/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: cybercrime gang DarkSide, which caused Colonial Pipeline to halt operations, stole and encrypted ~100GB of data on Thursday before demanding a ransom

- Attackers stole nearly 100GB of data in two hours on Thursday  — Theft followed by locking of computers and ransom demand

Bloomberg

Context & Ripple Effects

Colonial Pipeline had already halted operations after the ransomware attack, making the incident an immediate continuity problem for a conduit that related coverage says carries a large share of East Coast fuel. The new account establishes that DarkSide paired the shutdown with data theft, rather than relying on encryption alone.

DarkSide subsequently portrayed itself as financially motivated and said it would moderate targets, while later reporting said the group lost access to its servers and funds. Those developments frame the attack as both a high-impact extortion event and a challenge to the gang’s ability to operate.

First-order effects

  • Colonial must address both encrypted systems and the exposure of roughly 100GB of stolen data while restoring operations after the ransomware-driven shutdown.
  • DarkSide gains two sources of pressure in its ransom demand: unavailable systems and possession of Colonial data.

Second-order effects

  • The operational outage threatens fuel supply in the Southeast and East Coast, increasing the urgency of Colonial’s restoration and ransom decisions.
  • Colonial’s reported ransom payment turns the attack into a visible test of whether critical-infrastructure operators can avoid paying when attackers combine theft with encryption.

Third-order effects

  • The incident points to ransomware shifting toward dual-extortion campaigns, in which data exfiltration preserves leverage even after a victim restores systems.
  • For critical-infrastructure operators, remote-access weaknesses become an operational-continuity risk when a single intrusion can interrupt physical service as well as expose data.

The trend: Ransomware groups are increasingly pairing data theft with system encryption to raise the cost of resisting extortion, especially for operators whose outages affect essential services.

Discussion

  • @business @business on x
    The hackers who caused Colonial Pipeline to shut down the biggest U.S. gasoline pipeline on Friday began their blitz against the company a day earlier, sources say https://www.bloomberg.com/...
  • @catkngai Catherine Ngai on x
    BIG —> The hackers who caused Colonial Pipeline to shut down the biggest U.S. gas pipe on Friday began their blitz against the co. a day earlier, stealing a large amount of data before locking computers w ransomware https://www.bloomberg.com/... via @technology
  • @kevincollier Kevin Collier on x
    The financial sector. Wall Street keeps their shit tight and figured out information sharing with the federal government early. But Jim's point is valid, I think. It feels like there's a weak link absolutely everywhere you look, especially with the ransomware epidemic. https://tw…
  • @cahlberg Christopher Ahlberg on x
    Good commentary by @uuallan here. Zero reason to accept this to be run out of Russia. FSB knows who these guys are and let them be. Don't accept it. https://twitter.com/...
  • @williamturton William Turton on x
    SCOOP (w/ @jordanr1000): Hackers stole nearly 100 GBs of data from the operator of the U.S. biggest gasoline pipeline on Thursday. Hackers threatened to leak the data if the ransom was not paid. (We don't know the current status of the ransom.) Story TK.
  • @oxleyio David Oxley on x
    “Cyber security” works every day, until it fails, and that's what (rightly) catches people's attention. There's a lot wrong here, and much room for improvement, but companies successfully preventing ransomware attacks rarely make the news. https://twitter.com/...