logo

Recommendations Following the Colonial Pipeline Cyber Attack

ID: 74ddbec4-3d0f-576b-a5ce-8a02bf7b75c1

STIX ID: report--74ddbec4-3d0f-576b-a5ce-8a02bf7b75c1

Feed Name: Dragos Blog

Threat Score
85/100

Date Published: 2021-05-12

Date Updated: 2026-04-27

...
...

The Dragos analysis of the Colonial Pipeline incident attributes a disruptive May ransomware attack to the DarkSide group, describes how an IT compromise impacted OT operations prompting a precautionary shutdown, highlights common initial access vectors (exposed remote services, vulnerable VPN/FTA appliances, shared credentials) and lateral-movement techniques (RDP, SMB, NTLM), and recommends OT-specific defensive measures such as stronger segmentation, monitoring of crown-jewel assets, incident response planning, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.