/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← β†’ days Β· ↑ ↓ browse Β· Enter similar Β· o open

Investigator says hackers breached Colonial Pipeline through a VPN account whose password has since been discovered inside a batch of leaks on the dark web

🍿 Gangster Coworking CNN : Ransomware attackers used compromised password to access Colonial Pipeline network Kim Lyons / The Verge : Hackers reportedly used a compromised password in Colonial Pipeline cyberattack Michael Novinson / CRN : Colonial Pipeline Hacked Via Inactive Account Without MFA Jenn Gidman / Newser : After β€˜Exhaustive Search,’ a Reveal on Colonial Pipeline Breach Mat Smith / Engadget : The Morning After: Which streaming TV box or stick is the best one for you? Richard Lawler / Yahoo Finance : Colonial Pipeline ransomware attack linked to a single VPN login Cammy Pedroja / Newsweek : Colonial Pipeline Hackers Used Unprotected VPN to Access Network: Report Anthony Grenga / Security Boulevard : The June IronNet Threat Intelligence Brief Corbin Bolies / The Daily Beast : Colonial Pipeline Hack Result of Single Compromised Password Atlanta Journal-Constitution : BREAKING: Colonial Pipeline attack reportedly linked to 1 account Tweets: William Turton / @williamturton : NEW: hackers gained access to the network of Colonial Pipeline using the compromised credentials of a legacy VPN account. The account was not actively used and did not use multi-factor authentication. https://www.bloomberg.com/... ClearingTheFog / @clearing_fog : So - if this report is true - the Colonial pipeline attack could have been prevented simply by following what is *standard practice everywhere* - regularly disabling accounts that are no longer being used. https://twitter.com/... Carl Hewitt / @profcarlhewitt : Excellent suggestions on measures that companies should take immediately to slow down the rate of successful ransomware attacks.. However, cyber vulnerabilities are becoming worse because of increasing deployment of IoT and AI. Fundamental technological improvements required. https://twitter.com/... John Opdenakker / @j_opdenakker : A VPN account with a leaked password and no 2FA. It's the lack of this kind of basic security that makes it all to easy for attackers. https://www.bloomberg.com/... #infosec @brianhonan : Colonial Pipeline Cyber Attack: Hackers Used Compromised Password - Bloomberg This shows the importance of having a robust leavers process in place, using password managers so staff don't reuse passwords, and implementing MFA. https://www.bloomberg.com/... @wylienewmark : Waiting for someone with a galaxy-brain to explain how offensive cyber operations β€” rather than than the cyber πŸ₯¦ of good security hygiene β€” would've prevented this initial access tactic. https://twitter.com/... @viking_sec : Asset management should include access management. https://twitter.com/... Valdis Krebs / @valdiskrebs : The hack that took down the largest fuel pipeline in the U.S. and led to shortages across the East Coast was the result of a single compromised password, according to a cybersecurity consultant who responded to the attack. https://www.bloomberg.com/... Nicole Perlroth / @nicoleperlroth : So the water hack came down to a shared password and decade-old Windows software that hasn't been updated in years. And now, thanks to @williamturton we know that Colonial Pipeline ultimately came down to the lack of multi-factor authentication. What are we doing? https://twitter.com/... Kenn White / @kennwhite : The account was not actively used and the password was in a public breach database. https://twitter.com/... Dustin Volz / @dnvolz : Mandiant confirms on the record Colonial Pipeline was hacked with compromised credentials used on a VPN w/o two-factor authentication. This disclosure comes late on a Friday ahead of the CEO's scheduled testimony about the hack in front of Congress next week. πŸ€” https://twitter.com/... Lili Saintcrow / @lilithsaintcrow : Wait, wasn't the end result of this that it messed up billing so the company shut everything down because their customers might possibly get some petrol for free? https://www.bloomberg.com/... @crispinburke : There also appears to have been no Multi-Factor Authentication. https://twitter.com/... Kim Zetter / @kimzetter : Mandiant says Colonial Pipeline hackers used credentials for an employee's old VPN account to get in. The worker's passwrd was among stolen/leaked passwords posted online from other hacks, suggesting the worker used it for a diff account. But unclear if hackers got it thru leak https://twitter.com/... Eva / @evacide : Sometimes hacking is deploying a chain of 0-days to gain remote execution. But more often, it is this. https://twitter.com/...

Bloomberg

Context & Ripple Effects

Colonial Pipeline’s shutdown had already been tied to DarkSide, which stole and encrypted roughly 100GB of data before demanding ransom. The new account-level account narrows the reported entry point to an inactive VPN credential found in dark-web leaks, rather than an unknown exploit.

The episode also sits alongside the later reported theft from pipeline compliance provider LineStar Integrity Services, underscoring that pipeline-sector exposure extends beyond operators’ own networks.

First-order effects

  • Colonial Pipeline must treat inactive remote-access accounts and leaked passwords as live operational risk, with the reported lack of multi-factor authentication making VPN access an immediate remediation priority.
  • DarkSide’s reported intrusion is recast as credential-based access: the group’s ability to steal and encrypt data depended on a compromised login rather than a newly disclosed technical vulnerability.

Second-order effects

  • Pipeline operators and their compliance vendors face pressure to inventory dormant VPN accounts, revoke stale access, and enforce multi-factor authentication, since a single exposed credential can provide a path into operationally significant networks.
  • Security providers’ value shifts toward identity and access controlsβ€”credential monitoring, account lifecycle management, and MFA deploymentβ€”rather than perimeter defenses alone.

Third-order effects

  • If similar incidents continue, critical-infrastructure cyber scrutiny will increasingly measure operators by basic identity-control discipline, turning access governance into a policy and procurement issue rather than solely an IT task.
  • The pattern favors security programs that treat third-party and legacy remote access as part of the same risk surface as an operator’s core network.

The trend: Critical-infrastructure ransomware is making leaked credentials, dormant accounts, and weak authentication central targets for both attackers and defensive oversight.

Discussion

  • @williamturton William Turton on x
    NEW: hackers gained access to the network of Colonial Pipeline using the compromised credentials of a legacy VPN account. The account was not actively used and did not use multi-factor authentication. https://www.bloomberg.com/...
  • @clearing_fog ClearingTheFog on x
    So - if this report is true - the Colonial pipeline attack could have been prevented simply by following what is *standard practice everywhere* - regularly disabling accounts that are no longer being used. https://twitter.com/...
  • @brianhonan @brianhonan on x
    Colonial Pipeline Cyber Attack: Hackers Used Compromised Password - Bloomberg This shows the importance of having a robust leavers process in place, using password managers so staff don't reuse passwords, and implementing MFA. https://www.bloomberg.com/...
  • @wylienewmark @wylienewmark on x
    Waiting for someone with a galaxy-brain to explain how offensive cyber operations β€” rather than than the cyber πŸ₯¦ of good security hygiene β€” would've prevented this initial access tactic. https://twitter.com/...
  • @viking_sec @viking_sec on x
    Asset management should include access management. https://twitter.com/...
  • @valdiskrebs Valdis Krebs on x
    The hack that took down the largest fuel pipeline in the U.S. and led to shortages across the East Coast was the result of a single compromised password, according to a cybersecurity consultant who responded to the attack. https://www.bloomberg.com/...
  • @nicoleperlroth Nicole Perlroth on x
    So the water hack came down to a shared password and decade-old Windows software that hasn't been updated in years. And now, thanks to @williamturton we know that Colonial Pipeline ultimately came down to the lack of multi-factor authentication. What are we doing? https://twitter…
  • @kennwhite Kenn White on x
    The account was not actively used and the password was in a public breach database. https://twitter.com/...
  • @dnvolz Dustin Volz on x
    Mandiant confirms on the record Colonial Pipeline was hacked with compromised credentials used on a VPN w/o two-factor authentication. This disclosure comes late on a Friday ahead of the CEO's scheduled testimony about the hack in front of Congress next week. πŸ€” https://twitter.co…
  • @lilithsaintcrow Lili Saintcrow on x
    Wait, wasn't the end result of this that it messed up billing so the company shut everything down because their customers might possibly get some petrol for free? https://www.bloomberg.com/...
  • @crispinburke @crispinburke on x
    There also appears to have been no Multi-Factor Authentication. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Mandiant says Colonial Pipeline hackers used credentials for an employee's old VPN account to get in. The worker's passwrd was among stolen/leaked passwords posted online from other hacks, suggesting the worker used it for a diff account. But unclear if hackers got it thru leak h…
  • @evacide Eva on x
    Sometimes hacking is deploying a chain of 0-days to gain remote execution. But more often, it is this. https://twitter.com/...