Colonial Pipeline: How One Password Disrupted America’s Fuel Supply
In 2021, ransomware stopped the largest fuel pipeline on the US East Coast. The input was one password without MFA. The story of an attack that showed the fragility of infrastructure.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 4 July 2026
- READING TIME
- 13 min read
- TOPIC
- History
In May 2021, there were kilometers of queues at gas stations on the east coast of the United States, and “out of fuel” signs were hanging in front of the pumps. People panicked and filled canisters and even plastic bags. Prices skyrocketed and a state of emergency was declared. It was like the oil crisis of the 1970s — and it wasn’t because of a war or an embargo. The cause was ransomware. Or more precisely: one password, for an account that did not have two-factor authentication enabled. The story of the Colonial Pipeline is the purest lesson possible in how digital neglect translates directly into the physical world — and how fragile the infrastructure that underlies our daily lives is.
Pipeline that feeds the coast
Colonial Pipeline is not an anonymous company. It operates the largest fuel pipeline serving the U.S. East Coast - an artery that carries about half of the entire region’s gasoline, diesel and jet fuel. When it stops, the supply stops for millions of people, airports and businesses. This is critical infrastructure in its purest form.
And this company fell victim to a ransomware attack carried out by a criminal group operating in the ransomware-as-a-service model - i.e. “ransomware for rent”, where the creators of the malware make it available to “partners” and share the profits on a percentage basis. This is the industrialization of crime, which we write about in ransomware: how to defend yourself.
Input: one password without the second component
What’s most sobering is the simplicity of the entrance. The attackers didn’t use a brilliant exploit or a sophisticated zero-day chain. They accessed the Colonial network through a remote access (VPN) account, using a compromised password - presumably one that had previously been leaked elsewhere and reused here.
Key detail: This account was not protected by multi-factor authentication (MFA). If there was, the password alone would not be enough to enter. One missing, low-cost mechanism – the second login component – stood between security and one of the most serious infrastructure incidents of the decade. This is the best possible argument for implementing MFA and, ultimately, phishing-resistant authentication.
Why did the entire pipeline stop?
There is an important nuance to the story here that often gets lost. Ransomware attacked Colonial’s IT systems - administrative, billing and business. There is no clear evidence that the attackers took over the control systems of the fuel flow itself (OT/ICS world).
So why did the pipeline stop? Because Colonial stopped it itself - proactively, out of caution. Since the IT network was compromised and the boundary between IT and control systems was unclear, the company preferred to disable the flow rather than risk the attack spreading to the physical infrastructure or missing the systems needed to deliver fuel safely and accountable. This shows how intertwined IT and OT systems are today - and how an attack on a “standard” office network can stop a machine in the physical world, even without taking it over directly.
Ransom, panic and recovered bitcoins
Under pressure, Colonial paid a ransom - the equivalent of several million dollars in Bitcoin - to regain access more quickly. Interestingly, the decryption tool provided by the attackers was so slow that the company largely rebuilt itself from its own copies anyway - classic proof that paying the ransom is not a magic solution.
However, the story has an unusual epilogue: US authorities later managed to recover a significant part of the paid ransom by tracing the cryptocurrency flow. It was a rare case showing that bitcoin is not as anonymous as criminals may believe - and gave defenders an unusual reason for satisfaction.
Meanwhile, panic spread in the physical world. The multi-day shutdown, amplified by panic buying, caused real fuel shortages across a large area and led authorities to declare a state of emergency. A digital attack translated into queues, empty stations and price increases that millions of people could feel directly.
Why the Colonial Pipeline is a period lesson
- MFA is not a luxury, it is a necessity. The entire disaster hinged on the lack of the second component in one account. No single inspection provides a better protection-to-cost ratio.
- IT and OT are intertwined. An attack on an office network can bring physical infrastructure to a standstill, whether through direct takeover or precautionary shutdown. Segmentation and a clear IT/OT boundary are critical.
- Ransomware is an industrialized crime. The ransomware-for-hire model has made attacks on critical infrastructure a repeat business, not a feat. It’s the same logic as NotPetya, but here the motive was purely financial.
- Paying the ransom does not save you. The decryption tool is sometimes unreliable, and paying the ransom funds further attacks. The real lifesaver is having backups and a plan in place.
Lessons for companies
- Enable MFA everywhere - especially on remote access. Every VPN account, admin panel and external access must have a second component. This is the first thing to check today.
- Do not reuse passwords. A leak from one site cannot open your network. Password manager and unique passwords plus MFA close this door.
- Segment IT from OT. If you manage physical infrastructure, the hard boundary between the office network and control systems determines whether an IT incident brings machines to a standstill.
- Have offline copies and a rebuild plan. Ransom-free recovery - 3-2-1 strategy - is the difference between days of downtime and weeks.
- Practice incident response. Colonial made exclusion and payment decisions under enormous pressure. Prepared plan reduces chaos when the fuel of millions is at stake.
Summary
Colonial Pipeline is the purest lesson in how digital neglect turns into a physical crisis. The largest fuel pipeline on the US East Coast stopped not because of a brilliant attack, but because of one compromised password for an account without MFA - and the company itself turned off the flow because the boundary between its IT systems and physical infrastructure was not sufficiently secure. The result was queues, empty stations, panic and a state of emergency. It’s a story that brings together the most important truths of modern security: MFA is mandatory, IT and OT are inextricably entwined, ransomware is an industrialized crime, and paying the ransom is not a solution. If you’re looking for one reason to enable two-factor login on every remote access account, this is it.
Want to test whether your remote access and IT/OT perimeter could withstand an attack that started with a single password? Contact us - audits and penetration tests show these exact paths.
Frequently asked questions (FAQ)
How did the attackers get to the Colonial Pipeline? Through a remote access (VPN) account, using a compromised password - likely one that was previously leaked and reused. This account did not have multi-factor authentication (MFA) enabled, so the password alone was enough to gain entry. If MFA had been active, the attack would most likely have failed.
Have hackers taken control of fuel flow? There is no clear evidence that they took over the pipeline control systems - the attack affected the IT network (administration, billing). The pipeline stopped because Colonial itself stopped it out of caution, fearing that the attack could spread to physical systems or that it wouldn’t have the tools to deliver the fuel safely. This shows how entangled IT and OT are today.
Did paying the ransom solve the problem? Not fully. Colonial paid several million dollars in bitcoin, but the decryption tool provided was so slow that the company largely rebuilt from its own backups anyway. This is typical: paying the ransom does not guarantee quick data recovery and finances further attacks. Interestingly, the services later recovered a significant portion of the ransom by tracing the cryptocurrency.
What is the most important lesson from Colonial Pipeline? That MFA on remote access is an absolute necessity - the entire incident hinged on its lack on one account. In addition, there are: no re-use of passwords, hard segmentation of IT from OT, offline backups enabling recovery without paying ransom, and a well-practiced incident response plan. These are simple, cheap measures that would prevent a crisis on a half-coast scale.


