logo

Colonial Pipeline Ransomware Attack: What we know so far

ID: c6bc27ad-f2ff-5636-83ea-f9149c29e573

STIX ID: report--c6bc27ad-f2ff-5636-83ea-f9149c29e573

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2021-05-11

Date Updated: 2026-04-29

...
...

On 07 May 2021 the Colonial Pipeline network was impacted by a DarkSide ransomware attack that forced the company to halt operations and disrupted fuel distribution on the U.S. East Coast; the FBI later attributed the incident to DarkSide. The report summarizes the incident, likely initial access vectors (including possible IAB-supplied RDP access), the national-level operational impact and emergency responses, and provides mitigation guidance for IT/OT security to reduce similar risks to critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.