Episode · COLONIAL PIPELINE 2021

The Colonial Pipeline hack, start to finish: one unused password, 5,500 miles shut and a bitcoin clawback

Published 2026-10-01 · 8 min read · Episode 04 of the Cyber Heists long-form series
Colonial Pipeline 2021: one leaked password shut 5,500 miles of fuelPremieres 2026-10-14

On the morning of May 7, 2021, Colonial Pipeline stopped all 5,500 miles of the line that carries nearly half the fuel used on the East Coast, and the trouble traced back to a single password on a remote-access account nobody was supposed to be using.[1] This long read follows the whole Colonial heist in order: the login, the shutdown, the panic at the pumps, the ransom and the clawback, and the one control that would have made the stolen password worthless.

The old VPN password that let them in

Colonial Pipeline describes itself as the largest refined-products pipeline in the country by volume, moving more than 100 million gallons a day of gasoline, diesel, jet fuel and heating oil from the Houston area toward New York Harbor.[2] In 2021 its chief executive, Joseph Blount, told senators the system ran through 13 states and Washington, D.C., with 260 delivery points serving more than 50 million Americans, and that the company had about 950 employees.[1]

Like most companies, Colonial let people reach its network from outside the office through a virtual private network, or VPN, an encrypted tunnel that makes a remote computer behave as if it were plugged in at headquarters. One VPN profile was old. Blount later described it as a legacy account that was not intended to be in use, yet it still worked.[1][3] It was protected by a password and nothing else: no code from a phone, no second step of any kind.[3][4]

According to reporting on the investigation, someone first logged in with that account on April 29, 2021, more than a week before anyone noticed. The password later turned up in a batch of leaked credentials on the dark web, which suggested an employee may have used it somewhere else that had been breached. Investigators at the security firm Mandiant said it remained unclear how the attackers actually got it.[5] Before the ransomware went off, about 100 GB of company data was copied out, a tactic known as double extortion: scramble the files, and threaten to publish what was taken.[5]

Blount told the Senate that the password was a complicated one, not something easy to guess.[4] That detail matters. Complexity protects against guessing, but not against a password that has already leaked. Once it was in the wrong hands, a strong password and a weak one opened the same door.

Why Colonial shut down 5,500 miles of pipeline

Around 5 a.m. on May 7, a Colonial employee found a ransom note on a system in the company's business IT network, the side that handles things like billing and scheduling.[1] The pumps and valves that move fuel sit on a separate operational network. Colonial could not be sure the infection had stayed on its side of that line, so it chose to stop everything. The shutdown began at about 5:55 a.m., and by 6:10 a.m. the whole 5,500-mile system was confirmed shut.[1][3]

The company contacted the FBI that morning and brought in Mandiant to investigate.[1] Then Blount faced the decision he would later call one of the toughest of his life: whether to pay.[6] He said he authorized the payment so that Colonial would have every tool available to get the pipeline running again.[3] On May 8, the company paid about 75 bitcoin, worth roughly $4.4 million at the time.[7][8][4]

The decryption tool the criminals sent back did not save the day. People familiar with the transaction told reporters it was so slow that Colonial kept using its own backups to restore systems.[9] Blount described the keys as imperfect, and said that a month later some financial systems were still not fully back.[4]

Gas lines, panic buying and empty stations

With the line dark, the federal government started clearing other routes for fuel. On May 9, the Federal Motor Carrier Safety Administration issued a regional emergency declaration for 17 states and the District of Columbia, easing driving-hour rules for trucks hauling gasoline, diesel and jet fuel.[10] On May 10, the FBI confirmed that DarkSide ransomware was responsible for the compromise.[11] The same day, the group posted a statement saying its aim was money, not trouble for society, and that it would vet future targets more carefully.[12] Over the following days, federal agencies issued fuel-blend waivers and Jones Act waivers to move fuel by road and by sea.[13]

None of that calmed drivers. People filled cars and spare cans, and the rush itself emptied pumps. By the morning of May 12, about 71% of stations in the Charlotte, North Carolina, metro area had no gasoline, according to the price-tracking service GasBuddy.[14] Later that day, at least 40% of stations in Virginia, Georgia, North Carolina and South Carolina were dry, and the Consumer Product Safety Commission had to warn people to stop putting fuel in plastic bags.[15] Georgia's governor suspended the state gas tax.[15]

Colonial began restarting the line at about 5 p.m. on May 12, and by May 13 it said deliveries had resumed to all of its markets.[15][13] Fuel moves slowly through a pipeline that long, so the shortages lingered. On May 14, 87% of stations in Washington, D.C., were out of gas.[16] On May 18, the national average hit $3.04 a gallon, the highest since 2014.[17][16] One count put the number of stations that ran dry during the episode at more than 15,000.[18]

How the FBI clawed back the bitcoin

DarkSide ran its ransomware as a business with partners. The developers supplied the malware, and affiliates broke into victims and kept most of each ransom, with the developers taking a cut that shrank as payments grew.[19] The blockchain analytics firm Elliptic counted more than $90 million in bitcoin paid to DarkSide over roughly 9 months, and spotted Colonial's 75-bitcoin payment among them. The group reportedly shut down on May 13, less than a week after the Colonial attack.[19]

Bitcoin is not as anonymous as it looks. Every transfer is written to a public ledger, and the FBI followed Colonial's payment through several moves until most of it landed in one address. The Justice Department said the FBI had the private key for that address, the rough equivalent of its password, without saying how it was obtained.[8] On June 7, 2021, the department announced it had seized 63.7 bitcoin under a warrant approved by a federal magistrate judge in the Northern District of California.[8]

That was about 85% of the coins Colonial paid. Because bitcoin's price had fallen since May, the recovered coins were worth about $2.3 million, roughly half the original payment.[8][4] Deputy Attorney General Lisa Monaco put the lesson simply: following the money is still one of the most basic and most powerful tools investigators have.[8]

The Senate hearing and new pipeline rules

Washington did not wait for the hearings to change the rules. On May 27, 2021, the Department of Homeland Security announced a Transportation Security Administration security directive for critical pipelines, the first mandatory cybersecurity rules for the industry after years of voluntary guidance.[20] Operators had to report cyber incidents to the Cybersecurity and Infrastructure Security Agency within 12 hours, name a cybersecurity coordinator available around the clock, and review their own defenses against federal guidelines within 30 days.[20]

On June 8, Blount testified before the Senate Homeland Security and Governmental Affairs Committee.[1][6] He confirmed that the account had no multifactor authentication and that the company was still working out how the password was stolen.[3][1] He said Colonial had since shut down the legacy VPN profile and added more layers of protection, and that crews had driven more than 29,000 miles inspecting the line before restart.[1]

The hunt for the people behind the malware moved slowly. In November 2021, the State Department offered up to $10 million for information identifying or locating DarkSide's leaders, and up to $5 million for information on others who took part in its attacks.[21] Federal regulators also came back to Colonial itself. In May 2022, the Pipeline and Hazardous Materials Safety Administration proposed a penalty of nearly $1 million, saying poor planning for a manual shutdown and restart had made the national impact worse.[22]

How one login became a fuel crisis

Run the chain backward. The stations ran dry because drivers panicked during a shutdown. The shutdown happened because Colonial could not be certain its pipeline controls were safe. The ransomware was there because someone had been inside the business network since late April. And the intruder got in because an account that should have been deleted still accepted a password, with nothing else required.[1][5]

Every link after the first was expensive to break: millions in ransom, days of downtime, emergency waivers in 17 states. The first link was cheap. A second sign-in step on that account, or simply switching off a profile nobody used, would have turned a leaked password into a dead end.

Timeline

DateWhat happened
Apr 29, 2021Intruders first log in through the unused VPN account, according to reports on the investigation.[5]
May 7, 2021Ransom note found around 5 a.m.; all 5,500 miles shut by 6:10 a.m.; FBI contacted.[1]
May 8, 2021Colonial pays about 75 bitcoin, roughly $4.4 million.[7][8]
May 9, 2021Emergency trucking declaration for 17 states and D.C.[10]
May 10, 2021FBI confirms DarkSide ransomware was responsible.[11]
May 12, 2021Pipeline restart begins about 5 p.m. as stations run dry.[15]
May 13, 2021Deliveries resume to all markets; DarkSide reportedly shuts down.[13][19]
May 18, 2021National average gasoline price reaches $3.04 a gallon.[17]
May 27, 2021First mandatory cybersecurity directive for pipelines announced.[20]
Jun 7, 2021Justice Department announces seizure of 63.7 bitcoin, about $2.3 million.[8]
Jun 8, 2021CEO Joseph Blount testifies before a Senate committee.[1]
Nov 4, 2021State Department offers up to $10 million for DarkSide's leaders.[21]

The missing control

The missing control: multifactor authentication on every remote-access account, plus a routine that finds and disables accounts nobody uses. Either one would have stopped this login; together they leave a leaked password with nowhere to go.[1][3]

  1. Turn on a second sign-in step for every way in from outside. That means VPN, remote desktop, email, cloud storage and vendor portals. A code from an app or a tap on a phone is enough to make a stolen password useless on its own.
  2. List every account that can log in remotely. Export the user list from each remote-access system and match every name to a current person with a current reason to be there.
  3. Disable accounts on the day they stop being needed. Add remote access to your offboarding checklist, and review the full list every quarter for old test, vendor and former-employee accounts.
  4. Stop password reuse at work. Give staff a password manager and ask that work passwords never be used on personal sites, since leaked lists are where attackers shop.
  5. Keep offline backups and a written plan. Store copies the network cannot reach, test a restore, and write down who decides on a shutdown and who calls the FBI, so paying is never the only option.

What it means now

Colonial was not taken down by an exotic weapon. It was taken down by an account that should not have existed and a password that should not have been enough. The ransom was partly recovered, and the pipeline came back within a week, but the shortages, the price spike and the new federal rules showed how far one forgotten login can travel.[8][20]

For a small business the stakes are smaller but the shape is identical. Somewhere in your systems there is probably an old account with a password and nothing else. Find it, close it, and put a second lock on everything that remains.

The short version

How the Colonial Pipeline hack happened: one unused VPN account and no MFA: the case file and the Shorts from this case.

Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Related case files

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Senate Homeland Security and Governmental Affairs Committee: Testimony of Joseph A. Blount, Jr., President and CEO, Colonial Pipeline Company (June 8, 2021)
  2. Colonial Pipeline Company: Our Company
  3. CNBC: Colonial Pipeline CEO testifies on first hours of ransomware attack
  4. Cybersecurity Dive: Colonial Pipeline CEO Joseph Blount on the legacy VPN account and the ransom (June 9, 2021)
  5. The Hacker News: Hackers Breached Colonial Pipeline Using Compromised VPN Password
  6. Ohio Capital Journal: Colonial Pipeline CEO: 'One of the toughest decisions I have had to make' to pay a $4.4M ransom
  7. Law Street Media: DOJ Recovers $2.3M in Bitcoin From Colonial Pipeline Ransom Paid to Darkside
  8. U.S. Department of Justice: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside
  9. Al Jazeera: Colonial Pipeline paid hackers $5M to get fuel flowing: Sources
  10. Federal Motor Carrier Safety Administration: Regional Emergency Declaration No. 2021-002 (May 9, 2021)
  11. FBI: FBI Statement on Compromise of Colonial Pipeline Networks
  12. Insurance Journal (Reuters): Colonial Pipeline Ransomware Attackers Say They Seek Cash, Not Chaos
  13. U.S. Department of Energy: Colonial Pipeline Cyber Incident
  14. WBTV: GasBuddy reports 71% of gas stations without fuel in Charlotte metro amid Colonial Pipeline shutdown
  15. NPR: Colonial Restarts Operations After Cyberattack As Panic-Buying Mounts In Southeast
  16. Arab News (AFP): US capital running out of gas, even as Colonial Pipeline recovers
  17. UPI: AAA gas prices report ahead of Memorial Day (May 18, 2021)
  18. Pipeline & Gas Journal: Some US Gas Stations Still Without Fuel After Colonial Pipeline Reopens
  19. Elliptic: DarkSide Ransomware Has Netted Over $90 Million in Bitcoin
  20. Davis Wright Tremaine: TSA pipeline and LNG cybersecurity rules (June 2021)
  21. U.S. Department of State (via GlobalSecurity.org): DarkSide ransomware reward offers (November 4, 2021)
  22. Bulk Transporter: PHMSA proposes nearly $1M in penalties for Colonial Pipeline violations