The Colonial Pipeline Ransomware Attack: A Verified Account of What Happened

Key takeaways
- The Colonial Pipeline ransomware attack began with valid credentials on a forgotten virtual private network account that lacked multi-factor authentication rather than with a phishing email.
- DarkSide encrypted corporate information technology systems only, and the pipeline shutdown was a precaution taken because containment could not be confirmed.
- Colonial Pipeline Company paid the DarkSide ransomware ransom and still restored from its own backups, because the decryption tool ran too slowly to be useful.
- Much of what circulates about the Colonial Pipeline ransomware attack traces to DarkSide's own claims in preference to anything the company confirmed.
- Federal investigators recovered most of the ransom by quantity, though the method used to obtain the wallet key has never been disclosed.
- The regulatory and legal consequences of the Colonial Pipeline ransomware attack ran years past the incident and are absent from most coverage.
- Whether DarkSide was shut down by law enforcement or absconded with affiliate funds remains genuinely unresolved.
The Colonial Pipeline ransomware attack was a May 2021 intrusion by the DarkSide ransomware group against Colonial Pipeline Company, operator of the largest refined-products pipeline system in the United States. Cyberattackers entered through a legacy virtual private network account on April 29, 2021. The company halted the pipeline on May 7, paid 75 bitcoin, and restarted on May 12, 2021.

Few cybersecurity incidents have been documented as heavily as the Colonial Pipeline ransomware attack, and few carry as much circulating detail that no primary source supports. Sworn Congressional testimony, a federal seizure affidavit, and a regulatory enforcement action all exist, yet the widely repeated account still rests on figures DarkSide supplied about itself and on reporting that stopped in June 2021. This article covers:
- How the Colonial Pipeline ransomware attack actually began, and why the phishing explanation is wrong;
- A Colonial Pipeline ransomware attack timeline that separates first access from detection;
- What DarkSide claimed against what Colonial Pipeline Company confirmed;
- The regulatory and legal aftermath of the Colonial Pipeline ransomware attack through 2025;
- Which questions about the Colonial Pipeline ransomware attack remain unresolved.
Dormant credentials and reused passwords sit unnoticed inside most enterprise environments. Adaptive Security surfaces that human-layer exposure and turns it into measurable, monitored risk reduction across the workforce.
Quick Facts About the Colonial Pipeline Ransomware Attack
| Field | Detail | Confidence |
|---|---|---|
| Victim | Colonial Pipeline Company, Alpharetta, Georgia | CONFIRMED |
| Threat actor | DarkSide, assessed Russia-based | CONFIRMED, Federal Bureau of Investigation, May 10, 2021 |
| Operating model | Ransomware-as-a-Service, operator plus affiliates | CONFIRMED, CISA and FBI Joint Cybersecurity Advisory AA21-131A |
| First access | April 29, 2021 | CONFIRMED |
| Initial access vector | Valid credentials, legacy virtual private network profile, no multi-factor authentication | CONFIRMED |
| Credential acquisition method | Not established | UNKNOWN |
| Detection | May 7, 2021, before 5:00 a.m. | CONFIRMED |
| Full shutdown | May 7, 2021, 6:10 a.m. | CONFIRMED |
| Systems encrypted | Corporate information technology only; operational technology not encrypted | CONFIRMED |
| Ransom paid | 75 bitcoin, approximately 4.4 million dollars, May 8, 2021 | CONFIRMED |
| Amount recovered | Approximately 63.7 bitcoin, approximately 2.3 million dollars, June 7, 2021 | CONFIRMED |
| Restart | May 12, 2021; normal operations May 15, 2021 | CONFIRMED |
| Data volume taken | Approximately 100 gigabytes, as claimed by DarkSide | REPORTED, DarkSide-derived |
| Individuals notified | 5,810 | CONFIRMED |
| Ransom note filename | README.[victim_ID].TXT | CONFIRMED |
| Free decryptor | Available for an earlier variant only, superseded before the version used here | CONFIRMED |
| Arrests or indictments | None publicly named for this cyberattack | CONFIRMED |
What the Colonial Pipeline Ransomware Attack Was and Who It Hit
The Colonial Pipeline ransomware attack struck one privately held fuel transportation company whose physical scale, in preference to its security posture, determined how far the consequences reached. Colonial Pipeline Company operates the largest refined-products pipeline system in the United States, running from Houston, Texas to Linden, New Jersey through four mainlines carrying gasoline, diesel, and jet fuel.
The company is headquartered in Alpharetta, Georgia, the site of the control center where the ransom note was found on May 7, 2021. Five partners held the business privately in 2021 and sold their interests to a Brookfield Infrastructure affiliate in 2025. Private ownership limits what the public record contains about ransomware attacks on critical infrastructure.
Why the Colonial Pipeline Ransomware Attack Mattered Beyond One Company
The reach of the Colonial Pipeline ransomware attack followed directly from how much fuel the system carries for how many people. According to Colonial Pipeline Company's Public System Description 2021, the system carries approximately 45 percent of the fuel consumed on the United States East Coast and serves more than 50 million people across 14 states.
Downstream dependence extended past the company itself, since retailers, airports, and distributors across the Southeast and mid-Atlantic draw supply from the same mainlines. The consequence of the Colonial Pipeline ransomware attack flowed from that scale and from a shutdown decision made under uncertainty.
Was Colonial Pipeline Specifically Targeted in the Ransomware Attack?
Nothing in the evidentiary record indicates that Colonial Pipeline Company was selected for its strategic significance. DarkSide stated after the incident that the target had been chosen by an affiliate in preference to the operators, a claim the group made about itself that no independent source has verified. The practical takeaway from the Colonial Pipeline ransomware attack is that target selection sits decoupled from target significance.
Measure human-layer exposure before scale converts one credential into a national event. Adaptive Security gives security teams continuous visibility into workforce risk across every department and role.
How the Colonial Pipeline Ransomware Attack Unfolded Over Time
Existing coverage of the Colonial Pipeline ransomware attack routinely collapses four separate events into one date, which makes the sequence illegible and distorts every lesson drawn from it. First access, detection, public disclosure, and the threat actor's own public statement happened on three different days across a twelve-day span. Separating them is what turns a Colonial Pipeline ransomware attack timeline into something a security team can reason about.
The Four Dates Most Accounts of the Colonial Pipeline Ransomware Attack Collapse Into One
The Colonial Pipeline ransomware attack timeline rests on four distinct anchor points, each separately sourced:
- First access occurred on April 29, 2021, when a DarkSide affiliate authenticated to a legacy virtual private network profile;
- Detection occurred on May 7, 2021, before 5:00 a.m., when a control room employee saw a ransom note on a screen;
- Public disclosure occurred later on May 7, 2021, through a Colonial Pipeline Company statement;
- The threat actor's public claim came on May 10, 2021, when DarkSide issued a statement describing itself as apolitical.
That sequence produces approximately eight days of undetected dwell time, bounded at the front end by Mandiant's finding of no cyberattacker activity before April 29, 2021. The distinction changes the lesson: the Colonial Pipeline ransomware attack was a detection failure well before it became a shutdown decision.
Colonial Pipeline Ransomware Attack Timeline: April 29 to May 15, 2021
The core sequence of the Colonial Pipeline ransomware attack runs from first access to the return of normal operations across seventeen days. Colonial Pipeline Company detected the intrusion on the eighth day, halted the system within seventy minutes of that discovery, and paid the ransom the following morning. Federal attribution and a joint advisory both followed within four days of the shutdown.
| Date | Event | Confidence |
|---|---|---|
| April 29, 2021 | Cyberattacker authenticates to a legacy Colonial virtual private network profile using valid credentials with no multi-factor authentication | CONFIRMED |
| May 6, 2021 | Data taken from Colonial Pipeline Company's corporate environment | CONFIRMED |
| May 7, 2021, before 5:00 a.m. | Control room employee finds the ransom note and notifies an operations supervisor | CONFIRMED |
| May 7, 2021, 6:10 a.m. | Entire pipeline system shut down, the first full shutdown in 57 years | CONFIRMED |
| May 8, 2021 | Colonial Pipeline Company pays 75 bitcoin through outside lawyers and negotiators | CONFIRMED |
| May 9, 2021 | Federal Motor Carrier Safety Administration issues Regional Emergency Declaration No. 2021-002 | CONFIRMED |
| May 10, 2021 | Federal Bureau of Investigation publicly attributes the cyberattack to DarkSide | CONFIRMED |
| May 11, 2021 | CISA and FBI publish Joint Cybersecurity Advisory AA21-131A | CONFIRMED |
| May 12, 2021 | Colonial Pipeline Company restarts pipeline operations | CONFIRMED |
| May 13, 2021 | DarkSide announces closure, claiming lost servers and withdrawn funds | CLAIMED by DarkSide |
| May 15, 2021 | Colonial Pipeline Company returns to normal operations | CONFIRMED |
What Followed the Colonial Pipeline Ransomware Attack Through 2025
Consequences of the Colonial Pipeline ransomware attack continued for four years past the restart, and this is where almost every competing account stops entirely.
| Date | Event | Confidence |
|---|---|---|
| June 7, 2021 | Department of Justice announces seizure of approximately 63.7 bitcoin | CONFIRMED |
| June 8 and 9, 2021 | Joseph Blount and Charles Carmakal testify before Senate and House committees | CONFIRMED |
| July 20, 2021 | Transportation Security Administration announces Security Directive Pipeline-2021-02 | CONFIRMED |
| August 13, 2021 | Colonial Pipeline Company notifies state Attorneys General of a breach affecting 5,810 individuals | CONFIRMED |
| May 5, 2022 | PHMSA issues a Notice of Probable Violation and Proposed Compliance Order | CONFIRMED |
| June 17, 2022 | Ramon Dickerson et al. v. Colonial Pipeline Co. dismissed in full | CONFIRMED |
| 2025 | Colonial partners complete sale of their interests to a Brookfield Infrastructure affiliate | CONFIRMED |
The record of the Colonial Pipeline ransomware attack therefore extends four years past the restart. Federal directives arrived within eleven weeks, the breach notification followed in August 2021, and the proposed civil penalty came almost a year later. Both class actions ended in dismissal, and ownership changed hands in 2025.
Adaptive Security closes the reporting gap that lets eight days of intrusion pass unnoticed. Continuous workforce risk monitoring converts silent dwell time into early, actionable signals for security teams.
How Cyberattackers Got In: The Colonial Pipeline Ransomware Attack Chain
The entry point of the Colonial Pipeline ransomware attack is established under oath, and the middle of the intrusion is not publicly documented at all. Most published attack chains for the Colonial Pipeline ransomware attack fill that gap with strain-level assumptions about DarkSide tradecraft, which describes what the group did elsewhere compared to what happened here.
The Credential That Caused the Colonial Pipeline Ransomware Attack
A DarkSide affiliate authenticated to a Colonial Pipeline Company virtual private network profile using a valid username and password on an account that had never been disabled. According to Charles Carmakal's Prepared Statement Before the United States House Committee on Homeland Security 2021, the earliest evidence of compromise at Colonial Pipeline Company was April 29, 2021, through a legacy virtual private network profile that did not require multi-factor authentication.
Carmakal testified that the password was relatively complex in length, special characters, and case set, but it had been used on multiple websites. Joseph Blount indicated in Senate questioning that Colonial Pipeline Company's information technology team was unaware the profile existed. The Colonial Pipeline ransomware attack therefore began with an account nobody was managing.
Why the Phishing Explanation of the Colonial Pipeline Ransomware Attack Is Wrong
Coverage attributing the Colonial Pipeline ransomware attack to a phishing email contradicts the only investigative account given under oath. Reporting from June 4, 2021 states that the password was later located inside a batch of leaked passwords on the dark web, and Carmakal hedged that finding, saying investigators may never know how the credential was obtained. Whether that batch was the affiliate's source remains unknown, as does how the matching username was obtained.
What Is Not Known About the Colonial Pipeline Ransomware Attack Chain
No public source documents the tooling, privilege escalation path, or lateral movement inside Colonial Pipeline Company's environment between April 29 and May 6, 2021. This is the largest evidentiary gap in the Colonial Pipeline ransomware attack record, open since 2021.
Strain-level DarkSide tradecraft documented in threat intelligence literature is not evidence of what occurred here. An accurate rendering of the Colonial Pipeline ransomware attack chain presents that segment as an eight-day undetected interval.
Encryption and Double Extortion in the Colonial Pipeline Ransomware Attack
DarkSide encrypted corporate information technology systems and appended a victim-specific eight-character extension to affected files, writing a ransom note named README.[victim_ID].TXT. According to the Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation Joint Cybersecurity Advisory AA21-131A of May 11, 2021, no indication existed that operational technology networks were directly affected.
The extortion model combined encryption with separate data theft and a stated intention to publish on the leak site, documented across the DarkSide ransomware strain profile. Colonial Pipeline Company's data was never published, which is consistent with payment.
When one reused password opens a legacy account, complexity policy has already failed. Adaptive Security monitors credential reuse and dormant access so identity hygiene stays measurable across the workforce.
DarkSide: The Ransomware Group Behind the Colonial Pipeline Attack
DarkSide operated as a service business rather than a single crew, which explains most of what followed the Colonial Pipeline ransomware attack. A core operator group built and maintained the ransomware while separate affiliates ran the intrusions, so the choices made against Colonial Pipeline Company were an affiliate's choices. The alternate rendering "Darkside" appears frequently in coverage and refers to the same operation.
How the DarkSide Ransomware-as-a-Service Model Worked
According to the CISA and FBI Joint Cybersecurity Advisory AA21-131A published on May 11, 2021, DarkSide ran a Ransomware-as-a-Service operation in which operators supplied the ransomware, the leak site, and the payment infrastructure while affiliates conducted the intrusions. Reported revenue splits favored affiliates, rising from roughly 75 percent on smaller ransoms toward roughly 90 percent on the largest.
Affiliate recruitment ran through Russian-language cybercrime forums under the operator handle "darksupp", and the ransomware carried language checks that avoided executing on systems configured for Russian and other Commonwealth of Independent States languages. According to BleepingComputer's DarkSide Ransomware Attack Reporting 2021, Brenntag SE paid 78.29 bitcoin on May 11, 2021 after negotiating down from an initial demand of 133.65 bitcoin. Blockchain analysis firm Elliptic assessed that the affiliate shares of the Brenntag and Colonial ransoms reached the same wallet, indicating one affiliate ran both intrusions.
What DarkSide Claimed About Its Targets Before the Colonial Pipeline Attack
DarkSide claimed publicly that it vetted targets and avoided hospitals, schools, nonprofits, and government entities. Every element of that position is a DarkSide claim about itself, and no independent source has verified any part of it.
The group also publicized donations of 0.88 bitcoin each to Children International and The Water Project in October 2020, a DarkSide claim that drew a statement from Children International that it would not keep funds derived from crime. The Colonial Pipeline ransomware attack directly contradicted the targeting restrictions DarkSide claimed to observe. That contradiction is the reason every DarkSide statement in the record of this incident carries reduced weight.
Accountability for DarkSide After the Colonial Pipeline Ransomware Attack
The Federal Bureau of Investigation publicly attributed the Colonial Pipeline ransomware attack to DarkSide on May 10, 2021 and assessed the operation as Russia-based. Formal accountability stopped there.
According to the United States Department of State's Rewards for Justice Announcement 2021, the government offered up to 10 million dollars for information identifying DarkSide leadership and up to 5 million dollars for information on affiliates. No DarkSide member has been publicly indicted, arrested, or sanctioned by name in connection with the Colonial Pipeline ransomware attack, and the January 2022 Russian Federal Security Service action targeted the REvil operation in preference to DarkSide.
Behind every ransomware brand sits an affiliate workforce that outlives the brand itself. Adaptive Security prepares employees for the intrusion patterns affiliates reuse long after operators disappear.
The Impact of the Colonial Pipeline Ransomware Attack on Fuel Supply and the Public
The visible fuel shortages that followed the Colonial Pipeline ransomware attack were a demand-side event driven by panic buying, not a physical loss of supply. Product remained in terminals and in the system, and the pipeline sustained no damage from the Colonial Pipeline ransomware attack.
Operational Disruption From the Colonial Pipeline Ransomware Attack
Approximately 5,500 miles of pipeline sat offline from the May 7, 2021 shutdown until the May 12, 2021 restart, with normal operations restored on May 15, 2021. All four mainlines carrying gasoline, diesel, and jet fuel were affected.
Colonial Pipeline Company inspected approximately 29,000 miles of pipeline and found no physical damage, confirming that the Colonial Pipeline ransomware attack never reached the asset. The company conducted localized manual operations before the official restart.
Fuel Shortages and Price Effects After the Colonial Pipeline Ransomware Attack
According to GasBuddy's Fuel Station Outage Tracking Data 2021, reported by analyst Patrick De Haan, station outages peaked on May 13, 2021 at approximately 71 percent of stations in North Carolina and approximately 16,193 stations across the Southeast, with rates of approximately 55 percent in Virginia and approximately 47 percent in the District of Columbia. The retail effect of the Colonial Pipeline ransomware attack peaked after the pipeline had restarted.
National price data recorded the same pattern. According to the United States Energy Information Administration's Today in Energy 2021, the national average retail regular gasoline price reached 3.03 dollars per gallon on May 17, 2021, the first time above 3.00 dollars since October 27, 2014, as recorded in the Energy Information Administration fuel price data.
Government and Aviation Response to the Colonial Pipeline Ransomware Attack
Federal and state authorities responded to the Colonial Pipeline ransomware attack by relaxing transport rules in preference to intervening directly. Georgia, North Carolina, Virginia, and Florida each declared states of emergency.
According to the Federal Motor Carrier Safety Administration's Regional Emergency Declaration No. 2021-002 2021, hours-of-service relief for fuel haulers extended across 17 states and the District of Columbia, and the declaration was amended on May 12, 2021 to add West Virginia. American Airlines added intermediate fuel stops to two long-haul routes from Charlotte Douglas International Airport, routing a Honolulu service through Dallas Fort Worth and a London service through Boston Logan.
Correcting the Record on the Colonial Pipeline Ransomware Attack's Reach
The figure of 17 states describes the scope of the Federal Motor Carrier Safety Administration emergency declaration in preference to where fuel shortages occurred. Coverage of the Colonial Pipeline ransomware attack repeatedly presents that number as the shortage footprint.
Actual shortages concentrated in the Southeast and mid-Atlantic, with the sharpest station-level effects in North Carolina, Virginia, South Carolina, Georgia, and the District of Columbia. The conflation persists because the declaration was the most quotable federal document of the Colonial Pipeline ransomware attack, and its state count spread faster than the outage data.
No amount of physical resilience prevents a demand-side panic once operations halt publicly. Adaptive Security reduces the human-layer exposure that turns a corporate intrusion into an operational stoppage.
What Data DarkSide Took in the Colonial Pipeline Ransomware Attack

Two very different numbers circulated for data loss in the Colonial Pipeline ransomware attack, but only one of them came from Colonial Pipeline Company. One measures a claimed volume of files and originates with the group that stole them. The other measures affected individuals and appears in a regulatory notification the company was legally obliged to file, which is the only defensible measure of exposure from this incident.
Claimed Versus Confirmed Data Loss in the Colonial Pipeline Ransomware Attack
The distinction between what DarkSide claimed and what Colonial Pipeline Company confirmed shapes every accurate account of the Colonial Pipeline ransomware attack, and the claim followed the standard commercial pattern in how ransomware groups use double extortion.
| Claimed by DarkSide | Confirmed by Colonial Pipeline Company | Confidence |
|---|---|---|
| Approximately 100 gigabytes of data taken from the corporate environment, a figure that entered circulation through DarkSide extortion claims relayed by media | Personal information of 5,810 individuals, accessed on May 6, 2021 | REPORTED for the DarkSide claim; CONFIRMED for the company figure |
| Threatened publication on the DarkSide leak site if payment was withheld | Two years of credit monitoring offered to notified individuals | CLAIMED by DarkSide; CONFIRMED for the company response |
Reference works and vendor explainers routinely state the 100 gigabyte figure as an established fact. However, it remains a DarkSide claim that Colonial Pipeline Company has never confirmed or verified.
The two figures also measure different quantities and are frequently conflated in accounts of the Colonial Pipeline ransomware attack. One describes a claimed volume of files, and the other describes a counted population of affected individuals recorded in a regulatory filing.
Who Was Notified After the Colonial Pipeline Ransomware Attack?
According to Colonial Pipeline Company's Notice of Data Breach 2021, filed with state Attorneys General, the personal information of 5,810 individuals was accessed on May 6, 2021 and those individuals were notified on August 13, 2021.
The categories disclosed in that notification covered names, contact information, dates of birth, Social Security numbers, government-issued identification including driver's license, military, and tax identification numbers, and health and health insurance information. Roughly three months separated the access date from the notification date, a gap that sits inside the confirmed record of the Colonial Pipeline ransomware attack and receives almost no attention in coverage of it.
Most organizations discover the scope of a data theft from regulators in preference to cyberattackers. Adaptive Security strengthens the credential and access behavior that determines how much data leaves.
The Ransom Payment and Recovery in the Colonial Pipeline Ransomware Attack
Colonial Pipeline Company paid the DarkSide ransom and still restored its systems from its own backups, which is the central practical finding of the Colonial Pipeline ransomware attack. The purchased decryption tool arrived and functioned, yet ran too slowly to carry an operational recovery. Accounts that present payment as the mechanism of recovery reverse what happened.
Why Colonial Pipeline Company Paid the DarkSide Ransom
Colonial Pipeline Company paid 75 bitcoin, approximately 4.4 million United States dollars, on May 8, 2021, executing the transfer through outside lawyers and negotiators. Chief Executive Officer Joseph Blount made the decision personally and testified that he prioritized the national interest.
Blount also testified that he could not recall specific conversations with government officials about whether to pay, and that Colonial Pipeline Company did not consult the Department of the Treasury Office of Foreign Assets Control beforehand. According to Joseph Blount's Testimony Before the United States Senate Committee on Homeland Security and Governmental Affairs 2021, Colonial Pipeline Company invested more than 200 million dollars in its information technology systems over the five years preceding the Colonial Pipeline ransomware attack.
Why Paying Did Not Speed Recovery From the Colonial Pipeline Ransomware Attack
Blount testified that the decryption tool supplied by DarkSide worked "to some degree", and contemporaneous reports state that it ran too slowly to be operationally useful. Restoration relied on Colonial Pipeline Company's own backups, which existed and were viable.
A free DarkSide ransomware decryption tool released on January 11, 2021 addressed an earlier flawed variant only. Reporting published on May 24, 2021 states that DarkSide corrected that flaw within approximately a day of the public announcement, leaving the tool useless against the version deployed in the Colonial Pipeline ransomware attack four months later.
How Much of the Colonial Pipeline Ransom Was Recovered, and What Remains Unknown
According to the United States Department of Justice's Department of Justice Seizes 2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside 2021, the Federal Bureau of Investigation seized approximately 63.7 bitcoin valued at approximately 2.3 million dollars on June 7, 2021, as set out in the Department of Justice cryptocurrency seizure announcement.
Both framings of that recovery describe the same event: 63.7 of 75 bitcoin is approximately 85 percent of the quantity paid, but its dollar value amounted to roughly half the payment's dollar value, because bitcoin declined between May 8 and June 7, 2021. Elliptic assessed that the seized funds represented the affiliate's share in preference to the operators' share.
Elvis Chan of the Federal Bureau of Investigation San Francisco field office declined to explain how the private key was obtained, citing tradecraft; Coinbase Chief Security Officer Philip Martin stated on June 8, 2021 that Coinbase was not involved.
Stop treating ransom payment as a recovery plan when backups carry the actual restoration. Adaptive Security addresses the workforce exposure that precedes the payment decision, well before any negotiation begins.
The Regulatory and Legal Aftermath of the Colonial Pipeline Ransomware Attack
Consequences of the Colonial Pipeline ransomware attack ran for years past the restart, through federal security directives, a proposed civil penalty, and two dismissed class actions. This is where most coverage stops, since the news cycle closed in June 2021 and the vendor explainers carry no dates. The regulatory record also corrects two widely circulated claims.
Federal Directives Issued After the Colonial Pipeline Ransomware Attack
The Transportation Security Administration issued Security Directive Pipeline-2021-01 on May 27, 2021, twenty days after the shutdown that began the public phase of the Colonial Pipeline ransomware attack, applying it to designated pipeline operators.
Security Directive Pipeline-2021-02 followed, announced on July 20, 2021 and effective July 26, 2021. Together these directives introduced the first mandatory cybersecurity requirements for pipeline operators. The authority sits with the Transportation Security Administration in preference to the Cybersecurity and Infrastructure Security Agency, which several accounts misattribute.
The PHMSA Penalty Proposed After the Colonial Pipeline Ransomware Attack
The PHMSA Notice of Probable Violation of May 5, 2022 is the most specific official finding on the Colonial Pipeline ransomware attack. According to the Pipeline and Hazardous Materials Safety Administration's Notice of Probable Violation and Proposed Compliance Order to Colonial Pipeline Company 2022, proposed civil penalties totaled 986,400 dollars, of which 846,300 dollars related to a single alleged failure to plan, test, and vet manual shutdown and restart procedures.
The penalty was proposed, but not finalized, and the underlying inspections ran from January through November 2020, predating the Colonial Pipeline ransomware attack. Final disposition does not appear in the sourced record. The finding locates a contributing cause in preparation that predated the intrusion.
How Colonial Pipeline Ransomware Attack Litigation Actually Ended
Both major third-party class actions arising from the Colonial Pipeline ransomware attack were dismissed rather than settled. Ramon Dickerson et al. v. Colonial Pipeline Co. was dismissed in full on June 17, 2022 by the United States District Court for the Northern District of Georgia, on the grounds that Colonial Pipeline Company owed the plaintiffs no duty and was not a public utility.
According to the EZ Mart 1 LLC v. Colonial Pipeline Company Complaint 2021, more than 11,000 gasoline retailers were alleged to have experienced fuel shortages during the five-day shutdown. Judge Mark H. Cohen dismissed that case on no-duty grounds, holding that the claim would be barred as pure economic loss under Georgia law.
A circulating claim that Colonial Pipeline Company settled for 50 million dollars is incorrect and belongs to an unrelated Amplify Energy Corporation pipeline spill settlement.
Regulatory findings arrive years after an incident and land on preparation that predates it. Adaptive Security documents workforce readiness continuously so evidence exists before an investigation demands it.
What Happened to DarkSide After the Colonial Pipeline Ransomware Attack
The disappearance of DarkSide days after the Colonial Pipeline ransomware attack is usually reported as a law enforcement victory. The sourced evidence does not settle it, and no United States government entity has publicly claimed a takedown of DarkSide infrastructure. Two accounts remain live, and an accurate treatment of the Colonial Pipeline ransomware attack presents both.
The DarkSide Shutdown After the Colonial Pipeline Ransomware Attack: Takedown or Exit Scam
DarkSide announced its closure on May 13, 2021, claiming the loss of its blog, payment, and content delivery servers, the withdrawal of funds to an unknown address, and affiliate compensation by May 23, 2021. Every element of that announcement is a DarkSide claim, relayed on the Exploit forum by the public representative of the rival REvil operation in preference to DarkSide directly. According to Elliptic's Blockchain Analysis of DarkSide Ransom Flows 2021, the operation received more than 90 million dollars in bitcoin from 47 distinct wallets over approximately nine months.
Evidence supporting genuine disruption includes hosting support citing a law enforcement request and the emergence of a differently branded operation in preference to a DarkSide relaunch. Evidence supporting an exit scam includes forum users claiming to be unpaid affiliates, some of whom supplied material that forum administrators confirmed as legitimate.
DarkSide Successors and Code Lineage After the Colonial Pipeline Attack
BlackMatter emerged in July 2021 and was assessed by threat intelligence teams as a successor incorporating DarkSide characteristics, before announcing its own shutdown that November. The Federal Bureau of Investigation later linked DarkSide and BlackMatter developers and money launderers to the ALPHV operation, also known as BlackCat.
Affiliate activity continued independently of the brand. Mandiant documented that an affiliate cluster associated with DarkSide began a separate intrusion on May 18, 2021, five days after the announced closure, demonstrating that the brand and the people conducting intrusions are separable.
Ransomware brands disappear while the affiliates behind them continue operating under new names. Adaptive Security keeps workforce defenses tied to behavior in preference to any single group name.
Defensible Lessons From the Colonial Pipeline Ransomware Attack
The lessons worth drawing from the Colonial Pipeline ransomware attack are the ones that attach to something documented in the record of this incident. Generic ransomware checklists appended to competing coverage describe controls that no source connects to what happened at Colonial Pipeline Company. Each point below maps to a specific finding from the sworn testimony, the federal advisory, or the regulatory notice.
Identity Failures That Enabled the Colonial Pipeline Ransomware Attack
Three identity failures combined to produce the entry point of the Colonial Pipeline ransomware attack:
- Dormant remote access accounts remain live attack surface, and the profile used had never been disabled;
- Password complexity does not survive reuse, since the compromised password was complex and had been used on multiple websites;
- Multi-factor authentication on the virtual private network was the single decisive absent control.
Credential reuse monitoring against breach corpora is inferred as absent, given that the password was later found in a leaked set.
Detection and Segmentation Lessons From the Colonial Pipeline Ransomware Attack
Approximately eight days of dwell time passed undetected between April 29 and May 7, 2021, and discovery came only when a ransom note appeared on a control room screen. Detection failed, and the specific tooling in place at the time is UNKNOWN.
An information technology compromise stopped physical operations because Colonial Pipeline Company could not confirm containment. Uncertainty about segmentation drove the shutdown decision during the Colonial Pipeline ransomware attack, since operational technology was never encrypted.
Recovery Lessons From the Colonial Pipeline Ransomware Attack
Payment did not deliver timely recovery from the Colonial Pipeline ransomware attack, and viable backups did. That control was present and effective, and it is the reason restoration took five days in preference to considerably longer.
The absence of a tested manual restart plan extended the national impact, according to the Pipeline and Hazardous Materials Safety Administration finding of May 5, 2022. Organizations building comparable resilience should pair a tested manual procedure with a security awareness and behavior change platform, and should treat the No More Ransom decryption tool repository as the only legitimate source for any decryption tool.
Build lessons on controls that actually failed instead of generic ransomware checklists. Adaptive Security ties workforce readiness to the identity and access failures incidents genuinely expose, measured over time.
Reducing Credential and Human-Factor Exposure to Prevent Attacks Like the Colonial Pipeline Ransomware

The Colonial Pipeline ransomware attack began with a valid credential, reused across multiple websites, on an account nobody remembered, protected by no second factor. That combination is behavioral and administrative, which places it inside the population of risks an organization can measure, monitor, and reduce over time.
Adaptive Security addresses that exposure directly by measuring how the workforce handles credentials, where reuse is likely, and which remote access remains active without an owner. The human risk management platform scores individual and departmental exposure continuously, so security teams see concentration risk in the same terms the Colonial Pipeline ransomware attack exposed at Colonial Pipeline Company, and can act on it before an affiliate does. Outcomes are reported as reductions in measurable behavior in preference to completion rates.
The post-intrusion dimension matters equally. Eight days of undetected activity preceded discovery in the Colonial Pipeline ransomware attack, and once corporate information technology systems went down, the workforce lost the channels it used to communicate and coordinate. Adaptive Security prepares employees to recognize and report anomalies early, and to operate through a disruption when normal systems are unavailable.
Organizations that treat credential hygiene as an administrative chore inherit the exposure it leaves behind. Adaptive Security converts that exposure into monitored, reportable human risk across the workforce.
Frequently Asked Questions About the Colonial Pipeline Ransomware Attack
How Did Hackers Get Into Colonial Pipeline During the Ransomware Attack?
A DarkSide affiliate authenticated to a legacy Colonial Pipeline Company virtual private network profile on April 29, 2021 using a valid employee username and password on an account that did not require multi-factor authentication. The account was no longer in active use and had never been disabled. How the credential reached the affiliate was never established.
Why Did the Colonial Pipeline Shut Down After the Ransomware Attack?
Colonial Pipeline Company shut the pipeline at 6:10 a.m. on May 7, 2021 as a precaution, because it could not confirm containment of the intrusion. Operational technology was never encrypted, according to the CISA and FBI Joint Cybersecurity Advisory AA21-131A. The decision followed uncertainty about cyberattacker access in preference to any compromise of control systems.
How Long Was the Colonial Pipeline Shut Down by the Ransomware Attack?
The pipeline was offline for five days, from the shutdown on May 7, 2021 to the restart on May 12, 2021, with normal operations restored on May 15, 2021. It was the first full shutdown of the gasoline system in the 57-year history of Colonial Pipeline Company. The physical asset sustained no damage.
How Much Ransom Did Colonial Pipeline Pay in the Ransomware Attack?
Colonial Pipeline Company paid 75 bitcoin, valued at approximately 4.4 million United States dollars, on May 8, 2021. The payment was executed through outside lawyers and negotiators. Dollar figures in circulation vary between roughly 4.3 million and 5 million because the bitcoin exchange rate moved, while the quantity of 75 bitcoin is fixed and confirmed.
Did the FBI Recover the Colonial Pipeline Ransom After the Ransomware Attack?
The United States Department of Justice announced on June 7, 2021 that it had seized approximately 63.7 bitcoin, valued at approximately 2.3 million dollars at the time of seizure. That is approximately 85 percent of the bitcoin quantity paid and roughly half its dollar value, because bitcoin declined between the two dates. The Federal Bureau of Investigation has never disclosed how it obtained the private key.
Was the Actual Pipeline Hacked in the Colonial Pipeline Ransomware Attack?
No. Only corporate information technology systems were encrypted during the Colonial Pipeline ransomware attack, and the Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation reported no indication that operational technology networks were directly affected. The shutdown of approximately 5,500 miles of pipeline was a precautionary business decision taken by Colonial Pipeline Company.
Who Was Behind the Colonial Pipeline Ransomware Attack?
The Federal Bureau of Investigation publicly attributed the Colonial Pipeline ransomware attack to DarkSide on May 10, 2021 and assessed the operation as Russia-based. DarkSide ran a Ransomware-as-a-Service model, so an affiliate conducted the intrusion while the operators supplied the ransomware and payment infrastructure. The operation announced its closure on May 13, 2021.
Was Anyone Arrested for the Colonial Pipeline Ransomware Attack?
No DarkSide member has been publicly charged, arrested, or sanctioned by name for the Colonial Pipeline ransomware attack. The United States Department of State instead offered rewards in November 2021 for information identifying DarkSide leadership and affiliates. The January 2022 Russian Federal Security Service action targeted the REvil operation and has no established connection to this incident.
Every unused remote access account remains live infrastructure until someone deliberately disables it. Adaptive Security keeps human-layer risk visible so forgotten access stops becoming an entry point.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Related articles

AI Email Threat Detection: How It Finds Modern Phishing and BEC and How to Evaluate It Safely at Scale

MGM Ransomware Attack: The $100 Million Help Desk Phone Call
