CASE DOSSIER pleaded

Colonial Pipeline DarkSide Ransomware Attack

Docket: 1:21-mj-00454 Court: U.S. District Court for the Northern District of California Opened: 2021-05-07 Sector: Energy, Oil and Gas

Key Facts

Status
PLEADED
Legal disposition
Loss Amount
$4.4 million
Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.
Techniques
4
Verified mappings
Defendants
0
Named in charges
  • Legal Status: PLEADED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Energy, Oil and Gas.
  • Documented Financial Loss: $4.4 million.
  • 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

A single compromised employee password found on a dark web breach compilation for an inactive legacy Virtual Private Network (VPN) account that lacked multifactor authentication (MFA).

Operational & Financial Fallout

Colonial Pipeline proactively shut down all 5,500 miles of its fuel transport pipeline for 6 days, cutting off 45% of the fuel supply to the East Coast of the United States. The shutdown sparked panic buying, gas station fuel outages across 17 states, and flight diversions. Colonial paid 75 Bitcoins ($4.4M) in extortion.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: PLEADED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

A single compromised employee password found on a dark web breach compilation for an inactive legacy Virtual Private Network (VPN) account that lacked multifactor authentication (MFA).

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Legacy VPN Ingress Without MFA
MITRE ATT&CK T1078 →

DarkSide affiliates used valid domain credentials harvested from a prior third-party breach to authenticate through an inactive, unmonitored enterprise VPN gateway lacking multifactor verification.

Artifacts & Tooling: Legacy VPN profile Stolen Active Directory credential
2
Discovery & Reconnaissance Domain Trust and Network Mapping
MITRE ATT&CK T1087 →

Attackers executed lightweight discovery utilities including AdFind and BloodHound to map internal network segments, identify domain controllers, and locate corporate billing infrastructure.

Artifacts & Tooling: AdFind.exe BloodHound graph data
3
Exfiltration Automated Cloud Storage Data Theft
MITRE ATT&CK T1567 →

Threat actors gathered approximately 100 gigabytes of sensitive commercial files and employee records within two hours, staging and exfiltrating the archive to Mega cloud storage services.

Artifacts & Tooling: Mega cloud upload Encrypted 7-Zip archives
4
Lateral Movement & GPO Staging Group Policy Object Payload Distribution
MITRE ATT&CK T1021.002 →

After securing domain administrative rights, the attackers pushed DarkSide ransomware binaries across internal network endpoints and billing servers via Active Directory Group Policy Objects.

Artifacts & Tooling: Active Directory GPO push DarkSide.exe
5
Impact & Operational Shutdown Precautionary Physical OT Infrastructure Halting
MITRE ATT&CK T1486 →

Because the enterprise billing systems were encrypted and operators could not verify fuel delivery tallies, Colonial Pipeline proactively halted physical pipeline operations to prevent infection spillover into industrial SCADA controls.

Artifacts & Tooling: DarkSide payload Billing database encryption
Real-World Blast Radius & Operational Fallout

Colonial Pipeline proactively shut down all 5,500 miles of its fuel transport pipeline for 6 days, cutting off 45% of the fuel supply to the East Coast of the United States. The shutdown sparked panic buying, gas station fuel outages across 17 states, and flight diversions. Colonial paid 75 Bitcoins ($4.4M) in extortion.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across 100% of remote access endpoints without exceptions.
✓ Decommission and purge all legacy, test, and orphaned VPN accounts during continuous identity hygiene audits.
✓ Implement strict microsegmentation and one-way data diodes between IT billing systems and Operational Technology (OT) SCADA pipelines.
✓ Deploy network egress filtering and automated alerts on massive cloud storage uploads.

Procedural & Incident Timeline

2021-05-11 advisory

CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics.

2021-06-07 court_order

DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak." Senate Homeland Security Committee Testimony reviewed
T1486 Data Encrypted for Impact
Impact
"DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution." CISA Alert AA21-131A reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines." FBI Alert Flash reviewed
T1021.001 Remote Desktop Protocol
Lateral Movement
"The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers." House Homeland Security Committee Testimony reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Colonial Pipeline DarkSide Ransomware Attack, No. 1:21-mj-00454 (U.S. District Court for the Northern District of California 2021), https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/colonial-pipeline-ransomware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>