- Start
- May 7, 202190% CONFIDENCEfrom the source
Colonial Pipeline Shuts Down After a Ransomware Attack
- The pipeline runs from Houston to the Southeastern United States and was stopped in full to contain the attack, rather than because the operational systems themselves were encrypted. [S]
- The FBI oversaw the response; the ransom was paid and part of it was later recovered. [S]
- It became the reference case for ransomware as a physical-supply problem rather than an IT one, and CISA published DarkSide guidance for operators days later.
References 290% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]90%en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attacken.wikipedia.org· Posted Sep 21, 2026· Starts May 7, 2021 ✓· 50% of score
The day is not disputed: "On May 7, 2021, Colonial Pipeline ... suffered a ransomware cyberattack" and operations were halted the same day.
- [2]90%DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attackscisa.gov· Added Sep 21, 2026· 50% of score
CISA's advisory, issued in response to this attack, identifies the ransomware family and what operators were told to do about it.
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.