Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA
Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.
On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a ransomware attack on its IT systems. The shutdown lasted several days, leading to fuel shortages and panic buying in several states.
How it happened
Colonial's CEO told the US Senate that attackers had entered through a legacy VPN account that was no longer in use but still active. The account was protected only by a password — not multi-factor authentication — and the password was later found among leaked credentials. The ransomware group DarkSide then deployed ransomware on IT systems. Colonial shut down pipeline operations as a precaution because it could not be sure operational systems were safe and could not bill customers normally.
Ransom and recovery
Colonial paid about $4.4 million in bitcoin. The US Department of Justice later recovered a substantial portion of it. The incident prompted new pipeline security directives from the Transportation Security Administration.
Why it mattered
Colonial became the defining example of ransomware's impact on critical infrastructure. It also showed how basic the entry point can be: a single forgotten account without MFA.
Lessons in hindsight
- Remove unused accounts. Dormant accounts are invisible to their owners but visible to attackers.
- MFA on every remote access path — VPN, RDP gateways, Citrix and SaaS.
- IT compromise can stop operations, even when operational systems aren't directly hit.
- Separate IT and operational technology and plan for running operations when IT is down.
In hindsight
The 2024 Change Healthcare attack followed almost the same script: a remote access portal without MFA, followed by ransomware and massive disruption. The lesson hasn't been fully learned.
- How to Find Remote Access Accounts That Bypass MFA How-To & Hardening
- Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything CIO Briefings