Domain Systems
Back to Insights
Article
November 28, 2025

When Ransomware Shut Down the East Coast Gas Supply: Personal Experience

S
By Sudon't • 10 min read
Oil & Gas

A firsthand account of the Colonial Pipeline Ransomware attack.

When Ransomware Shut Down the East Coast Gas Supply: My Personal Experience with the Colonial Pipeline Attack

In May 2021, I lived in Northern Virginia and commuted an hour and a half each way into D.C. We were still reeling from COVID-19 restrictions, all mission-essential personnel with absolutely no work from home option, then this happened. Like a lot of people in the DMV, I watched in disbelief as gas stations ran dry overnight. Pumps were bagged, lines stretched for blocks, and prices spiked; none of it mattered when there was literally nothing to buy. Several of my coworkers couldn’t get to the office at all—their tanks were on E and there was no fuel anywhere. Leadership demanded carpooling and all others prayed the car we piled into would be the one to get us home. On the tail of a global pandemic, it felt like the closest I’ve ever come to living through a disaster movie, except the villain wasn’t a hurricane or a blackout. It was a ransomware attack on Colonial Pipeline.

What Actually Happened

Colonial Pipeline operates the largest refined-products pipeline in the United States, moving roughly 2.5 million barrels a day of gasoline, diesel, and jet fuel along 5,500 miles from the Gulf Coast to the New York harbor area. On May 7, 2021, the company discovered that its corporate IT network had been hit by DarkSide, a ransomware group operating out of Eastern Europe.1

The attackers had gained access through a compromised VPN account that, according to later reports, did not have multi-factor authentication enabled. Once inside the billing and business systems, they exfiltrated nearly 100 gigabytes of data and then deployed ransomware that encrypted large parts of the corporate network.

Importantly, the operational technology (OT) network—the industrial control systems that actually move fuel through the pipeline—was not directly compromised. However, because the IT and OT environments were not sufficiently isolated, Colonial made the conservative decision to shut down pipeline operations entirely while it assessed the scope of the breach. That single precautionary step halted 45% of the East Coast’s fuel supply for nearly six days.

Timeline of Events

Colonial Pipeline Ransomware TimelineColonial Pipeline Ransomware Timeline

The Real-World Impact

By the time the pipeline restarted, terminals in the Southeast were effectively empty. Trucking couldn’t make up the shortfall fast enough, and the ripple effects lasted almost two weeks in some areas. Average gasoline prices jumped more than 20 cents a gallon in a matter of days—the largest weekly spike in years.

A Preventable Bridge Between Networks

The fundamental vulnerability here was architectural: the attack started in Colonial's corporate IT network, but the lack of proper isolation allowed it to impact physical operations. This exemplifies what security professionals call the "IT/OT convergence" challenge; enterprise networks require internet connectivity for business operations, while industrial control systems must remain isolated from those same threats to ensure operational safety and reliability.

This is where hardware-enforced solutions like data diodes and cross-domain solutions (CDS) become relevant. A data diode is a physical, one-way data transfer device. Information can flow out of the OT network for monitoring and logging, but nothing, can flow back in. A properly implemented cross-domain solution adds policy-enforced filtering on top of that unidirectional gateway.

Had Colonial Pipeline used a true data diode or certified CDS to separate its business systems from the industrial control network, the ransomware would almost certainly have been contained to the IT side. Pipeline operations could have continued safely while the company restored its corporate systems from backups.

These aren’t theoretical tools. They’re deployed today in nuclear facilities, power grids, defense networks, and increasingly in oil & gas and water utilities precisely because they eliminate the lateral movement path that turned a serious IT breach into a national fuel crisis.

Lessons Four Years Later

The Colonial Pipeline attack forced a wave of new federal cybersecurity requirements for pipeline operators and highlighted how quickly a digital incident can become a physical one. It also reminded those of us who lived through the empty pumps that critical infrastructure isn’t just “someone else’s problem.”

At Domain Systems, we specialize in helping organizations design and implement data diodes and cross-domain solutions that keep essential operations running even when the enterprise network is under attack. The goal is practical isolation: when ransomware hits the enterprise side, it should not reach the control room.

(And yes, I still fill up my tank every time it hits half—just in case.)

References

Footnotes

  1. Colonial Pipeline confirms it paid $4.4M ransom to hackers - AP, May 19, 2021 ↩