CASE DOSSIER
pleaded
Colonial Pipeline DarkSide Ransomware Attack
Docket: 1:21-mj-00454 Court: U.S. District Court for the Northern District of California Opened: 2021-05-07 Sector: Energy, Oil and Gas
Key Facts
Status
PLEADED
Legal disposition
Loss Amount
$4.4 million
Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.
Techniques
4
Verified mappings
Defendants
0
Named in charges
- Legal Status: PLEADED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Energy, Oil and Gas.
- Documented Financial Loss: $4.4 million.
- 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.
Procedural & Incident Timeline
2021-05-11 advisory
CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics.
2021-06-07 court_order
DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak." | Senate Homeland Security Committee Testimony | reviewed |
| T1486 | Data Encrypted for Impact Impact | "DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution." | CISA Alert AA21-131A | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines." | FBI Alert Flash | reviewed |
| T1021.001 | Remote Desktop Protocol Lateral Movement | "The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers." | House Homeland Security Committee Testimony | reviewed |
CISA Cybersecurity Advisories
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, Colonial Pipeline DarkSide Ransomware Attack, No. 1:21-mj-00454 (U.S. District Court for the Northern District of California 2021), https://cyberattackcaselibrary.pages.dev/cases/colonial-pipeline-ransomware/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/colonial-pipeline-ransomware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>