Why Did the Colonial Pipeline Ransomware Attack?

288 views
•
August 13, 2021
by
RSAC Cybersecurity
YouTube video player
Why Did the Colonial Pipeline Ransomware Attack?

TL;DR

Colonial Pipeline shut down because ransomware locked its IT network, creating uncertainty and preventing automated tracking and billing, even though the operational network was not directly targeted. The incident showed that critical operations can fail through indirect dependencies, and that tested restoration procedures, tabletop exercises, manual alternatives, and careful separation of IT and operational networks are essential.

Transcript

Next up we have Kim Zetter. Uh, Kim wrote what I would call the, one of the definitive books on, uh, industrial control system attacks with, uh, detailing what happened with Stuxnet. Uh, Kim, uh, are you on? Yes, I'm here. All right. So- Okay ... Colonial Pipeline just happened. Should we have seen this coming? Yeah, I mean, I think it, I think the... Read More

Key Insights

  • The Colonial Pipeline attack targeted the IT network rather than the operational network, but the resulting loss of visibility, tracking, and automated billing contributed to a shutdown with direct consequences for fuel distribution.
  • Ransomware attackers are primarily motivated by money and intentionally seek organizations capable of paying large demands. DarkSide said it avoided hospitals, nonprofits, and educational institutions because those targets did not offer the financial return it wanted.
  • Operational disruption can result from an attacker's actions even when industrial systems are neither targeted nor compromised. Connectivity and business dependencies can create cascading effects that attackers may not intend, understand, or care about.
  • Industrial control system risks had been visible for years before the Colonial Pipeline incident. Stuxnet brought targeted industrial attacks into public view in 2010, while earlier non-targeted cyber incidents had already disrupted or endangered operational environments.
  • The 2003 Slammer worm entered a nuclear power plant through a contractor's computer, crossed the corporate network, and reached systems linked to reactor process controls. Loss of monitoring capabilities required the facility to shut down under applicable regulations.
  • The Colonial Pipeline shutdown partly reflected uncertainty and a rapid defensive response after systems went dark on a Friday. A rehearsed incident strategy and tabletop exercises might have enabled a more deliberate response, including manual tracking and billing.
  • Backups are useful only when they contain the needed information and their restoration procedures have been tested. Recovery can be involved and convoluted, making untested backups far less helpful when responders are working under pressure.
  • Ransomware groups may disappear publicly without abandoning their business. Zetter expected DarkSide to go deeper underground, rebrand, change names, or possibly recode because ransomware remained too lucrative for permanent withdrawal.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why did Colonial Pipeline shut down after the ransomware attack?

Colonial Pipeline shut down after ransomware locked its IT network, even though the attackers did not directly target the operational network. The company faced uncertainty about what was happening and followed the common advice to disconnect systems. It also lost the automated ability to track which customers received fuel and bill them, making continued distribution difficult without a prepared manual process.

Q: Did ransomware directly compromise Colonial Pipeline's operational network?

The account presented here says the ransomware targeted Colonial Pipeline's IT network, not its operational network. Nevertheless, the attack disrupted operations because the company could no longer rely on business systems used to track deliveries and bill customers. The case illustrates that operational consequences can arise from dependencies on compromised IT services without attackers directly entering industrial control systems.

Q: What motivated the attackers behind the Colonial Pipeline incident?

The attackers were primarily motivated by money. They intentionally targeted an organization they believed could pay the ransom, rather than accidentally selecting Colonial Pipeline. DarkSide said it avoided hospitals, nonprofits, and educational institutions because those organizations were not where it expected to find the money it sought. The attackers apparently did not intend to cause the pipeline shutdown itself.

Q: Could Colonial Pipeline have continued distributing fuel manually?

Colonial Pipeline could potentially have continued distributing fuel while manually recording who received what and determining what each customer owed. However, that alternative would have required advance planning. Once the automated tracking and billing systems were unavailable, the company lacked a ready process for operating manually, so the locked IT network effectively forced the operational decision to stop distribution.

Q: Why was the Colonial Pipeline ransomware attack foreseeable?

The incident was foreseeable because attackers had shown interest in industrial control systems for a decade, and earlier events had exposed the risks of connected business and operational networks. Stuxnet became public information in 2010. The 2003 Slammer worm disrupted a nuclear power plant, while investigators of the 1999 Bellingham pipeline incident found porous connections between business and operational networks.

Q: Why did Colonial Pipeline pay the ransom despite having backups?

Colonial Pipeline reportedly had backups and restored its network from them, but backups may not contain every item needed from the business network. Restoration can also be involved and convoluted, especially if the recovery process has not been tested beforehand. The company may have paid to regain faster access to IT systems, although the attackers' decryption tool worked slowly and was not ultimately helpful.

Q: How does double extortion increase pressure on ransomware victims?

Double extortion combines file encryption with a threat to publish stolen business data. In the Colonial Pipeline incident, the attackers stole about 100 gigabytes. If stolen material includes sensitive business communications or security documents, a victim may consider paying not only to unlock systems but also to discourage disclosure, although Zetter did not think this was necessarily Colonial Pipeline's reason.

Q: Did DarkSide permanently stop its ransomware operations?

Zetter did not believe DarkSide's announcement that it was leaving ransomware meant the activity would permanently end. The group and the forums advertising its ransomware service had attracted unwanted attention, so a temporary retreat was plausible. She expected participants could move deeper underground, rebrand, change names, or possibly recode because the activity was too lucrative to abandon for good.

Summary & Key Takeaways

  • Ransomware attackers targeted Colonial Pipeline's IT network for money, not its industrial control systems. However, the company shut down the pipeline amid uncertainty and after losing automated tracking and billing capabilities. The disruption demonstrated how an attack on business systems can produce serious operational consequences without directly compromising operational technology.

  • Kim Zetter argues that the danger was foreseeable because industrial control systems had attracted attacker interest for a decade. Earlier incidents, including the 2003 Slammer worm infection at a nuclear power plant and the 1999 Bellingham pipeline incident, had already revealed the risks created by porous connections and operational dependencies.

  • Colonial Pipeline reportedly had backups and restored its network from them, but still paid the ransom. Possible reasons included incomplete backups, an untested or difficult restoration process, and a need to recover inaccessible business information. The attackers' slow decryption tool proved unhelpful, reinforcing the importance of tested recovery procedures.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚