Sources: cybercrime gang DarkSide, which caused Colonial Pipeline to halt operations, stole and encrypted ~100GB of data on Thursday before demanding a ransom
> The hackers who caused Colonial Pipeline to shut down the biggest U.S. gas pipe on Friday began their blitz against the co. a day earlier, stealing a large amount of data before locking computers w ransomware https://www.bloomberg.com/... via @technology William Turton / @williamturton : SCOOP (w/ @jordanr1000): Hackers stole nearly 100 GBs of data from the operator of the U.S. biggest gasoline pipeline on Thursday. Hackers threatened to leak the data if the ransom was not paid. (We don't know the current status of the ransom.) Story TK.
Bloomberg
Context & Ripple Effects
Colonial Pipeline had already confirmed an operational shutdown after a ransomware incident affecting a conduit that carries 45% of fuel consumed on the U.S. East Coast. The reported sequence—data theft, encryption, and a leak threat—shows why the shutdown of Colonial's fuel conduit was more than a conventional systems-recovery event.
DarkSide's subsequent claim that it would add moderation to its target selection sits uneasily beside an attack that disrupted essential fuel infrastructure. Later reports that the group lost control of its servers and funds add to the picture of a ransomware operation under unusual pressure.
First-order effects
- Colonial Pipeline must manage both restoration of affected systems and the risk that the stolen data will be published if ransom demands are not met.
- DarkSide gains leverage from combining encryption with an alleged data-leak threat, while its public claim to avoid social harm is directly challenged by Colonial's shutdown.
Second-order effects
- Other ransomware operators have a clear incentive to pair data exfiltration with encryption, since victims face disclosure risk even if they can restore systems.
- Operators of essential infrastructure face pressure to treat theft of business data and interruption of operational systems as a single incident-response problem.
Third-order effects
- If this attack pattern persists, ransomware resilience for critical infrastructure will be measured not only by recovery speed but also by the ability to prevent data leaving the network before systems are locked.
- The apparent pressure on DarkSide, including its reported loss of control over web servers and funds, points to a more contested operating environment for ransomware groups after high-impact attacks.
The trend: Ransomware is evolving into a dual-extortion model in which data theft amplifies the operational leverage of system encryption against critical-infrastructure operators.
Related: Colonial Pipeline · Colonial Pipeline halts operations after ransomware attack · DarkSide pledges target moderation after Colonial attack · DarkSide reports loss of servers and funds
Related Coverage
- Russian criminal group suspected in Colonial pipeline ransomware attack NBC News
- Ransom group linked to Colonial Pipeline hack is new but experienced Reuters · Raphael Satter
- Colonial pipeline shutdown highlights need for better OT cybersecurity practices CSO · Cynthia Brumfield
- View article ZDNet
- U.S. Pipeline Shutdown Exposes Cyber Threat to Energy Sector Wall Street Journal
- Oil industry rattled by cyberattack on US gas pipeline Silicon Republic · Jonathan Keane
- Criminal group originating from Russia believed to be behind pipeline cyberattack CNN
- View article Fast Company
- Pipeline cyberattack was likely the work of a ransomware gang Engadget · Jon Fingas
- View article RCR Wireless News
- Biden Declares State of Emergency While Colonial Pipeline Is Down Zero Day · Kim Zetter
- Major US fuel pipeline taken down by ransomware attack TechRadar · Mayank Sharma
- Daily Digest Of Tech Policy News And Updates (May 10, 2021) MediaNama · Advait Palepu
- Major US oil pipeline shut down after ransomware attack Graham Cluley
- Major ransomware attack cripples largest gas pipeline in the US HackRead · Habiba Rashid
- Shutdown of US pipeline after cyber attack prompts worry over gas prices The Guardian
- Ransomware Attack Shuts Down Fuel Pipeline Supplying the East Coast Security Boulevard · Roark Pollock
- US passes emergency waiver over fuel pipeline cyber-attack BBC · Mary-Ann Russon
- Pipeline ransomware attack: US invokes emergency transport rules to keep fuel flowing ZDNet · Liam Tung
- SolarWinds Says Russian Group Likely Took Data During Cyber-Attack Bloomberg · Alyza Sebenius
- Regional Emergency Declaration fmcsa.dot.gov
- The Colonial Pipeline Hack Is a New Extreme for Ransomware Wired · Andy Greenberg
- Cyber attack sparks US effort to keep fuel lines open Financial Times
- Biden Plans an Order to Strengthen Cyberdefenses. Will It Be Enough? New York Times
- Russian cybercriminals just pulled off a devastating attack inside the US BGR · Andy Meek
- After ransomware, U.S. fuel pipeline Colonial Pipeline shuts down VentureBeat
- Ransomware attack leads to shutdown of major U.S. pipeline system Washington Post
- Ransomware just got very real. And it's likely to get worse ZDNet · Steve Ranger
- Top U.S. fuel pipeline operator pushes to recover from cyberattack Reuters
- Hacked Pipeline May Stay Shut for Days, Raising Concerns About Fuel Supply New York Times · Clifford Krauss
- Restarting U.S. Pipeline Hit by Cyberattack May Not Be Easy Bloomberg
- Colonial Pipeline Ransomware Attack Highlights Alarming Security Vulnerabilities In Critical Infrastructure HotHardware.com News · Nathan Ord
- Ransomware Infection on Colonial Pipeline Shows Potential for Worse Gas Disruption Zero Day · Kim Zetter
- Ransomware Attack Shuts Down Biggest U.S. Gasoline Pipeline Bloomberg
- Ransomware Attack Forces Top US Gas Pipeline to Halt Operations MUO · Manuviraj Godara
- Ransomware Cyber Attack Forced the Largest U.S. Fuel Pipeline to Shut Down The Hacker News · Ravie Lakshmanan
- Pipeline cyberattack comes after years of government warnings The Record · Adam Janofsky
- Colonial Pipeline halts all pipeline operations after cybersecurity attack Reuters
- Colonial Pipeline, the Largest Fuel Pipeline in the U.S., Has Shut Down Over a Ransomware Attack Gizmodo · Jody Serrano
- Cyberattack forces shutdown of major U.S. fuel pipeline Axios
- Colonial Pipeline cyberattack shuts down pipeline that supplies 45% of East Coast's fuel ZDNet · Larry Dignan
- Cyberattack forces major US fuel pipeline to shut down CNN · Veronica Stracqualursi
- ‘Jugular’ of the U.S. fuel pipeline system shuts down after cyberattack Politico
- A cyberattack shutdown US Colonial Pipeline Security Affairs · Pierluigi Paganini
- Largest U.S. pipeline shuts down operations after ransomware attack BleepingComputer · Lawrence Abrams
- Cyberattack prompts shutdown of major fuel pipeline in the US The Verge · Kim Lyons
- Cyber-attack forces shutdown of one of the US's largest pipelines The Guardian · Erum Salam
- Ransomware Attack Shuts Down Top U.S. Gasoline Pipeline Slate · Daniel Politi
- Major U.S. Pipeline Crippled in Ransomware Attack Threatpost · Tom Spring
- Cyberattack shuts down major US gas pipeline CNET · Edward Moyer
- Cyber Attack Shuts Down Vital Fuel Pipeline To Northeast U.S. Forbes · Christopher Helman
- Ransomware Attack Shuts Down A Top U.S. Gasoline Pipeline NPR · Marisa Peñaloza
- Cyberattack Takes US Pipeline Operator Offline PCMag · Chloe Albanesius
- Major US pipeline halts operations after cyberattack The Hill · Tal Axelrod
- US pipeline giant shuts down major fuel line following cyberattack Engadget · Jon Fingas
- One of country's largest pipelines shuts down to contain cybersecurity breach DataBreaches.net · David E. Sanger entries
- Cyberattack Forces Shutdown of Major U.S. Pipeline SecurityWeek · Mike Lennon
- U.S. Pipeline Giant Halts All Operations Following Cyberattack CRN · Michael Novinson
Discussion
-
@rvawonk
Caroline Orr Bueno, Ph.D
on x
This comes just a month after the DOJ launched a “ransomware task force” amid a surge in ransomware attacks targeting critical infrastructure and government systems. https://twitter.com/...
-
@kevincollier
Kevin Collier
on x
The financial sector. Wall Street keeps their shit tight and figured out information sharing with the federal government early. But Jim's point is valid, I think. It feels like there's a weak link absolutely everywhere you look, especially with the ransomware epidemic. https://tw…
-
@cahlberg
Christopher Ahlberg
on x
Good commentary by @uuallan here. Zero reason to accept this to be run out of Russia. FSB knows who these guys are and let them be. Don't accept it. https://twitter.com/...
-
@oxleyio
David Oxley
on x
“Cyber security” works every day, until it fails, and that's what (rightly) catches people's attention. There's a lot wrong here, and much room for improvement, but companies successfully preventing ransomware attacks rarely make the news. https://twitter.com/...
-
@business
@business
on x
The hackers who caused Colonial Pipeline to shut down the biggest U.S. gasoline pipeline on Friday began their blitz against the company a day earlier, sources say https://www.bloomberg.com/...
-
@catkngai
Catherine Ngai
on x
BIG —> The hackers who caused Colonial Pipeline to shut down the biggest U.S. gas pipe on Friday began their blitz against the co. a day earlier, stealing a large amount of data before locking computers w ransomware https://www.bloomberg.com/... via @technology
-
@williamturton
William Turton
on x
SCOOP (w/ @jordanr1000): Hackers stole nearly 100 GBs of data from the operator of the U.S. biggest gasoline pipeline on Thursday. Hackers threatened to leak the data if the ransom was not paid. (We don't know the current status of the ransom.) Story TK.
-
@samjmintz
Sam Mintz
on x
New: In response to Colonial Pipeline shutdown, DOT eases hours of service rules for truck drivers transporting gasoline, diesel, jet fuel and other refined petroleum products to 18 states https://www.fmcsa.dot.gov/...
-
@facethenation
@facethenation
on x
Commerce Sec. Gina Raimondo says cyber attacks on critical U.S. energy infrastructure, like the recent attack against Colonial Pipeline, are “here to stay.” She says it is critical to work with the private sector to “secure networks to defend ourselves.” https://twitter.com/...
-
@c_c_krebs
Chris Krebs
on x
Ransomware shuts down one of the most critical regional pipelines. This has gotten out of control. https://www.bloomberg.com/...
-
@ngleicher
Nathaniel Gleicher
on x
The most striking thing about this incident is how many times it has been predicted by so many security experts. We are fascinated with sudden, genius hacks ("zero-days"), but most serious threats are more like long-observed trains crashing in slow motion. https://www.wired.com/.…
-
@osinttechnical
@osinttechnical
on x
DarkSide is definitely one of the more professional hacker groups, and they show it. They have a mailing list, a press center, and a victim hotline. One of the weird things is that they popped up out of nowhere and began hitting targets hard and fast. https://twitter.com/...
-
@carlquintanilla
Carl Quintanilla
on x
(FT) - The US government declared a state of emergency on Sunday in a bid to keep fuel supply lines open as fears of shortages rose following the shutdown of a major pipeline. @FT @LiveSquawk https://www.ft.com/...
-
@martinsfp
Martin Sfp Bryant
on x
Wow. Ransomware really is a blight on the modern world that needs stamping out. US declares state of emergency to keep fuel flowing after cyber attack https://giftarticle.ft.com/...
-
@digieconomist
Digiconomist
on x
In before “Bitcoin is great for the environment because it enables ransomware that takes down fossil fuels” https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
Ransomware infection at Colonial Pipeline only infected its IT network; but according to source I spoke to it had potential to spread to operational network and even to upstream oil suppliers whose control systems connect directly to Colonial's systems https://zetter.substack.com…
-
@peteryared
Peter Yared
on x
Maybe the future will be like Dune with critical infrastructure going analog cc @ThufirHawat https://www.wsj.com/...
-
@nakashimae
Ellen Nakashima
on x
ALERT: Ransomware attack leads to shut down of major U.S. pipeline system, U.S. official says. Still unknown if carried out by criminals or foreign govt. These incidents are more common than realized, but mostly go unreported to the public, experts say. https://www.washingtonpost…
-
@ddosecret
@ddosecret
on x
“The people behind DarkSide follow the “double extortion” trend in #ransomware, meaning they not only encrypt user data but exfiltrate it and make it public if a ransom payment isn't made.” https://www.bloomberg.com/...
-
@cirincione
Joe Cirincione
on x
Imagine if this story said “ICBM silos” instead of pipelines. Could it happen? Could hackers sabotage nuclear weapon system? Yes. They are vulnerable, studies show. This is a dangerous new risk if we insist on keeping thousands of weapons we don't need. 1/ https://www.washingtonp…
-
@etherealmind
Greg Ferro
on x
Behind every successful ransomware event is a team of very tired infrastructure engineers muttering “I told you so” and executives shouting “it was only a matter of time”. Thoughts and prayers. https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
As suspected, the Colonial Pipeline precautionary shutdown was due to ransomware. This is what I was hearing from sources as well. https://www.washingtonpost.com/ ...
-
@noahpinion
Noah Smith
on x
Cyberattacks now can *and do* shut down key U.S. infrastructure. https://www.reuters.com/...
-
@sammy_roth
Sammy Roth
on x
One of the nation's largest pipelines, which carries refined gasoline and jet fuel from Texas up the East Coast, was forced to shut down after being hit by ransomware in a vivid demonstration of the vulnerability of energy infrastructure to cyberattacks: https://www.nytimes.com/.…
-
@jasonbordoff
Jason Bordoff
on x
This should be wake up call to two key risks we've long known about: the vulnerability of our energy infrastructure to cyberattack & the dependence of much of the eastern seaboard's fuel supply on this one pipeline, particularly after the closure of several Northeast refineries. …
-
@thegrugq
Thaddeus E. Grugq
on x
“US pipeline system shutdown after {exposed VPN system not patched, weak password RDP exposed on internet, employee runs malware emailed to them}” After gaining access, financially motivated threat actors disrupted systems to extort money. Cyber extortion is big criminal business…
-
@dnvolz
Dustin Volz
on x
The attack appears to involve ransomware, according to people familiar with the investigation. No indications at this time OT systems were directly hit. I'm told FireEye is probing the hack for Colonial. https://twitter.com/...
-
@urbanachievr
Christian Vanderbrouk
on x
If confirmed as a cyberattack, how is this not an act of war? https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
Update: Biden was briefed this morning on the Colonial pipeline cyberattack, a White House spokeswoman confirms. Admin is working with company to restore operations as quickly as possible. https://www.wsj.com/...
-
@k8em0
Katie Moussouris
on x
I'm old enough to recall when penetration testers were routinely chastised by business owners for bringing up threats that could lead to ransomware - especially when we retested & found the same bugs at their next audit. Let's hope this doesn't end with knee jerk policy on Monday…
-
@joycewhitevance
Joyce Alene
on x
Cyber attacks are like arsons - you need someone to put the fire out, but then you need investigators to figure out who started it & how. This type of attack on our infrastructure is one of the major threats we face. https://www.washingtonpost.com/ ...
-
@senmarkey
Ed Markey
on x
An understaffed, underprepared TSA cannot successfully ensure the security of dangerous and susceptible natural gas pipeline infrastructure. The federal inability to prevent cyberattacks turns our pipeline system into a risk for communities. https://twitter.com/...
-
@cloud_opinion
@cloud_opinion
on x
Do you call the hackers that took out oil pipeline whitehats because they delayed climate change by half a second?
-
@katearonoff
Kate Aronoff
on x
cyberattack shuts down Colonial Pipeline is quite the sentence https://www.nytimes.com/...
-
@natashabertrand
Natasha Bertrand
on x
“The operator, Colonial Pipeline, which transports more than 100 million gallons of gasoline and other fuel daily from Houston to the New York Harbor...said it learned of the cyberattack on Friday, causing them to pause operations.” https://www.cnn.com/...
-
@dnvolz
Dustin Volz
on x
Two people briefed on the probe said the attack appeared to be limited to information systems and hadn't infiltrated operational control systems, but cautioned that the investigation was in its early stages. https://www.wsj.com/...
-
@shashj
Shashank Joshi
on x
“The [ransomware] attack on top U.S. fuel pipeline operator Colonial Pipeline appears to have been carried out by a criminal group, but federal officials and the private security firm Mandiant are still investigating the matter, one official said.” https://www.washingtonpost.com/…
-
@ajohnsocyber
Ann Johnson
on x
We spend a lot of time legitimately discussing Nation State activity whilst ransomware - often used by criminal gangs - is still the most disruptive global cyber problem. There is often affiliation b/t the two. Regardless don't take your eyes off ransomware anytime soon. https://…
-
@bing_chris
Chris Bing
on x
First reported by WaPo. Have confirmed it was ransomware. https://twitter.com/...
-
@juliettekayyem
Juliette Kayyem
on x
45% of the East Coast's fuel supply is carried through one delivery system, operated by Colonial Pipeline, the victim of a cyberattack Friday. The shutdown was precautionary; company says attack did not impact delivery. But, that's a lot of dependency on one company. https://twit…
-
@jimsciutto
Jim Sciutto
on x
Can anyone share some examples of where “cyber security” is working? Critical government and private sector networks are consistently proving themselves vulnerable. https://twitter.com/...
-
@scalzi
John Scalzi
on x
This is a very serious issue, but as I am a nerd, the thing in this story that really stuck out was when that guy said “it is the country's jugular aorta for moving fuel” and I was all EXCUSE ME I THINK YOU MEAN CAROTID ARTERY DO YOU EVEN ANATOMY SIR https://www.nytimes.com/...
-
@peterzeihan
Peter Zeihan
on x
I truly hope that this was not done by a state actor. If a foreign government hacked American critical infrastructure, the American response is going to be brutal. https://www.wsj.com/...
-
@nycsouthpaw
Southpaw
on x
An ongoing “cybersecurity attack” has turned off the biggest gasoline pipeline from the gulf to the US east coast. https://www.colpipe.com/... https://twitter.com/...
-
@nycsouthpaw
Southpaw
on x
Quite a kicker. https://twitter.com/...
-
@robertmlee
Robert M. Lee
on x
Good reporting by Ellen with quotes from me. The reality is ransomware is becoming more pervasive in both IT and OT networks, impacts in IT can impact operations as well. https://twitter.com/...
-
@sstapczynski
Stephen Stapczynski
on x
This is wild Colonial Pipeline, which operates the largest US gasoline and diesel pipeline system, said it shut its entire network after a cyber-attack. The artery transports roughly 45% of the fuel to the East Coast https://www.bloomberg.com/... https://twitter.com/...
-
@jasonbordoff
Jason Bordoff
on x
Colonial is a critical piece of energy infrastructure, supplying nearly half of gasoline & diesel along much of east coast. If outage lasts, could see higher prices, calls to tap new northeast gasoline reserve & renewed discussion of fuel system resiliency https://www.energypolic…
-
@anthony
@anthony
on x
The Colonial Pipeline is the largest refined-products pipeline in the U.S., transporting more than 100 million gallons per day, or roughly 45% of fuel consumed on the East Coast https://www.wsj.com/...
-
@anthony
@anthony
on x
The main conduit carrying gasoline and diesel fuel to the U.S. East Coast said it had halted all operations after being hit with a cyberattack https://www.wsj.com/...