63.7 bitcoin, then worth roughly $2.3 million, of the ransom paid to DarkSide. Investigators followed the payment across the public bitcoin ledger to a specific address and, with a seizure warrant approved by a federal magistrate judge in the Northern District of California, took control of the funds. Because bitcoin's price had fallen after the payment, the 63.7 coins were worth only about half of what Colonial originally paid.[4] Deputy Attorney General Lisa Monaco described ransom payments as the fuel that keeps digital extortion running.[4]

The missing control

The missing control: multifactor authentication on every remote-access account, together with removing accounts that are no longer used.

Multifactor authentication (MFA) means a login needs something besides the password, usually a code from an app or a tap on a phone. With MFA on that VPN profile, a stolen or guessed password would have been only half a key, and the attackers would have hit a locked door. Removing the account entirely would have been even better: an account that does not exist cannot be abused.

A strong password was not enough on its own. Passwords leak, get reused, and get phished, and a complicated one is still just one secret. The lesson from this case is less about sophisticated hacking and more about housekeeping: one forgotten login, with one layer of protection, put fuel for much of the East Coast on hold.

What to do in your business

Watch the case
Episode drops 2026-09-29
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More case files

Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.

Sources
  1. CNBC: Colonial Pipeline CEO testifies on first hours of ransomware attack
  2. Ohio Capital Journal: Colonial Pipeline CEO: 'One of the toughest decisions I have had to make' to pay a $4.4M ransom
  3. FBI: FBI Statement on Compromise of Colonial Pipeline Networks
  4. U.S. Department of Justice: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside
  5. NPR: Colonial Restarts Operations After Cyberattack As Panic-Buying Mounts In Southeast
  6. U.S. Department of Energy: Colonial Pipeline Cyber Incident