Home / Blog / Colonial Pipeline: One Old Password Shut Down Fuel for the US East Coast
Korp Labs · Field Notes

Colonial Pipeline: One Old Password Shut Down Fuel for the US East Coast

 ·  4 min read  ·  By Korp VPN

On 7 May 2021, Colonial Pipeline shut down the pipeline system that carries roughly 45% of the fuel consumed on the United States East Coast — around 2.5 million barrels a day of petrol, diesel and jet fuel.

Within days there were queues at filling stations across the southeast, states declared emergencies, and some airlines rerouted flights around fuel availability. People filled plastic bags with petrol, which fire services had to publicly discourage.

The intrusion that caused this required no zero-day exploit, no custom malware and no insider. Attackers logged in.

The account nobody remembered

The entry point was a VPN account used for remote access to the corporate network. It was no longer actively used, but it had never been deactivated.

Its password had appeared in a batch of credentials leaked from some other, unrelated breach — the ordinary consequence of the same password being used in more than one place. Someone found it, tried it, and it worked.

The account had no multi-factor authentication. A password was sufficient.

That is the whole intrusion. A dormant account, a reused password, and a missing second factor.

What followed

Once inside the corporate network, the DarkSide ransomware group did what such groups do: moved through the environment, took copies of data for extortion leverage, and then encrypted systems.

An important detail is frequently misunderstood. The ransomware hit the business network — billing, scheduling, corporate IT — not the industrial control systems that physically operate the pipeline.

Colonial shut the pipeline down anyway.

The reasoning was partly precautionary — uncertainty about whether the attackers could reach operational systems — and partly mundane: with billing systems down, the company could not reliably measure and invoice the fuel it delivered. A pipeline that cannot bill for what it moves is a pipeline that stops.

This is worth sitting with. The physical infrastructure was never compromised. The dependency that took it offline was accounting.

Colonial paid a ransom of roughly $4.4 million in Bitcoin. The decryption tool provided was reportedly slow enough that the company largely restored from its own backups regardless. The US Department of Justice later recovered about $2.3 million by seizing the wallet.

Why this case matters more than more sophisticated ones

Most high-profile attacks are, in some sense, reassuring: they involve resources ordinary organisations do not face. Colonial is the opposite. Every element of it is present in a very large number of organisations right now.

Dormant accounts that were never closed. Every organisation has them — the contractor who finished last year, the service account for a decommissioned system, the emergency access nobody wants to remove. Each is a credential that exists, still works, and is watched by nobody.

Password reuse. The password was not guessed or cracked. It was already public because it had been used elsewhere. Credential-stuffing tooling automates this at enormous scale: take breach dumps, try them everywhere, see what opens.

Remote access without a second factor. Multi-factor authentication would have made the leaked password useless. It is the single highest-value control available, and it was absent on the one door facing the internet.

Business systems as a single point of failure for physical operations. The operational technology was fine. The company still stopped.

What to take from it

For an organisation, the checklist is uncomfortably short and mostly free:

For an individual, the same failure mode is the most common way personal accounts are lost, and the same defences apply:

There is a broader point about VPNs specifically, since one is at the centre of this story. A VPN is a tool for protecting traffic in transit — it is not an authentication system, and it does not make an entry point safe on its own. Colonial's VPN worked exactly as designed. It faithfully granted encrypted remote access to whoever presented valid credentials, and the credentials were valid.

The encryption was never the weak link. The list of who was still allowed in was.

hacking historyransomwarepasswordsnetwork security

Read this on a network nobody is watching

Korp VPN encrypts every packet leaving your device with AES-256 and a stealth protocol that looks like ordinary HTTPS traffic. Unlimited bandwidth, 20+ countries, a strict no-logs policy, and a 5-day free trial — from $1.60 per month.

← Previous
Why Free VPNs Are Dangerous — What the Research Actually Found
Next →
WireGuard vs OpenVPN vs Stealth Protocols: Which One Should You Actually Use?

More from Korp Labs

What "No-Logs VPN" Really Means and How to Check the Claim

Almost every VPN says it keeps no logs. The phrase can mean very different things. Here is what a meaningful no-logs policy covers, and the questions that expose a weak one.

VPN vs Proxy vs Tor: What Each One Actually Protects

They all change your IP address, but they protect very different things. A plain-language comparison of VPNs, proxies and Tor, and how to pick the right one for what you are doing.

How to Test Your VPN for Leaks: DNS, IPv6 and WebRTC

A VPN can be connected and still leak your real IP address or DNS lookups. Here is how to run the three tests that matter in under five minutes, and how to fix what you find.