/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Investigator says hackers breached Colonial Pipeline through a VPN account whose password has since been discovered inside a batch of leaks on the dark web

- Investigators suspect hackers got password from dark web leak  — Colonial CEO hopes U.S. goes after criminal hackers abroad

Bloomberg

Context & Ripple Effects

Earlier coverage identified DarkSide as the group behind an attack that forced Colonial Pipeline to halt operations and involved the theft and encryption of roughly 100GB of data. The newly reported leaked VPN credential supplies a likely initial-access explanation for an incident previously defined mainly by its operational disruption and ransom demand.

The exposure also sits alongside reports that a pipeline-compliance technology provider had data posted on the dark web, underscoring that pipeline-sector cyber risk extends beyond the operator itself to specialized service providers.

First-order effects

  • Colonial Pipeline must treat the compromised VPN account and any reused credentials as an immediate access-control failure, requiring credential resets and tighter remote-access controls.
  • The reported breach vector strengthens Colonial's call for U.S. action against criminal hackers abroad by tying a major disruption to credentials circulating in criminal leak markets.

Second-order effects

  • Pipeline operators and their compliance vendors face pressure to audit remote-access accounts and leaked-password exposure, rather than treating ransomware defenses as only a data-backup problem.
  • Security providers serving critical-infrastructure customers gain a clearer case for credential monitoring and stronger VPN authentication as controls against initial access.

Third-order effects

  • If similar incidents keep tracing back to exposed credentials, critical-infrastructure cyber policy is likely to focus more on identity controls and third-party access alongside disruption response.
  • The combination of an operator breach and DarkSide's earlier data theft and encryption points to ransomware risk becoming a supply-chain issue across infrastructure operators and their service providers.

The trend: Ransomware defense for critical infrastructure is shifting from recovery after encryption toward preventing initial access through exposed identities and connected vendors.

Discussion

  • @williamturton William Turton on x
    NEW: hackers gained access to the network of Colonial Pipeline using the compromised credentials of a legacy VPN account. The account was not actively used and did not use multi-factor authentication. https://www.bloomberg.com/...
  • @kennwhite Kenn White on x
    The account was not actively used and the password was in a public breach database. https://twitter.com/...
  • @evacide Eva on x
    Sometimes hacking is deploying a chain of 0-days to gain remote execution. But more often, it is this. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Mandiant says Colonial Pipeline hackers used credentials for an employee's old VPN account to get in. The worker's passwrd was among stolen/leaked passwords posted online from other hacks, suggesting the worker used it for a diff account. But unclear if hackers got it thru leak h…
  • @dnvolz Dustin Volz on x
    Mandiant confirms on the record Colonial Pipeline was hacked with compromised credentials used on a VPN w/o two-factor authentication. This disclosure comes late on a Friday ahead of the CEO's scheduled testimony about the hack in front of Congress next week. 🤔 https://twitter.co…
  • @lilithsaintcrow Lili Saintcrow on x
    Wait, wasn't the end result of this that it messed up billing so the company shut everything down because their customers might possibly get some petrol for free? https://www.bloomberg.com/...
  • @crispinburke @crispinburke on x
    There also appears to have been no Multi-Factor Authentication. https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    So the water hack came down to a shared password and decade-old Windows software that hasn't been updated in years. And now, thanks to @williamturton we know that Colonial Pipeline ultimately came down to the lack of multi-factor authentication. What are we doing? https://twitter…