Colonial Pipeline: What a Real Infrastructure Cyberattack Looked Like
"Can a cyberattack shut down American infrastructure" is a question with an actual answer, because it happened in May 2021 and the details are public. What the details show is considerably more useful — and stranger — than the version in the headlines.
What happened
Colonial Pipeline operates roughly 5,500 miles of pipeline carrying refined fuel from the Gulf Coast to the East Coast, supplying something on the order of 45% of the region's fuel.
On 7 May 2021, the company discovered ransomware on its systems, attributed to a criminal group called DarkSide. Colonial shut the pipeline down. Fuel stopped moving for about six days before operations resumed on 12 May.
Colonial paid a ransom of roughly $4.4 million. The Department of Justice later recovered about half of it.
That's the summary. Here's the part that matters.
The attackers never touched the pipeline
The ransomware hit Colonial's business systems — billing, invoicing, corporate IT. It did not compromise the operational technology that actually controls pumps and valves.
Colonial shut the pipeline down as a business decision, not because an attacker turned it off. Two reasons were cited: uncertainty about whether the intrusion could spread to operational systems, and the more prosaic problem that without billing systems the company could not track and invoice what it was delivering.
So the most consequential infrastructure cyberattack in recent American history worked by encrypting an accounting system, and the physical shutdown was a precaution taken by the victim.
That is not reassuring in the way it first sounds. It means the IT/OT boundary held — but it also means an attacker doesn't need to reach the control system to stop the flow. Encrypting the business that operates the infrastructure is sufficient.
The shortage was mostly panic
Six days of pipeline downtime should not have emptied thousands of filling stations. Fuel was in storage terminals, tanker trucks were running, and the physical supply had not disappeared.
What emptied the stations was people topping up. Reports of a fuel shortage produced a surge in demand that no distribution system is sized for — every vehicle in a region filling simultaneously is far more fuel movement than normal operations, regardless of what's in the pipeline. Stations ran dry because trucks couldn't restock fast enough against that demand, not because there was no fuel.
Some drivers filled plastic bags and improvised containers, prompting official warnings against it.
This is the most transferable lesson in the entire event: the shortage was demand-side. The infrastructure failure created the conditions, and the public response created the actual scarcity. The same pattern recurs in almost every supply disruption — toilet paper in 2020, bottled water before a hurricane, bread before a snowstorm.
The initial access
Reporting on the intrusion pointed to a single compromised password for a legacy VPN account that was no longer in active use but remained enabled, and which did not have multi-factor authentication. The password was reportedly found in a batch of leaked credentials, suggesting reuse.
Not a zero-day. Not a nation-state exploit chain. A disused account that was never turned off.
That's characteristic rather than exceptional. The large majority of successful intrusions against critical infrastructure operators involve credential compromise, unpatched known vulnerabilities, or exposed remote access — not novel attacks.
What this tells you about the threat generally
The realistic attack is disruption, not destruction. Ransomware operators want payment. Encrypting an operator's business systems and letting the operator shut itself down is easier, cheaper, and more reliable than manipulating industrial control systems.
The IT/OT boundary is the thing that matters, and in this case it worked. Operational technology remained intact. That boundary is where infrastructure security effort is concentrated, and the outcome here is a point in its favour.
Duration is bounded by the nature of the attack. Encrypted business data is recoverable — from backups, from decryption, from rebuilding. This is fundamentally different from physical destruction of equipment with multi-year lead times, which is why the large-transformer problem is a more serious tail risk than ransomware despite getting a fraction of the attention.
Public response amplifies everything. A six-day pipeline outage became a multi-week regional fuel disruption because of how people reacted to news of it.
What actually helps a household
The honest answer is that this scenario needs very little specialised preparation, and what it does need is boring.
Keep your tank above half. That single habit renders most regional fuel disruptions a non-event for you, costs nothing, and means you never join the queue that creates the shortage.
Store fuel properly if you store it at all. Approved containers, treated with stabiliser, rotated. Gasoline degrades in months without treatment. Never in improvised containers — the 2021 event produced genuinely dangerous behaviour on this point.
Have a few days of cash. Payment systems depend on the same networks, and a ransomware event at a payment processor or a regional bank produces a cash-only period.
Don't participate in the run. If you're already at half a tank you don't need to top up during a panic, and the people who don't participate are the reason the system recovers.
Nothing here requires a product. That's true of most cyberattack scenarios, which is why they're less marketed than the ones you can sell a Faraday bag against.
The short version
The most disruptive infrastructure cyberattack in recent memory reached an accounting system, never touched a valve, and produced a shortage that was mostly caused by drivers rather than by the attack.
The lesson isn't that infrastructure is invulnerable — a disused VPN account without MFA is not a reassuring entry point. The lesson is that the failure mode is a temporary interruption amplified by public reaction, and the single most effective preparation is to not need anything urgently at the moment everyone else does.
Related: What an EMP would actually do covers the physical-destruction scenario, where the recovery timeline is genuinely different. Texas 2021 covers what a real multi-day utility failure did to households.
Last reviewed: July 2026