top of page

Colonial Pipeline: When IT Ransomware Stopped an OT Operation

7 days ago
4 min read

The Colonial Pipeline incident is one of the most instructive OT security stories precisely because the malware never reached the operational technology. A ransomware infection on the business side was enough to halt one of the largest fuel pipelines in the United States for days. It is the clearest public example of how tightly IT and OT are tied together, even when they look separate on a diagram.

What happened

On 7 May 2021, Colonial Pipeline discovered a ransom note on its IT network. The company had been hit by ransomware from a criminal group known as DarkSide.

The pipeline itself, which runs about 5,500 miles and carries close to 45% of the fuel consumed on the US East Coast, was not infected. But Colonial could not confidently bill and track the fuel it moved while its business systems were compromised, and it could not be certain the infection would stay on the IT side. The company chose to shut the pipeline down as a precaution.

That shutdown, not the malware, is what the public felt. Over roughly five to six days, fuel stopped flowing north, panic-buying set in, and gas stations across the southeast ran dry. Operations resumed on 12 May 2021.

Colonial paid a ransom of about 75 bitcoin, worth roughly US$4.4 million at the time. In June 2021, the US Department of Justice announced it had recovered about 63.7 of those bitcoin, worth around US$2.3 million by then after the price had fallen.

How it worked, at a high level

Five-step flow: legacy VPN account without MFA, DarkSide ransomware on IT network, business systems encrypted, precautionary pipeline shutdown, fuel shortages
May 2021: a forgotten VPN account without MFA led to ransomware on business systems and a precautionary pipeline shutdown.

The entry point was mundane, which is exactly why it matters. According to the company's later testimony:

  • The attackers used a legacy virtual private network (VPN) account that was still active but no longer meant to be in use.

  • That account did not have multi-factor authentication. A single compromised password was enough to get in.

  • From the business network, the ransomware did what ransomware does: it encrypted systems the company needed to run day to day.

There was no clever industrial exploit and no attack on controllers. It was an unused account, a password and a missing second factor.

Who was behind it

The attack was carried out by DarkSide, a criminal ransomware operation widely reported to be based in Russia. This was financially motivated crime rather than a state operation aimed at the pipeline itself.

Impact

Beyond the fuel shortages and the ransom, the incident had lasting policy effects. In the weeks that followed, the US Transportation Security Administration issued its first mandatory cybersecurity directives for pipeline operators, replacing what had been voluntary guidance with specific requirements around incident reporting, a named cybersecurity coordinator and security assessments. The first directive came in late May 2021 and a more detailed one followed in July 2021.

What it taught the industry

  • IT and OT are not truly separate if one depends on the other. The pipeline could run mechanically, but the business could not function without its IT systems, so the pipeline stopped anyway.

  • Business decisions can take OT offline. The shutdown was a cautious choice made under uncertainty. When defenders cannot tell how far an infection has spread, stopping production becomes a reasonable option, which is itself an impact worth planning for.

  • Basic account hygiene is critical infrastructure. An old account without multi-factor authentication undid an enormous operation. The most consequential attacks often start with the most ordinary failures.

  • Regulators respond to visible disruption. A single high-profile incident reshaped the rules for an entire sector.

Practical defensive lessons

  • Turn on multi-factor authentication everywhere it matters. Every remote-access path, especially VPNs that can reach sensitive environments, should require a second factor. This one control would likely have stopped the attack.

  • Decommission old accounts and access. Inventory VPN profiles, service accounts and remote-access credentials. Disable anything unused, and build account cleanup into your routine, not just your audits.

  • Map IT/OT dependencies. Understand which business systems your operations truly depend on, such as billing, scheduling and measurement, and what happens if they are unavailable.

  • Make OT able to run independently. Where safe and practical, ensure operations can continue for a defined period without the IT systems they normally lean on, and know in advance what will force a shutdown.

  • Rehearse the shutdown decision. Decide ahead of time who can order an operational stop, under what conditions, and how recovery will proceed. Making that call under pressure is easier when it has been practised.

Key takeaways

  • In May 2021, DarkSide ransomware hit Colonial Pipeline's IT systems; the OT was never infected, but the pipeline was shut down for about five to six days.

  • Entry was through a legacy VPN account without multi-factor authentication, reached with a single compromised password.

  • Colonial paid about 75 bitcoin (around US$4.4 million); the DOJ later recovered about 63.7 bitcoin (around US$2.3 million).

  • The incident led to the first mandatory US pipeline cybersecurity directives.

  • Multi-factor authentication, account decommissioning and OT independence are the central lessons.

How QBits Networks can help

Colonial Pipeline shows how an ordinary IT weakness and a hidden IT/OT dependency can stop an operation cold. Our secure remote access reviews find forgotten accounts and missing controls like multi-factor authentication before someone else does, and our OT incident response readiness work helps you understand your IT/OT dependencies and plan for the shutdown-and-recovery decisions this kind of event forces. Tell us what you need through our contact page and we'll scope it with you.

bottom of page