Critical severity Famous Malware

DarkSide / Colonial Pipeline

The 2021 ransomware attack that shut 5,500 miles of US fuel pipeline for six days.

Overview

A single compromised password without multi-factor authentication on a legacy VPN account gave DarkSide access.\nThe operators encrypted nothing on the pipeline itself, yet Colonial shut it down because they could not bill or meter deliveries.\nThe outage triggered fuel hoarding across the south-eastern United States and pushed ransomware into national policy.\nMFA on every remote-access path is the lesson that stuck.

Indicators of Compromise

Signals that suggest this is present on a system.

  • VPN accounts without MFA
  • Legacy remote-access gateways exposed
  • Large data staged for exfiltration before encryption

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used