logo

One Year Later: 3 Insights Into the Colonial Pipeline Attack and Gas & Oil Critical Infrastructure

ID: b521bab7-1692-52db-872c-86d05e7b77db

STIX ID: report--b521bab7-1692-52db-872c-86d05e7b77db

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2022-05-16

Date Updated: 2026-04-27

Author: Matt Lembright; Global Lead Of Censys Data

...
...

This report recounts the May 2021 Colonial Pipeline ransomware incident attributed to the Russian-speaking DarkSide gang and summarizes Censys's assessment of internet exposure across Colonial and ten other major U.S. pipeline companies: root cause (reused VPN password and missing MFA), Censys findings of numerous internet-exposed hosts, insecure protocols, and expired certificates, observed improvements at Colonial (reduced exposed logins and outdated software), and an overall increase in attack surface across the peer group that highlights ongoing risk to critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.