On 7 May 2021, Colonial Pipeline shut down the pipeline system that carries roughly 45% of the fuel consumed on the United States East Coast — around 2.5 million barrels a day of petrol, diesel and jet fuel.
Within days there were queues at filling stations across the southeast, states declared emergencies, and some airlines rerouted flights around fuel availability. People filled plastic bags with petrol, which fire services had to publicly discourage.
The intrusion that caused this required no zero-day exploit, no custom malware and no insider. Attackers logged in.
The account nobody remembered
The entry point was a VPN account used for remote access to the corporate network. It was no longer actively used, but it had never been deactivated.
Its password had appeared in a batch of credentials leaked from some other, unrelated breach — the ordinary consequence of the same password being used in more than one place. Someone found it, tried it, and it worked.
The account had no multi-factor authentication. A password was sufficient.
That is the whole intrusion. A dormant account, a reused password, and a missing second factor.
What followed
Once inside the corporate network, the DarkSide ransomware group did what such groups do: moved through the environment, took copies of data for extortion leverage, and then encrypted systems.
An important detail is frequently misunderstood. The ransomware hit the business network — billing, scheduling, corporate IT — not the industrial control systems that physically operate the pipeline.
Colonial shut the pipeline down anyway.
The reasoning was partly precautionary — uncertainty about whether the attackers could reach operational systems — and partly mundane: with billing systems down, the company could not reliably measure and invoice the fuel it delivered. A pipeline that cannot bill for what it moves is a pipeline that stops.
This is worth sitting with. The physical infrastructure was never compromised. The dependency that took it offline was accounting.
Colonial paid a ransom of roughly $4.4 million in Bitcoin. The decryption tool provided was reportedly slow enough that the company largely restored from its own backups regardless. The US Department of Justice later recovered about $2.3 million by seizing the wallet.
Why this case matters more than more sophisticated ones
Most high-profile attacks are, in some sense, reassuring: they involve resources ordinary organisations do not face. Colonial is the opposite. Every element of it is present in a very large number of organisations right now.
Dormant accounts that were never closed. Every organisation has them — the contractor who finished last year, the service account for a decommissioned system, the emergency access nobody wants to remove. Each is a credential that exists, still works, and is watched by nobody.
Password reuse. The password was not guessed or cracked. It was already public because it had been used elsewhere. Credential-stuffing tooling automates this at enormous scale: take breach dumps, try them everywhere, see what opens.
Remote access without a second factor. Multi-factor authentication would have made the leaked password useless. It is the single highest-value control available, and it was absent on the one door facing the internet.
Business systems as a single point of failure for physical operations. The operational technology was fine. The company still stopped.
What to take from it
For an organisation, the checklist is uncomfortably short and mostly free:
- Inventory accounts with remote access, and disable anything unused. An account nobody needs is pure liability.
- Require multi-factor authentication on every externally reachable entry point, without exception for legacy systems — the exceptions are what get used.
- Segment networks so that reaching one part does not mean reaching all of it.
- Know which business dependencies would halt operations, and test that assumption before an incident does.
For an individual, the same failure mode is the most common way personal accounts are lost, and the same defences apply:
- Unique passwords everywhere, via a password manager. This is what makes a breach at one service stay at that service.
- Multi-factor authentication, prioritising email first — the account that can reset everything else.
- Check whether your addresses appear in known breaches, using a reputable breach-notification service, and change anything that shows up.
- Close accounts you no longer use. They do not become safer with age; they become forgotten while remaining valid.
There is a broader point about VPNs specifically, since one is at the centre of this story. A VPN is a tool for protecting traffic in transit — it is not an authentication system, and it does not make an entry point safe on its own. Colonial's VPN worked exactly as designed. It faithfully granted encrypted remote access to whoever presented valid credentials, and the credentials were valid.
The encryption was never the weak link. The list of who was still allowed in was.