On May 7, 2021, Colonial Pipeline discovered a ransomware attack on its IT systems and proactively shut down its 5,500-mile fuel pipeline from Texas to New Jersey. The company paid a ransom of 75 Bitcoin to the DarkSide ransomware group. At the time of the transaction, that sum was worth roughly $4.4 million based on the prevailing exchange rate tracked by CoinDesk. The U.S. Department of Justice recovered approximately $2.3 million of that payment on June 7, 2021, a figure the FBI arrived at by valuing the seized coins at the day's market price. The pipeline resumed normal operations after a six-day shutdown. DarkSide dismantled its infrastructure shortly after the attack. The incident triggered a U.S. executive order on cybersecurity and new mandatory reporting requirements for critical infrastructure operators.
The timeline below covers the operational impact on fuel supplies across the Southeastern United States, the federal emergency response, the ransom payment and partial recovery, the Congressional testimony of Colonial's CEO, and the collapse of the DarkSide group.

The Attack and Immediate Shutdown
Colonial Pipeline discovered the ransomware infection on May 7, 2021. The company chose to shut down pipeline operations the same day, a decision that stopped the flow of gasoline, diesel, and jet fuel along the 5,500-mile corridor that supplies roughly 45 percent of the fuel consumed on the U.S. East Coast. The intruder was DarkSide, a ransomware-as-a-service group that recruited affiliates to deploy its malware in exchange for a cut of the ransom. DarkSide publicly claimed it was apolitical and motivated only by profit.
Why Colonial Shut Down the Pipeline
Colonial stated that it shut down the pipeline proactively to prevent the ransomware from spreading from its IT systems into the operational technology that controls the physical pipeline. The decision was not forced by a direct loss of control over the pipeline's valves and pumps, but by the risk that the malware could migrate to those systems. The company later confirmed that the ransomware had encrypted data on its business network but had not affected the pipeline's operational controls.
Fuel Shortages and Federal Emergency Response
The shutdown caused immediate fuel shortages across the Southeastern United States. Panic buying emptied gas stations in Georgia, North Carolina, Virginia, and Florida. The average U.S. gasoline price rose above $3 per gallon for the first time since 2014, according to AAA's daily fuel gauge, driven partly by the disruption. The federal government issued a regional emergency declaration on May 9, 2021, waiving restrictions on fuel transport by truck and allowing drivers to work extended hours to move fuel from refineries to stations.
The emergency declaration also authorized Jones Act waivers to permit foreign-flagged vessels to carry fuel between U.S. ports. The federal response was coordinated by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Energy. The pipeline restarted operations on May 12, 2021, but normal supply levels took several more days to stabilize.
The Ransom Payment and Partial Recovery
Colonial Pipeline paid the ransom of 75 Bitcoin on May 8, 2021, one day after the attack was discovered. CEO Joseph Blount later testified that the company paid because executives did not know how badly the systems were damaged or how long the recovery would take. The transaction was made in Bitcoin to a wallet controlled by DarkSide. At the time of the payment, the cryptocurrency's spot price on major exchanges put the value at roughly $4.4 million.
On June 7, 2021, the U.S. Department of Justice announced that the FBI had seized 63.7 Bitcoin of the ransom. The FBI valued the recovered coins at about $2.3 million based on the market price that day. The recovery was accomplished by gaining access to the private key of the Bitcoin wallet that DarkSide had used to receive the payment. The FBI did not disclose the specific method used to obtain the key, but the seizure represented the first time the DOJ had recovered a significant portion of a ransomware payment through cryptographic access rather than tracking financial transactions.
CEO Congressional Testimony
Colonial Pipeline CEO Joseph Blount testified before the U.S. Senate Committee on Homeland Security and Governmental Affairs on June 8, 2021, one day after the DOJ announced the ransom recovery. Blount defended the decision to pay, stating that the company had no guarantee that decryption would work and that restoring operations from backups would have taken longer. He also acknowledged that Colonial had not followed its own cybersecurity protocols and that the attack succeeded through a single compromised password on a legacy VPN account that was not protected by multi-factor authentication.
The testimony sparked policy debates about whether ransom payments should be banned or regulated for critical infrastructure operators. Some lawmakers argued that paying ransoms incentivized further attacks. Others noted that a ban could leave companies with no option if their backups failed. The hearing did not produce immediate legislation, but it contributed to the broader push for mandatory ransomware reporting requirements that were later included in the 2022 Cyber Incident Reporting for Critical Infrastructure Act.

The Collapse of DarkSide
DarkSide went offline shortly after the Colonial Pipeline attack. The group's infrastructure was disrupted, and the group announced it was shutting down. The precise cause of the collapse is not publicly confirmed, but multiple factors contributed. Law enforcement actions, including the FBI's seizure of servers and cryptocurrency wallets, degraded the group's operational capacity. The loss of affiliate trust also played a role: after DarkSide failed to deliver on its promise to avoid attacking critical infrastructure, affiliates worried that their own operations could be exposed. The group's public statement after the attack claimed it wanted to avoid political consequences.
DarkSide had operated as a ransomware-as-a-service model, in which core developers created the malware and infrastructure while affiliates conducted the actual intrusions and shared the ransom proceeds. The group's infrastructure included a data leak site where it published stolen data from victims who refused to pay. After the Colonial attack, that site went dark. Some former DarkSide affiliates are believed to have moved to other ransomware groups, including the now-defunct BlackMatter and the still-active ALPHV (BlackCat) group.
Policy and Regulatory Aftermath
The Colonial Pipeline attack was a direct catalyst for the Biden administration's Executive Order on Improving the Nation's Cybersecurity, issued on May 12, 2021, the same day the pipeline restarted. The executive order mandated federal agencies to adopt zero-trust architecture, required software vendors to report security incidents, and established a Cyber Safety Review Board. It also directed the National Institute of Standards and Technology (NIST) to develop standards for software supply chain security.
The attack also led to mandatory reporting requirements for critical infrastructure operators. The Transportation Security Administration (TSA) issued two security directives in 2021 that required pipeline operators to report cyber incidents to CISA, designate a cybersecurity coordinator, and conduct vulnerability assessments. The directives were later expanded to cover other modes of transportation. As of June 2024, the reporting requirements remain in effect, and the broader push for comprehensive federal cyber incident reporting legislation has continued through the 2022 Cyber Incident Reporting for Critical Infrastructure Act, which requires covered entities to report ransomware payments within 24 hours.
Key Facts
- Attack discovered: May 7, 2021
- Pipeline length: 5,500 miles (Texas to New Jersey)
- Ransomware group: DarkSide (ransomware-as-a-service)
- Ransom paid: 75 Bitcoin (approx. $4.4 million at the time of payment, per exchange spot prices)
- Ransom recovered by DOJ: 63.7 Bitcoin (approx. $2.3 million on June 7, 2021, per FBI valuation)
- Pipeline restarted: May 12, 2021
- Federal emergency declaration: May 9, 2021
- CEO testified: Joseph Blount, June 8, 2021
- DarkSide outcome: Infrastructure dismantled, group disbanded shortly after attack
Timeline of Key Events
| Date | Event |
|---|---|
| May 7, 2021 | Colonial Pipeline discovers ransomware attack and shuts down pipeline. |
| May 8, 2021 | Colonial pays 75 Bitcoin ransom to DarkSide. |
| May 9, 2021 | Federal government issues regional emergency declaration. |
| May 12, 2021 | Pipeline restarts operations; Biden cybersecurity executive order signed. |
| June 7, 2021 | DOJ announces recovery of 63.7 Bitcoin of the ransom. |
| June 8, 2021 | CEO Joseph Blount testifies before Senate committee. |
Frequently Asked Questions
How did the FBI recover the ransom payment?
The FBI obtained the private key to the Bitcoin wallet that DarkSide used to receive the ransom. This allowed the bureau to transfer the funds to a government-controlled wallet. The exact method used to acquire the key has not been publicly disclosed.
Did Colonial Pipeline pay the ransom in full?
Yes. Colonial paid 75 Bitcoin, valued at approximately $4.4 million at the time. The DOJ later recovered 63.7 Bitcoin of that amount, worth about $2.3 million at the time of seizure. It is not publicly known whether any additional funds were recovered after June 2021.
Was the pipeline ever under the attackers' control?
No. The ransomware encrypted data on Colonial's IT network, not on the operational technology that controls the physical pipeline. Colonial shut down the pipeline proactively to prevent the malware from spreading to operational systems.
What happened to the DarkSide ransomware group?
DarkSide disbanded its infrastructure and went offline shortly after the Colonial attack. The group's collapse was driven by law enforcement actions and loss of trust among its affiliates. Some affiliates are believed to have joined other ransomware groups.




