---
title: "Cybersecurity Scary Stories: Colonial Pipeline - EMPIST®"
description: When hackers strike, we should all be scared. Gather ‘round the campfire, let us tell you the harrowing tale of the Colonial Pipeline Attack.
image: https://hs.empist.com/hubfs/Imported_Blog_Media/What-Business-Owners-Need-to-Know-V2-1.jpg
---

[Skip to main content](https://hs.empist.com/blog/cybersecurity-scary-stories-colonial-pipeline#main-content)

[![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png)](https://hs.empist.com/home)

- [Show submenu for IT Services IT Services](https://hs.empist.com/it-services/) 
    - [Managed IT Services](https://hs.empist.com/it-managed-services)
    - [Co-Managed IT](https://hs.empist.com/co-managed-it)
- [Cybersecurity Services](https://hs.empist.com/cybersecurity)
- [Cloud Services](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- [Show submenu for Why EMPIST Why EMPIST](https://empist.com/about-us/) 
    - [Blog](https://hs.empist.com/blog)
- [Show submenu for Support Support](https://empist360.com) 
    - [Status](https://status.empist.com)

Open main navigation

Close main navigation

- Show submenu for IT Services  IT Services 
  
    - IT Services
    - [IT Services](https://hs.empist.com/it-services/)
    - [Managed IT Services](https://hs.empist.com/it-managed-services)
    - [Co-Managed IT](https://hs.empist.com/co-managed-it)
- [Cybersecurity Services](https://hs.empist.com/cybersecurity)
- [Cloud Services](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- Show submenu for Why EMPIST  Why EMPIST 
  
    - Why EMPIST
    - [Why EMPIST](https://empist.com/about-us/)
    - [Blog](https://hs.empist.com/blog)
- Show submenu for Support  Support 
  
    - Support
    - [Support](https://empist360.com)
    - [Status](https://status.empist.com)
- [Under Attack?](https://empist.com/under-attack/)
  
  [Call Now](tel:+13123601900)

[Under Attack?](https://empist.com/under-attack/)

[Call Now](tel:+13123601900)

[Blog](https://hs.empist.com/blog)

Tags

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)
- [Business](https://hs.empist.com/blog/tag/business)
- [Business Intelligence](https://hs.empist.com/blog/tag/business-intelligence)

Search

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)
- [Business](https://hs.empist.com/blog/tag/business)
- [Business Intelligence](https://hs.empist.com/blog/tag/business-intelligence)

When hackers strike, we should all be scared. 

Gather ‘round the campfire, let us tell you the harrowing tale of the Colonial Pipeline Attack: 

Founded in 1961, The Colonial Pipeline Company is the largest refined products pipeline in the United States. Running from New York Harbor to Houston, it delivers over 100 million gallons of fuel to the East Coast of the country each and every day – [that’s nearly 45% of the total gas supply for the region.](https://www.nytimes.com/2021/05/08/us/politics/cyberattack-colonial-pipeline.html)  

Needless to say, the functionality of this mighty piece of infrastructure is fundamental to the daily lives of millions; So, when officials discovered that Colonial Pipeline had been hit with a debilitating cyberattack this past spring, you can understand that the response was nothing short of horror. 

The mighty had fallen.   

On May 7th, 2021, Colonial Pipeline [announced](https://www.reuters.com/technology/colonial-pipeline-halts-all-pipeline-operations-after-cybersecurity-attack-2021-05-08/) the immediate halt of all operations in the wake of a cybersecurity breach. The shutdown caused gas shortages, price spikes, and considerable consumer alarm up and down the East Coast for days on end. This reaction, of course, is understandable – with no immediate resolution in sight, [Americans began fearfully stockpiling gas](https://www.usatoday.com/story/news/factcheck/2021/05/12/fact-check-yes-viral-photo-shows-gas-hoarding-alabama/5060046001/), officials called emergency meetings in anticipation of the worst – it was chaos.  

Luckily, in this case, the attacker’s target was *not *the infrastructure of the pipeline itself, but rather the business operations of the Colonial Pipeline Company. Once the threat was dealt with, regular service returned to consumers within a few days. But while the world awaited an answer from the FBI and others as to what *really* happened, many remained visibly shaken by how easily bad actors were able to decimate such a large enterprise. **If this could happen to Colonial Pipeline, couldn’t it happen to the water supply? The electricity? Couldn’t it happen to *****you*? **

Fears only mounted a month later when the alleged cause of the breach was finally revealed: **[one single leaked password.](https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08/) ** 

That’s right; One exposed password wreaked days-worth of havoc for the entire eastern seaboard of a global superpower. According to testimony from Colonial Pipeline CEO Joseph Blount during a U.S. Senate Committee hearing, [the inactive employee password was discovered by hacking group DarkSide on the dark web](https://www.washingtonpost.com/business/2021/06/08/colonial-pipeline-ceo-blount-congress/). Some speculate that the password was a repeat, meaning it had previously been used for another of the employee’s personal accounts.  

Once found, this password was then used to access the Colonial Pipeline network via a legacy VPN that did not have [multi-factor authentication enabled](https://empist.com/do-i-need-mfa-for-my-personal-accounts/). Worming in through this small point of entry, DarkSide was then able to encrypt a significant portion of Colonial Pipeline’s data with ransomware, essentially holding the company hostage to their demands. Panic ensued.  

And in that panic, Blount made a decision that the EMPIST team never recommends – he paid the ransom. Desperate to get the system back online, Colonial Pipeline paid DarkSide approximately [$4.3M in bitcoin](https://www.washingtonpost.com/business/2021/06/08/colonial-pipeline-ceo-blount-congress/) for the safe return of their data. While the U.S. government was eventually able to trace some of the bitcoin Colonial Pipeline used, to this day the full balance has never been recovered.  

News of the ransom payment left leaders shocked; As did the follow-up [statements](https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08/), in which Blount revealed that the Colonial Pipeline Company did not even have a proactive ransomware attack program, but rather just an emergency response protocol.  

Those who weren’tshocked in the slightest, however, were cybersecurity professionals. You see, cyber experts have been warning the general public for *years *about the gaping holes in much of our protective protocol. From business owners to government agencies, [no one is safe from ransomware](https://empist.com/do-i-need-to-worry-about-ransomware/) or other cybersecurity attacks.  

And while we’d love to end this story on a high note, there really isn’t one. Comprehensive, proactive security isn’t just the best measure we have to protect our data, it’s the *only *measure.  The threat of cyberattacks is very, very real; And if you aren’t scared yet, just wait – you will be.  

Ready to build out your own cybersecurity program? Contact team EMPIST [online today](https://empist.com/contact/) to get started!  

(Sources: [Bloomberg](https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline-using-compromised-password), [Vox,](https://www.vox.com/recode/22428774/ransomeware-pipeline-colonial-darkside-gas-prices) [Reuters,](https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08/)[New York Times,](https://www.nytimes.com/2021/05/08/us/politics/cyberattack-colonial-pipeline.html)[USA Today,](https://www.usatoday.com/story/news/factcheck/2021/05/12/fact-check-yes-viral-photo-shows-gas-hoarding-alabama/5060046001/)[The Washington Post)](https://www.washingtonpost.com/business/2021/06/08/colonial-pipeline-ceo-blount-congress/)

Tags:

[Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)

![EMPIST - Symbol](https://hs.empist.com/hs-fs/hubfs/EMPIST%20Branding/EMPIST%20-%20Symbol.png?width=96&height=106&name=EMPIST%20-%20Symbol.png)

### Got A Question?

Feel free to contact us with any questions about this post or anything else you may be interested in finding out.

###### Categories

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)

###### Recent Posts

- [What Every Business Needs to Know About Ransomware Protection](https://hs.empist.com/blog/what-every-business-needs-to-know-about-ransomware-protection)
- [How to Choose the Right IT Support Model for Your Business](https://hs.empist.com/blog/how-to-choose-the-right-it-support-model-for-your-business)
- [Hidden Risks of Shadow IT and How to Mitigate Them](https://hs.empist.com/blog/hidden-risks-of-shadow-it-and-how-to-mitigate-them)
- [What Small Business Owners Should Know About Network Security](https://hs.empist.com/blog/what-small-business-owners-should-know-about-network-security)
- [5 Ways Co-Managed IT Services Can Boost Your Team’s Efficiency](https://hs.empist.com/blog/5-ways-co-managed-it-services-can-boost-your-teams-efficiency)

## Related Articles

[![What Every Business Needs to Know About Ransomware Protection](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0703_WistiaBlogThumbnail.jpg?width=500&height=500&name=0703_WistiaBlogThumbnail.jpg) What Every Business Needs to Know About Ransomware Protection Marty Hitzeman • Jul 3, 2026, 4:00:01 AM](https://hs.empist.com/blog/what-every-business-needs-to-know-about-ransomware-protection)

[![What Small Business Owners Should Know About Network Security](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0612WistiaBlogThumbnail.jpg?width=500&height=500&name=0612WistiaBlogThumbnail.jpg) What Small Business Owners Should Know About Network Security Marty Hitzeman • Jun 12, 2026, 4:00:51 AM](https://hs.empist.com/blog/what-small-business-owners-should-know-about-network-security)

[![Healthcare IT: Risk Management and Compliance Tips](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0515WistiaBlogThumbnail.jpg?width=500&height=500&name=0515WistiaBlogThumbnail.jpg) Healthcare IT: Risk Management and Compliance Tips Marty Hitzeman • May 15, 2026, 4:00:05 AM](https://hs.empist.com/blog/healthcare-it-risk-management-and-compliance-tips)

[![Securing Hybrid Cloud Environments: Best Practices for SMBs](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0424_WistiaBlogThumbnail.jpg?width=500&height=500&name=0424_WistiaBlogThumbnail.jpg) Securing Hybrid Cloud Environments: Best Practices for SMBs Marty Hitzeman • Apr 24, 2026, 4:00:05 AM](https://hs.empist.com/blog/securing-hybrid-cloud-environments-best-practices-for-smbs)

[![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png)](https://empist.com)

- [MANAGED IT SERVICES](https://hs.empist.com/it-managed-services)
- [CYBERSECURITY](https://hs.empist.com/cybersecurity)
- [CLOUD SERVICES](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- [CO-MANGED IT](https://hs.empist.com/co-managed-it)
- [PROFESSIONAL IT SERVICES](https://empist.com/it-services/professional-it-services)
- [BUSINESS PROCESS IMPROVEMENT](https://empist.com/it-services/business-process-improvement)
- [DIGITAL SERVICES](https://empist.com/it-services/digital-services)
- [SUPPORT](https://empist360.com)

EMPIST, LLC 2026 Copyright. All rights reserved.  [Privacy policy](https://empist.com/privacy-policy/) | [Terms](https://empist.com/terms-conditions-us/)

- <https://www.facebook.com/empist/>
- <https://www.instagram.com/empistgroup/>
- <https://www.linkedin.com/company/empist/>
- <https://www.youtube.com/@EMPIST>
- <https://twitter.com/Empist>
- <http://tiktok.com/@empist>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Christina Tzouganatos",
    "url" : "https://hs.empist.com/blog/author/christina-tzouganatos"
  },
  "dateModified" : "2026-02-02T15:51:30.930Z",
  "datePublished" : "2021-09-20T09:29:08.000Z",
  "headline" : "Cybersecurity Scary Stories: Colonial Pipeline - EMPIST®",
  "image" : [ "https://hs.empist.com/hubfs/Imported_Blog_Media/What-Business-Owners-Need-to-Know-V2-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://hs.empist.com/blog/cybersecurity-scary-stories-colonial-pipeline",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://hs.empist.com/hubfs/Empist_logo_dark-1.png"
    },
    "name" : "EMPIST"
  }
}
```