Open cardosec

Case DF6227 · Famous breaches · L1 Foundations

Colonial Pipeline

Practise as: Explain it · Interview

Interview questionHow did a ransomware attack on IT systems end up stopping fuel delivery in 2021?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. May 2021, DarkSide affiliate got in via a legacy VPN account with a leaked password and no MFA
  2. Ransomware hit IT (billing) systems; Colonial proactively shut the OT pipeline for about 5 days
  3. Largest US East Coast fuel pipeline; panic buying and shortages across the southeast
  4. Paid about 75 BTC (~$4.4M); the DOJ later seized back 63.7 BTC
  5. Led to TSA pipeline security directives; lessons: MFA on remote access, IT/OT segmentation

If the interviewer pushes back

  • If OT was never encrypted, why shut the pipeline? Discuss billing dependency and blast-radius uncertainty.

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.