Colonial Pipeline, which carries almost half the fuel used on the US East Coast, shut down its pipeline network after a ransomware attack on its IT systems. The FBI attributed the attack to the DarkSide ransomware group.
What happened
- The company halted pipeline operations as a precaution, leading to panic buying and fuel shortages in parts of the south-eastern US.
- Colonial paid a ransom of about 75 bitcoin, then worth around $4.4 million.
- In June 2021 the US Department of Justice recovered about 63.7 bitcoin of the payment.
- Investigators later said the attackers had used a compromised password for a VPN account without multi-factor authentication.
Why it mattered
The attack brought ransomware to the top of the US political agenda and led to new security requirements for pipelines and other critical infrastructure.
Lessons for organisations
Enforce multi-factor authentication on all remote access, remove unused accounts, and plan how operational technology can keep running safely if IT systems are compromised. Decide in advance, with legal advice, how the organisation would approach a ransom demand. Regularly test incident response plans with exercises that involve senior leadership.
Source: BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.