Colonial Pipeline shut down its fuel distribution network after a ransomware attack hit the company’s business systems, disrupting a pipeline that carries about 45% of the East Coast’s fuel supply. The outage triggered supply concerns across the eastern United States, prompted fuel sellers and traders to seek alternatives, and led the U.S. government to invoke emergency powers to ease transportation constraints as gasoline shortages and panic buying spread in some markets.
The FBI attributed the intrusion to the DarkSide ransomware group, making the incident one of the most consequential cyberattacks on U.S. critical infrastructure. Colonial later restored service and said operations had returned to normal, while reports said the company paid roughly $5 million to the attackers; the company also said its operational technology systems did not appear to have been directly affected, but that it had taken systems offline as a precaution and would increase cybersecurity investment.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced that an FBI-led operation recovered about $2.3 million in Bitcoin from the ransom Colonial Pipeline paid to the DarkSide group after the May 2021 attack. Officials said the seizure was part of a broader federal ransomware crackdown and involved tracing funds to a cryptocurrency wallet linked to the attackers.
Despite Colonial Pipeline's operational restart, fuel outages continued in some areas and U.S. gas prices rose to their highest level in six years. The development showed that consumer impacts from the ransomware-driven disruption were still unfolding after pipeline service resumed.
Colonial Pipeline announced that its systems had returned to normal operations and that it was again servicing all of its markets across the eastern United States. The company said this came about a week after it shut down in response to the ransomware attack.
Georgia Governor Brian Kemp extended the state's suspension of motor fuel taxes for another week and prolonged tanker truck weight-limit and driving-time waivers as fuel shortages and price increases persisted after the Colonial Pipeline outage. State officials also warned against price gouging and urged residents to limit fuel purchases to essential travel.
Colonial Pipeline launched the restart of its fuel pipeline system after a six-day shutdown caused by the ransomware attack. The move marked the start of operational recovery, several days before the company later reported a return to normal service.
FireEye published research identifying five activity clusters linked to the DarkSide ransomware-as-a-service ecosystem, including affiliates such as UNC2628, UNC2659, and UNC2465. The report detailed intrusion methods including VPN credential abuse, exploitation of SonicWall SMA100 flaw CVE-2021-20016, phishing, TeamViewer persistence, Smokedham malware, and NGROK exposure of remote desktop services.
Colonial Pipeline's chief executive later confirmed that the company had already paid the ransom demanded by the attackers following the May 2021 cyberattack. The disclosure clarified earlier reporting that had incorrectly said the company chose not to pay.
DarkSide issued a public statement saying its aim in the Colonial Pipeline incident was to make money rather than create social or political disruption, suggesting the fallout exceeded its intentions. The statement provided a rare direct comment from the ransomware group after the attack drew widespread attention.
As the Colonial Pipeline shutdown continued, petrol shortages began appearing across multiple U.S. regions, reflecting a broader real-world impact on consumers beyond earlier market disruption concerns. The shortages marked an escalation in the consequences of the ransomware-driven outage.
In response to the pipeline disruption, the U.S. government invoked emergency powers to ease fuel transportation rules and help keep supplies moving. The action was intended to mitigate shortages caused by the outage.
The FBI publicly confirmed that the DarkSide ransomware group was responsible for the Colonial Pipeline intrusion. This provided the first widely reported official attribution of the attack.
As the shutdown stretched into the weekend, fuel suppliers, traders, and shippers sought alternatives while uncertainty grew over when the pipeline would restart. The prolonged outage raised concerns about fuel availability and broader supply-chain disruption.
Colonial Pipeline took its major U.S. fuel pipeline system offline after a ransomware attack affected its business networks. The shutdown disrupted a system that supplies a large share of fuel to the U.S. East Coast.
Bloomberg reported that the attackers exfiltrated data from Colonial Pipeline on May 6, 2021, before the company shut down pipeline operations the next day. The report added an early technical and impact detail to the incident beyond the already known operational disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
44 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourcenpr.org
Open sourcecnn.com
Open sourceabcnews.go.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceforbes.com
Open sourcenytimes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.