A ransomware attack on Colonial Pipeline’s IT environment forced the company to temporarily halt pipeline operations, causing fuel supply disruptions across parts of the United States. Dragos said with high confidence that the DarkSide ransomware group was responsible for the compromise and described the incident as the most disruptive cyber intrusion it had seen affecting U.S. energy infrastructure. The shutdown highlighted how closely linked IT and OT environments can be in industrial organizations, allowing an enterprise-system intrusion to trigger major operational consequences.
As Colonial Pipeline restarted service, U.S. officials warned that fuel availability would recover gradually and urged the public not to panic-buy gasoline or accept price gouging. The FBI said the Russian government was not behind the attack, though the perpetrators were believed to be operating from Russia. Reporting on the incident also pointed to common ransomware entry paths, including weak passwords on internet-exposed services and exploitation of devices such as Pulse Connect Secure, Fortinet FortiOS, and Accellion FTA, while recommended defenses included stronger network segmentation, improved monitoring and logging, offline backups, and exercised OT incident response plans.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On May 13, President Joe Biden publicly addressed the Colonial Pipeline attack from the White House, urging Americans not to panic-buy gasoline and warning against price gouging. He also said there was no evidence the Russian government was behind the attack, though the perpetrators were believed to be living in Russia.
On May 9, Dragos released an intelligence report to customers assessing with high confidence that the DarkSide ransomware group was responsible for the IT compromise at Colonial Pipeline. This provided an early attribution for the incident.
Public reporting on May 7 said Colonial Pipeline operations were impacted by a ransomware incident in the company's IT environment. The attack disrupted pipeline operations and contributed to fuel shortages and rising prices in parts of the United States.
Biden signed an executive order to strengthen U.S. cybersecurity defenses in response to the broader threat environment highlighted by the Colonial Pipeline incident. The order requires federal contractors to share hack information with the government and sets security standards for software bought by the federal government.
On Thursday morning, Colonial Pipeline said it had made substantial progress and that product delivery had resumed in a majority of the markets it serves in the Southeast. The statement indicated restoration was underway but not yet complete.
Colonial Pipeline restarted its system late Wednesday afternoon after the disruption. The restart marked the beginning of service restoration, though fuel availability was expected to recover gradually.
After the ransomware incident in its IT environment, Colonial Pipeline operators temporarily halted OT operations as a precaution. The event highlighted how enterprise-side compromises can disrupt industrial operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
abcnews.go.com
Open sourcepylos.co
Open sourcedragos.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.