Sources: Colonial paid ~$5M ransom in cryptocurrency within hours of the attack, but the hackers' decrypting tool was so slow that it had to use its own backups
this should significantly escalate the political pressure to finally counter the ransomware ecosystem https://www.bloomberg.com/... Barbara Malmet / @b52malmet : Maybe it was a four hundred pound eighth grader in a basement in Russia? https://twitter.com/... @blackvaultcom : “Colonial Pipeline Co. paid nearly $5 million to Eastern European hackers on Friday, contradicting reports earlier this week that the company had no intention of paying an extortion fee...” — Heh. Watch them do it again tomorrow. 🙄 https://finance.yahoo.com/... Paolo Gregoletto / @triviumpaolo : Cyber bullying works https://twitter.com/... Dr. Carol M. Swain / @carolmswain : Welcome to Biden's world. Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom https://finance.yahoo.com/... War Medic / @foxholemedicine : Great, now terrorists will be demanding a cool $50 Mil for a power grid. Was this a test run? Nice job, enablers. #WeDontNegotiate https://www.cnbc.com/... @reuters : 'So far there is no evidence based on, from our intelligence people, that Russia is involved, although there's evidence that the actors' ransomware is in Russia,' President Biden on the Colonial Pipeline hack https://www.reuters.com/... https://twitter.com/... Kim Zetter / @kimzetter : .@cnn has now confirmed what I wrote 4 days ago, that CP shut down pipeline because they couldn't bill customers. Per CNN: “The company halted operations because its billing system was compromised...and they were concerned they wouldn't be able to figure out how much to bill” https://twitter.com/... Kim Zetter / @kimzetter : .@nicoleperlroth has also confirmed that CP shut down pipeline in part because it couldn't bill customers, and in part to prevent ransomware from spreading. Big thanks to Nicole for the shoutout in this piece to my prior stories on billing issue. 🙏 https://www.nytimes.com/... Joe Concha / @joeconchatv : This sets a wonderful precedent... https://twitter.com/... BDW / @bryandeanwright : When you incentivize illegal behavior — to cross the border, to hack infrastructure — more will try. This was a disastrous decision. https://twitter.com/... Mitch Kapor / @mkapor : Sometimes it IS a pipeline problem. https://twitter.com/... Max Burns / @themaxburns : The lesson here, which our government has been slow to acknowledge for years, is that our critical civil infrastructure is so vulnerable to cyberattack that even non-state free agents can seize and ransom our own infrastructure back to us. https://finance.yahoo.com/... Denilson N. / @dnastacio : They should have paid extra for the professional edition of the decrypting tool. https://twitter.com/... Corey Quinn / @quinnypig : The real story here is that an enterprise was able to pay $5 million without six weeks of dickering with Procurement beforehand. https://twitter.com/... Kevin Collier / @kevincollier : Wild reporting from @WilliamTurton here. Very key point is that Colonial did not restore their operations by paying tha ransom, though. They paid, realized DarkSide's decryptor sucks (which we already knew), then restored from backups anyway. https://www.bloomberg.com/... @briankrebs : Bloomberg says Colonial Pipeline paid ~$5M to the DarkSide ransomware extortionists, 6 days after the company shut down 5,500 miles of fuel pipe in response to attack. https://www.bloomberg.com/... That's less than 1/2 what a similarly sized recent victim paid https://krebsonsecurity.com/ ... Thomas Brewster / @iblametom : So Colonial paid up, decrypting tool didn't work, they used their own backups to restore... and yet they still shut the pipeline down for five days? https://twitter.com/... Southpaw / @nycsouthpaw : Colonial paid the cost of approx five avg homes in Brooklyn as ransom for its pipeline data https://www.bloomberg.com/... Chuck Wendig / @chuckwendig : well that won't encourage more of the same to be sure https://twitter.com/... Robert Burgess / @bobonmarkets : Nah, crypto isn't the domain of criminals and hackers https://www.bloomberg.com/... via @business Thaddeus E. Grugq / @thegrugq : Colonial Pipeline paid $5million, according to the grain of rice backdoor people. https://www.bloomberg.com/... Keith Olbermann / @keitholbermann : But don't worry. They'll immediately share those costs with YOU, Joe Driver https://twitter.com/... Glen Gilmore / @glengilmore : Contradicting Earlier Reports, #ColonialPipeline Paid Hackers Nearly $5M in Ransom #Ransomware costs increased by 311% in 2020, reaching $350M in #cryptocurrency Average ransom paid by organizations in 2020 was $312,493 https://www.bloomberg.com/... #IoT #infrastructure https://twitter.com/... Alex Hern / @alexhern : I wonder what would happen to ransomware if the US government declared interacting with a bitcoin exchange a prima facie AML violation Joseph Cox / @josephfcox : This is bad for ransomware operators. If your tool is so crappy that even when people pay they still then have to go use their backups, why pay at all https://www.bloomberg.com/... https://twitter.com/... Brad Stone / @bradstone : incredible and terrifying. https://twitter.com/... Matthew Green / @matthew_d_green : I'm definitely in the wrong job. https://www.bloomberg.com/... Hamza Shaban / @hshaban : Once the hackers received the $5 million in crypto, they gave Colonial Pipeline a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system https://www.bloomberg.com/... Secretary Jennifer Granholm / @secgranholm : We just got off the phone with #ColonialPipeline CEO. They are restarting pipeline operations today at ~5pm. More soon. Frank Bajak / @fbajak : Audit of Colonial Pipeline three years ago found “atrocious” info management. “I mean an eighth-grader could have hacked into that system,” the author told @AP https://apnews.com/...
Context & Ripple Effects
Colonial had already halted operations after DarkSide reportedly stole and encrypted about 100GB of data, turning a cyberattack into an operational disruption. The reported payment adds a concrete cost to that earlier shutdown and data-extortion attack.
The failed decryptor is the critical detail: Colonial’s own backups, rather than the paid-for tool, reportedly supported recovery. Later coverage frames the payment as an executive decision made amid uncertainty over the attack’s scope.
First-order effects
- Colonial absorbed both a roughly $5 million cryptocurrency payment and the operational work of restoring from backups, because DarkSide’s decryption tool reportedly could not restore systems fast enough.
- DarkSide received a rapid payment, while its ineffective tool weakened the practical value of the service ransomware operators claim to provide victims.
Second-order effects
- For operators facing ransomware, tested backups become a more credible recovery path than relying on an attacker’s decryption process, shifting attention toward recoverability in procurement.
- The disruption and payment intensify the political pressure described in the coverage to target the ransomware ecosystem, not only the affected company’s restoration process.
Third-order effects
- If ineffective decryptors are a recurring feature of ransomware incidents, resilience spending will increasingly be judged by how quickly organizations can operate from independent backups rather than by their ability to negotiate a ransom.
- The later seizure of part of Colonial’s ransom payment indicates that ransomware response is extending from incident recovery into tracing and recovering cryptocurrency proceeds.
The trend: Ransomware is pushing critical operators toward recoverability as a core operating requirement while authorities pursue the financial infrastructure behind attacks.