{
  "id": "case-colonial-pipeline",
  "slug": "colonial-pipeline-ransomware",
  "title": "Colonial Pipeline DarkSide Ransomware Attack",
  "summary": "DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.",
  "case_number": "1:21-mj-00454",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2021-05-07",
  "status": "pleaded",
  "victim_sector": "Energy, Oil and Gas",
  "victim_country": "United States",
  "loss_amount_usd": 4400000,
  "loss_amount_note": "Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.",
  "first_seen_at": "2021-05-06T00:00:00Z",
  "last_updated_at": "2026-09-17T11:00:00Z",
  "actor_slug": "darkside",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak.",
      "evidence_locator": "Senate Homeland Security Committee Testimony",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Senate Testimony of Colonial Pipeline CEO",
      "source_url": "https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution.",
      "evidence_locator": "CISA Alert AA21-131A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-131A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines.",
      "evidence_locator": "FBI Alert Flash",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Cyber Division Alert",
      "source_url": "https://www.fbi.gov/investigate/cyber",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1021.001",
      "evidence_excerpt": "The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers.",
      "evidence_locator": "House Homeland Security Committee Testimony",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Congressional Hearing Transcript",
      "source_url": "https://homeland.house.gov/hearing/cyber-threats-in-the-pipeline-lessons-from-the-colonial-pipeline-attack/",
      "technique_name": "Remote Desktop Protocol",
      "tactic": "Lateral Movement"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2021-05-11",
      "description": "CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics."
    },
    {
      "event_type": "court_order",
      "event_date": "2021-06-07",
      "description": "DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "A single compromised employee password found on a dark web breach compilation for an inactive legacy Virtual Private Network (VPN) account that lacked multifactor authentication (MFA).",
    "blast_radius": "Colonial Pipeline proactively shut down all 5,500 miles of its fuel transport pipeline for 6 days, cutting off 45% of the fuel supply to the East Coast of the United States. The shutdown sparked panic buying, gas station fuel outages across 17 states, and flight diversions. Colonial paid 75 Bitcoins ($4.4M) in extortion.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Legacy VPN Ingress Without MFA",
        "description": "DarkSide affiliates used valid domain credentials harvested from a prior third-party breach to authenticate through an inactive, unmonitored enterprise VPN gateway lacking multifactor verification.",
        "technical_artifacts": [
          "Legacy VPN profile",
          "Stolen Active Directory credential"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Discovery & Reconnaissance",
        "title": "Domain Trust and Network Mapping",
        "description": "Attackers executed lightweight discovery utilities including AdFind and BloodHound to map internal network segments, identify domain controllers, and locate corporate billing infrastructure.",
        "technical_artifacts": [
          "AdFind.exe",
          "BloodHound graph data"
        ],
        "mitre_technique_id": "T1087"
      },
      {
        "phase": "Exfiltration",
        "title": "Automated Cloud Storage Data Theft",
        "description": "Threat actors gathered approximately 100 gigabytes of sensitive commercial files and employee records within two hours, staging and exfiltrating the archive to Mega cloud storage services.",
        "technical_artifacts": [
          "Mega cloud upload",
          "Encrypted 7-Zip archives"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Lateral Movement & GPO Staging",
        "title": "Group Policy Object Payload Distribution",
        "description": "After securing domain administrative rights, the attackers pushed DarkSide ransomware binaries across internal network endpoints and billing servers via Active Directory Group Policy Objects.",
        "technical_artifacts": [
          "Active Directory GPO push",
          "DarkSide.exe"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Impact & Operational Shutdown",
        "title": "Precautionary Physical OT Infrastructure Halting",
        "description": "Because the enterprise billing systems were encrypted and operators could not verify fuel delivery tallies, Colonial Pipeline proactively halted physical pipeline operations to prevent infection spillover into industrial SCADA controls.",
        "technical_artifacts": [
          "DarkSide payload",
          "Billing database encryption"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across 100% of remote access endpoints without exceptions.",
      "Decommission and purge all legacy, test, and orphaned VPN accounts during continuous identity hygiene audits.",
      "Implement strict microsegmentation and one-way data diodes between IT billing systems and Operational Technology (OT) SCADA pipelines.",
      "Deploy network egress filtering and automated alerts on massive cloud storage uploads."
    ]
  }
}