Colonial Pipeline, 2021: one legacy VPN profile, no second factor.
Ransomware encrypted Colonial Pipeline's IT systems and the company shut down its entire pipeline as a precaution. Testimony to the US House Homeland Security Committee traced the entry to a VPN profile that was not meant to be in use.
Last updated Published by TryTrustableNot legal advice
On 7 May 2021 Colonial Pipeline found a ransom note on its IT network and shut down all 5,500 miles of its pipeline. Mandiant, which investigated, testified that the earliest evidence of compromise was on 29 April 2021, when the attacker logged into a VPN appliance using a legacy VPN profile and an employee's username and password; the profile did not require a one-time passcode. Colonial's CEO testified that the profile was not intended to be in use and that the company paid the ransom. Pipelines were returned to service from 12 May.
What happened
| Date | What happened |
|---|---|
| 29 April 2021 | Earliest evidence of compromise: the attacker logs into a VPN appliance with a legacy VPN profile and an employee's username and password (Mandiant testimony). |
| 7 May 2021, just before 5:00 EDT | An employee finds a ransom note on a system in the IT network (Blount testimony). |
| 7 May 2021, by 6:10 EDT | All 5,500 miles of pipeline are confirmed shut down. |
| 7 May 2021 | Colonial contacts the FBI and CISA within hours. |
| 12 May 2021, evening | Colonial begins returning all pipelines to service. |
| 27 May 2021 | DHS announces a TSA Security Directive with cybersecurity requirements for critical pipeline owners and operators. |
| 9 June 2021 | Colonial's CEO and Mandiant testify to the House Committee on Homeland Security. |
Root cause
The written testimony of Colonial's chief executive, Joseph Blount, states that the attacker "exploited a legacy virtual private network (VPN) profile that was not intended to be in use" (Blount testimony). At the time of the hearing the company was still working out how the attackers obtained the credentials.
Mandiant's testimony adds the technical detail (Carmakal testimony): the attacker used an employee's username and password, and the legacy VPN profile "did not require a one-time passcode". In other words, the account had no second factor. The profile has since been disabled.
Two control failures sit behind that sentence. The first is an access path that should have been removed and was not: a legacy profile still able to authenticate. The second is authentication by password alone on an internet-facing remote access service. Blount's testimony attributes the ransomware to the criminal group DarkSide and says the attack encrypted IT systems; the pipeline was shut down as a precaution while operational technology and other systems were checked.
Impact and regulatory outcome
- Operations: the whole 5,500-mile pipeline was shut down on 7 May and returned to service from the evening of 12 May. Blount describes panic-buying and shortages that followed the shutdown.
- Ransom: Blount testified that he decided Colonial would pay the ransom. This page does not state an amount, because the official source for it could not be read when this page was checked.
- Regulation: on 27 May 2021 DHS announced a TSA Security Directive requiring critical pipeline owners and operators to report cybersecurity incidents to CISA, name a 24/7 cybersecurity coordinator, and identify gaps and remediation measures for cyber-related risks, reporting them to TSA and CISA within 30 days. DHS cited "the recent ransomware attack on a major petroleum pipeline".
The controls that address it
| Control | SOC 2 criteria | ISO 27001:2022 Annex A |
|---|---|---|
| Multi-factor authentication on every remote access path | CC6.1, CC6.6 | A.8.5 |
| Access reviews that remove unused accounts, profiles and access paths | CC6.2, CC6.3 | A.5.18 |
| Joiner, mover and leaver process tied to the identity provider | CC6.2 | A.5.16, A.5.18 |
| Password policy and detection of compromised credentials | CC6.1 | A.5.17 |
| Backups and tested recovery for ransomware | A1.2, A1.3, CC7.5 | A.8.13, A.5.30 |
| Incident response plan, including regulator and law enforcement contact | CC7.3, CC7.4 | A.5.24, A.5.26 |
SOC 2 references are the 2017 Trust Services Criteria (points of focus revised 2022); Annex A references are ISO/IEC 27001:2022. These are the usual mappings: agree yours with your auditor.
How TryTrustable checks these controls
TryTrustable does not connect to VPN appliances. It checks MFA and account hygiene in the identity providers and clouds you connect, which is where most SaaS companies now anchor remote access:
- Okta: that an MFA policy is enforced, MFA enrolment across users, inactive users, deprovisioned users still holding access, password policy, session lifetime and the number of super admins.
- Google Workspace: that 2-Step Verification is enforced and how many users are enrolled, inactive and suspended users, password policy and super-admin count.
- AWS: every IAM user with console access has MFA, and the root account has MFA.
- GitHub: two-factor authentication required across the organisation.
- Recovery: AWS RDS automated backups; Cloud SQL automated backups and point-in-time recovery on GCP.
- Response: the incident management module tracks detection, containment and regulatory deadlines for each incident.
These are the checks TryTrustable runs today. None of them is a claim about what would have happened in this incident: they test whether the control is in place in your environment, continuously, and record the result as audit evidence.
Sources
- Testimony of Joseph Blount, CEO, Colonial Pipeline, House Committee on Homeland Security (9 June 2021)
- Prepared statement of Charles Carmakal, FireEye-Mandiant, House Committee on Homeland Security (9 June 2021)
- House Committee on Homeland Security hearing record: Cyber Threats in the Pipeline (9 June 2021)
- DHS: DHS announces new cybersecurity requirements for critical pipeline owners and operators (27 May 2021)
Every figure on this page is taken from the official documents listed here, read in October 2026. Regulatory findings quoted are the regulator's; where a company neither admitted nor denied them, or where proceedings are still open, the page says so. Not legal advice.
More case studies: all breach case studies · Research
The things people ask us
How did attackers get into Colonial Pipeline?
Through a legacy VPN profile that was not meant to be in use. Mandiant testified that the attacker logged in on 29 April 2021 with an employee's username and password, and that the profile did not require a one-time passcode.
Did Colonial Pipeline have multi-factor authentication?
Not on the account that was used. According to Mandiant's testimony, the legacy VPN profile did not require a one-time passcode, so a username and password were enough to log in.
Why did Colonial shut down the pipeline if only IT systems were encrypted?
As a precaution. Colonial's CEO testified that employees shut down all 5,500 miles of pipeline within about an hour of finding the ransom note, and restarted only after systems were checked.
What changed in regulation after the attack?
On 27 May 2021 DHS announced a TSA Security Directive requiring critical pipeline operators to report cybersecurity incidents to CISA, designate a cybersecurity coordinator and review their practices within 30 days.
Check these controls in your own environment.
We connect GitHub and one cloud account in a demo and show which of these checks pass, with the evidence an auditor would ask for.