Colonial Pipeline, which carries 45% of fuel consumed on the US East Coast, says it halted operations due to a ransomware attack
Colonial Pipeline carries roughly 45% of gasoline and diesel fuel consumed on the East Coast — The main pipeline carrying gasoline and diesel fuel …
Wall Street Journal
Context & Ripple Effects
Colonial Pipeline’s shutdown turns a network intrusion into a physical supply disruption because the conduit carries a large share of East Coast gasoline and diesel. Subsequent coverage identifies the attackers as DarkSide and reports that they stole and encrypted about 100GB of data before demanding a ransom.
The immediate operational priority is restoration: Colonial later restarted after a five-day shutdown, while its CEO later said the company paid $4.4 million because executives lacked clarity on the attack’s scope.
First-order effects
- Colonial Pipeline’s halt immediately disrupts the fuel conduit serving the East Coast, putting gasoline and diesel supply under pressure for the company’s downstream markets.
- Colonial must shift from normal pipeline operations to incident response and recovery, with service restoration becoming its central business decision.
Second-order effects
- Fuel distributors and buyers dependent on Colonial’s route must manage supply around an unavailable conduit until operations resume.
- The outage gives ransomware operators leverage by tying the value of data recovery and system access to the cost of interrupted physical operations.
Third-order effects
- The incident establishes ransomware as a business-continuity threat to critical infrastructure, not solely an IT-data-loss event.
- If similar disruptions persist, infrastructure operators will be pushed to treat access controls, backup recovery, and outage response as operational resilience requirements.
The trend: Ransomware is increasingly targeting organizations whose digital outages can interrupt essential physical services, raising the stakes of cyber resilience.
Related: Security-to-policy pipeline · Colonial Pipeline · Colonial Pipeline restarts operations · Colonial Pipeline CEO says it paid ransom
Related Coverage
- View article Colonial Pipeline
- Regional Emergency Declaration fmcsa.dot.gov
- Biden Plans an Order to Strengthen Cyberdefenses. Will It Be Enough? New York Times
- Ransomware Infection on Colonial Pipeline Shows Potential for Worse Gas Disruption Zero Day
- View article BBC
- View article NBC News
- View article VICE
- View article Financial Times
- View article CyberScoop
- Cyber attack sparks US effort to keep fuel lines open Financial Times
- The Colonial Pipeline Hack Is a New Extreme for Ransomware Wired
- View article BleepingComputer
- View article ZDNet
- View article Associated Press
- View article CNBC
- View article The Register
- View article Security Boulevard
- Russian cybercriminals just pulled off a devastating attack inside the US BGR
- View article Enterprise Times
- After ransomware, U.S. fuel pipeline Colonial Pipeline shuts down VentureBeat
- View article infosecurity-magazine.com
- Top U.S. fuel pipeline operator pushes to recover from cyberattack Reuters
- Hacked Pipeline May Stay Shut for Days, Raising Concerns About Fuel Supply New York Times
- View article Bloomberg
- Colonial Pipeline Ransomware Attack Highlights Alarming Security Vulnerabilities In Critical Infrastructure HotHardware.com News
- Ransomware Attack Forces Top US Gas Pipeline to Halt Operations MUO
- Ransomware Cyber Attack Forced the Largest U.S. Fuel Pipeline to Shut Down The Hacker News
- Colonial Pipeline, the Largest Fuel Pipeline in the U.S., Has Shut Down Over a Ransomware Attack Gizmodo
- Russian criminal group suspected in Colonial pipeline ransomware attack NBC News
- Ransomware attack leads to shutdown of major U.S. pipeline system Washington Post
- Ransomware just got very real. And it's likely to get worse ZDNet
- Restarting U.S. Pipeline Hit by Cyberattack May Not Be Easy Bloomberg
- Ransomware Attack Shuts Down Biggest U.S. Gasoline Pipeline Bloomberg
- Pipeline cyberattack comes after years of government warnings The Record
- Colonial Pipeline halts all pipeline operations after cybersecurity attack Reuters
- Cyberattack forces shutdown of major U.S. fuel pipeline Axios
- Colonial Pipeline cyberattack shuts down pipeline that supplies 45% of East Coast's fuel ZDNet
- Cyberattack forces major US fuel pipeline to shut down CNN
- ‘Jugular’ of the U.S. fuel pipeline system shuts down after cyberattack Politico
- Ransomware Attack Shuts Down Fuel Pipeline Supplying the East Coast Security Boulevard
- A cyberattack shutdown US Colonial Pipeline Security Affairs
- Largest U.S. pipeline shuts down operations after ransomware attack BleepingComputer
- Cyberattack prompts shutdown of major fuel pipeline in the US The Verge
- Cyber-attack forces shutdown of one of the US's largest pipelines The Guardian
- Ransomware Attack Shuts Down Top U.S. Gasoline Pipeline Slate
- Major U.S. Pipeline Crippled in Ransomware Attack Threatpost
- Cyberattack shuts down major US gas pipeline CNET
- Cyber Attack Shuts Down Vital Fuel Pipeline To Northeast U.S. Forbes
- Ransomware Attack Shuts Down A Top U.S. Gasoline Pipeline NPR
- Cyberattack Takes US Pipeline Operator Offline PCMag
- Major US pipeline halts operations after cyberattack The Hill
- US pipeline giant shuts down major fuel line following cyberattack Engadget
- One of country's largest pipelines shuts down to contain cybersecurity breach DataBreaches.net
- Cyberattack Forces Shutdown of Major U.S. Pipeline SecurityWeek
- U.S. Pipeline Giant Halts All Operations Following Cyberattack CRN
Discussion
-
@samjmintz
Sam Mintz
on x
New: In response to Colonial Pipeline shutdown, DOT eases hours of service rules for truck drivers transporting gasoline, diesel, jet fuel and other refined petroleum products to 18 states https://www.fmcsa.dot.gov/...
-
@facethenation
@facethenation
on x
Commerce Sec. Gina Raimondo says cyber attacks on critical U.S. energy infrastructure, like the recent attack against Colonial Pipeline, are “here to stay.” She says it is critical to work with the private sector to “secure networks to defend ourselves.” https://twitter.com/...
-
@c_c_krebs
Chris Krebs
on x
Ransomware shuts down one of the most critical regional pipelines. This has gotten out of control. https://www.bloomberg.com/...
-
@ngleicher
Nathaniel Gleicher
on x
The most striking thing about this incident is how many times it has been predicted by so many security experts. We are fascinated with sudden, genius hacks ("zero-days"), but most serious threats are more like long-observed trains crashing in slow motion. https://www.wired.com/.…
-
@osinttechnical
@osinttechnical
on x
DarkSide is definitely one of the more professional hacker groups, and they show it. They have a mailing list, a press center, and a victim hotline. One of the weird things is that they popped up out of nowhere and began hitting targets hard and fast. https://twitter.com/...
-
@carlquintanilla
Carl Quintanilla
on x
(FT) - The US government declared a state of emergency on Sunday in a bid to keep fuel supply lines open as fears of shortages rose following the shutdown of a major pipeline. @FT @LiveSquawk https://www.ft.com/...
-
@martinsfp
Martin Sfp Bryant
on x
Wow. Ransomware really is a blight on the modern world that needs stamping out. US declares state of emergency to keep fuel flowing after cyber attack https://giftarticle.ft.com/...
-
@digieconomist
Digiconomist
on x
In before “Bitcoin is great for the environment because it enables ransomware that takes down fossil fuels” https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
Ransomware infection at Colonial Pipeline only infected its IT network; but according to source I spoke to it had potential to spread to operational network and even to upstream oil suppliers whose control systems connect directly to Colonial's systems https://zetter.substack.com…
-
@peteryared
Peter Yared
on x
Maybe the future will be like Dune with critical infrastructure going analog cc @ThufirHawat https://www.wsj.com/...
-
@nakashimae
Ellen Nakashima
on x
ALERT: Ransomware attack leads to shut down of major U.S. pipeline system, U.S. official says. Still unknown if carried out by criminals or foreign govt. These incidents are more common than realized, but mostly go unreported to the public, experts say. https://www.washingtonpost…
-
@ddosecret
@ddosecret
on x
“The people behind DarkSide follow the “double extortion” trend in #ransomware, meaning they not only encrypt user data but exfiltrate it and make it public if a ransom payment isn't made.” https://www.bloomberg.com/...
-
@cirincione
Joe Cirincione
on x
Imagine if this story said “ICBM silos” instead of pipelines. Could it happen? Could hackers sabotage nuclear weapon system? Yes. They are vulnerable, studies show. This is a dangerous new risk if we insist on keeping thousands of weapons we don't need. 1/ https://www.washingtonp…
-
@etherealmind
Greg Ferro
on x
Behind every successful ransomware event is a team of very tired infrastructure engineers muttering “I told you so” and executives shouting “it was only a matter of time”. Thoughts and prayers. https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
As suspected, the Colonial Pipeline precautionary shutdown was due to ransomware. This is what I was hearing from sources as well. https://www.washingtonpost.com/ ...
-
@noahpinion
Noah Smith
on x
Cyberattacks now can *and do* shut down key U.S. infrastructure. https://www.reuters.com/...
-
@sammy_roth
Sammy Roth
on x
One of the nation's largest pipelines, which carries refined gasoline and jet fuel from Texas up the East Coast, was forced to shut down after being hit by ransomware in a vivid demonstration of the vulnerability of energy infrastructure to cyberattacks: https://www.nytimes.com/.…
-
@jasonbordoff
Jason Bordoff
on x
This should be wake up call to two key risks we've long known about: the vulnerability of our energy infrastructure to cyberattack & the dependence of much of the eastern seaboard's fuel supply on this one pipeline, particularly after the closure of several Northeast refineries. …
-
@thegrugq
Thaddeus E. Grugq
on x
“US pipeline system shutdown after {exposed VPN system not patched, weak password RDP exposed on internet, employee runs malware emailed to them}” After gaining access, financially motivated threat actors disrupted systems to extort money. Cyber extortion is big criminal business…
-
@dnvolz
Dustin Volz
on x
The attack appears to involve ransomware, according to people familiar with the investigation. No indications at this time OT systems were directly hit. I'm told FireEye is probing the hack for Colonial. https://twitter.com/...
-
@urbanachievr
Christian Vanderbrouk
on x
If confirmed as a cyberattack, how is this not an act of war? https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
Update: Biden was briefed this morning on the Colonial pipeline cyberattack, a White House spokeswoman confirms. Admin is working with company to restore operations as quickly as possible. https://www.wsj.com/...
-
@k8em0
Katie Moussouris
on x
I'm old enough to recall when penetration testers were routinely chastised by business owners for bringing up threats that could lead to ransomware - especially when we retested & found the same bugs at their next audit. Let's hope this doesn't end with knee jerk policy on Monday…
-
@joycewhitevance
Joyce Alene
on x
Cyber attacks are like arsons - you need someone to put the fire out, but then you need investigators to figure out who started it & how. This type of attack on our infrastructure is one of the major threats we face. https://www.washingtonpost.com/ ...
-
@senmarkey
Ed Markey
on x
An understaffed, underprepared TSA cannot successfully ensure the security of dangerous and susceptible natural gas pipeline infrastructure. The federal inability to prevent cyberattacks turns our pipeline system into a risk for communities. https://twitter.com/...
-
@cloud_opinion
@cloud_opinion
on x
Do you call the hackers that took out oil pipeline whitehats because they delayed climate change by half a second?
-
@katearonoff
Kate Aronoff
on x
cyberattack shuts down Colonial Pipeline is quite the sentence https://www.nytimes.com/...
-
@natashabertrand
Natasha Bertrand
on x
“The operator, Colonial Pipeline, which transports more than 100 million gallons of gasoline and other fuel daily from Houston to the New York Harbor...said it learned of the cyberattack on Friday, causing them to pause operations.” https://www.cnn.com/...
-
@dnvolz
Dustin Volz
on x
Two people briefed on the probe said the attack appeared to be limited to information systems and hadn't infiltrated operational control systems, but cautioned that the investigation was in its early stages. https://www.wsj.com/...
-
@shashj
Shashank Joshi
on x
“The [ransomware] attack on top U.S. fuel pipeline operator Colonial Pipeline appears to have been carried out by a criminal group, but federal officials and the private security firm Mandiant are still investigating the matter, one official said.” https://www.washingtonpost.com/…
-
@ajohnsocyber
Ann Johnson
on x
We spend a lot of time legitimately discussing Nation State activity whilst ransomware - often used by criminal gangs - is still the most disruptive global cyber problem. There is often affiliation b/t the two. Regardless don't take your eyes off ransomware anytime soon. https://…
-
@bing_chris
Chris Bing
on x
First reported by WaPo. Have confirmed it was ransomware. https://twitter.com/...
-
@juliettekayyem
Juliette Kayyem
on x
45% of the East Coast's fuel supply is carried through one delivery system, operated by Colonial Pipeline, the victim of a cyberattack Friday. The shutdown was precautionary; company says attack did not impact delivery. But, that's a lot of dependency on one company. https://twit…
-
@jimsciutto
Jim Sciutto
on x
Can anyone share some examples of where “cyber security” is working? Critical government and private sector networks are consistently proving themselves vulnerable. https://twitter.com/...
-
@scalzi
John Scalzi
on x
This is a very serious issue, but as I am a nerd, the thing in this story that really stuck out was when that guy said “it is the country's jugular aorta for moving fuel” and I was all EXCUSE ME I THINK YOU MEAN CAROTID ARTERY DO YOU EVEN ANATOMY SIR https://www.nytimes.com/...
-
@peterzeihan
Peter Zeihan
on x
I truly hope that this was not done by a state actor. If a foreign government hacked American critical infrastructure, the American response is going to be brutal. https://www.wsj.com/...
-
@nycsouthpaw
Southpaw
on x
An ongoing “cybersecurity attack” has turned off the biggest gasoline pipeline from the gulf to the US east coast. https://www.colpipe.com/... https://twitter.com/...
-
@nycsouthpaw
Southpaw
on x
Quite a kicker. https://twitter.com/...
-
@robertmlee
Robert M. Lee
on x
Good reporting by Ellen with quotes from me. The reality is ransomware is becoming more pervasive in both IT and OT networks, impacts in IT can impact operations as well. https://twitter.com/...
-
@sstapczynski
Stephen Stapczynski
on x
This is wild Colonial Pipeline, which operates the largest US gasoline and diesel pipeline system, said it shut its entire network after a cyber-attack. The artery transports roughly 45% of the fuel to the East Coast https://www.bloomberg.com/... https://twitter.com/...
-
@jasonbordoff
Jason Bordoff
on x
Colonial is a critical piece of energy infrastructure, supplying nearly half of gasoline & diesel along much of east coast. If outage lasts, could see higher prices, calls to tap new northeast gasoline reserve & renewed discussion of fuel system resiliency https://www.energypolic…
-
@anthony
@anthony
on x
The Colonial Pipeline is the largest refined-products pipeline in the U.S., transporting more than 100 million gallons per day, or roughly 45% of fuel consumed on the East Coast https://www.wsj.com/...
-
@anthony
@anthony
on x
The main conduit carrying gasoline and diesel fuel to the U.S. East Coast said it had halted all operations after being hit with a cyberattack https://www.wsj.com/...