{
  "id": "case-colonial-pipeline",
  "slug": "colonial-pipeline-ransomware",
  "title": "Colonial Pipeline DarkSide Ransomware Attack",
  "summary": "DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.",
  "case_number": "1:21-mj-00454",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2021-05-07",
  "status": "pleaded",
  "victim_sector": "Energy, Oil and Gas",
  "victim_country": "United States",
  "loss_amount_usd": 4400000,
  "loss_amount_note": "Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.",
  "first_seen_at": "2021-05-06T00:00:00Z",
  "last_updated_at": "2026-09-17T11:00:00Z",
  "actor_slug": "darkside",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak.",
      "evidence_locator": "Senate Homeland Security Committee Testimony",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Senate Testimony of Colonial Pipeline CEO",
      "source_url": "https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution.",
      "evidence_locator": "CISA Alert AA21-131A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-131A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines.",
      "evidence_locator": "FBI Alert Flash",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Cyber Division Alert",
      "source_url": "https://www.fbi.gov/investigate/cyber",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1021.001",
      "evidence_excerpt": "The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers.",
      "evidence_locator": "House Homeland Security Committee Testimony",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Congressional Hearing Transcript",
      "source_url": "https://homeland.house.gov/hearing/cyber-threats-in-the-pipeline-lessons-from-the-colonial-pipeline-attack/",
      "technique_name": "Remote Desktop Protocol",
      "tactic": "Lateral Movement"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2021-05-11",
      "description": "CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics."
    },
    {
      "event_type": "court_order",
      "event_date": "2021-06-07",
      "description": "DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline."
    }
  ]
}