HomeSecurityColonial Pipeline: Ransomware attack hits largest US fuel pipeline

Colonial Pipeline: Ransomware attack hits largest US fuel pipeline

Colonial Pipeline, the operator of the largest fuel pipeline in the United States, has been forced to shut down after reportedly being attacked by ransomware. Colonial Pipeline transports 2.5 million barrels of gasoline and other fuels daily from refineries on the US Gulf Coast to customers in the eastern and southern US states, while also serving some of the largest airports in the US, including Atlanta's Hartsfield Jackson Airport, which is considered the busiest airport in the world.

According to CNBC, Colonial Pipeline was hit by a ransomware attack on May 7 , forcing it to shut down its entire network to prevent the malware from spreading. This event has raised concerns about a potential increase in commercial gasoline prices.

Read also: Cuba ransomware collaborates with Hancitor malware for spam attacks

Colonial Pipeline: Ransomware attack hits largest US fuel pipeline
Colonial Pipeline: Ransomware attack hits largest US fuel pipeline

On May 8, Colonial Pipeline issued a statement confirming the security incident and stating that it had temporarily suspended operations of its pipeline as it attempted to mitigate and respond to the attack. Specifically, the company stated the following in its statement:

“On May 7, Colonial Pipeline discovered that it had been the victim of a cyberattack. In an effort to respond, we proactively took certain systems offline to mitigate the threat, which temporarily disrupted all pipeline operations and impacted some of our IT systems. Upon learning of the incident, a leading cybersecurity firm decided to assist in the investigation and has already begun an investigation into the nature and scope of the incident, which is ongoing.”

A US official told the Washington Post that the DarkSide ransomware gang is believed to be behind the attack. The DarkSide ransomware “operation” began operating in mid-August 2020.

Ransomware attack
Colonial Pipeline: Ransomware attack hits largest US fuel pipeline

See also: DarkSide: New ransomware earns millions of dollars

Like other ransomware gangs targeting businesses, once DarkSide gains access to a corporate network, it silently spreads to other devices, while also harvesting credentials and stealing unencrypted files and documents. Additionally, once it gains access to Windows domain credentials, it deploys the ransomware across the network to encrypt devices.

Suggestion: Well-known car rental company victim of DarkSide ransomware

Colonial Pipeline Ransomware attack
Colonial Pipeline: Ransomware attack hits largest US fuel pipeline

If the DarkSide gang is indeed behind this attack, the malicious actors likely stole data, which they will later use to blackmail Colonial Pipeline into paying a ransom.

Among the high-profile attacks carried out by the DarkSide gang in the past are those that hit CompuCom, Discount Car and Truck Rentals, Brookfield Residential, and Companhia Paranaense de Energia (Copel) of Brazil.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS