CASE DOSSIER pleaded

Colonial Pipeline DarkSide Ransomware Attack

Docket: 1:21-mj-00454 Court: U.S. District Court for the Northern District of California Opened: 2021-05-07 Sector: Energy, Oil and Gas

Key Facts

Status
PLEADED
Legal disposition
Loss Amount
$4.4 million
Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.
Techniques
4
Verified mappings
Defendants
0
Named in charges
  • Legal Status: PLEADED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Energy, Oil and Gas.
  • Documented Financial Loss: $4.4 million.
  • 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.

Procedural & Incident Timeline

2021-05-11 advisory

CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics.

2021-06-07 court_order

DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak." Senate Homeland Security Committee Testimony reviewed
T1486 Data Encrypted for Impact
Impact
"DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution." CISA Alert AA21-131A reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines." FBI Alert Flash reviewed
T1021.001 Remote Desktop Protocol
Lateral Movement
"The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers." House Homeland Security Committee Testimony reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Colonial Pipeline DarkSide Ransomware Attack, No. 1:21-mj-00454 (U.S. District Court for the Northern District of California 2021), https://cyberattackcaselibrary.pages.dev/cases/colonial-pipeline-ransomware/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/colonial-pipeline-ransomware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>