One Year Later: 3 Insights Into the Colonial Pipeline Attack and Gas & Oil Critical Infrastructure
ID: b521bab7-1692-52db-872c-86d05e7b77db
STIX ID: report--b521bab7-1692-52db-872c-86d05e7b77db
Feed Name: Censys Blog
Date Published: 2022-05-16
Date Updated: 2026-04-27
Author: Matt Lembright; Global Lead Of Censys Data
This report recounts the May 2021 Colonial Pipeline ransomware incident attributed to the Russian-speaking DarkSide gang and summarizes Censys's assessment of internet exposure across Colonial and ten other major U.S. pipeline companies: root cause (reused VPN password and missing MFA), Censys findings of numerous internet-exposed hosts, insecure protocols, and expired certificates, observed improvements at Colonial (reduced exposed logins and outdated software), and an overall increase in attack surface across the peer group that highlights ongoing risk to critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
