Retrospective
Colonial Pipeline: what ransomware taught operational technology
The May 2021 shutdown of a major US fuel pipeline exposed how brittle the line between IT and OT security had become.
Marcus Whitfield
Senior Editor, American Computer Society
May 2021 · 6 min read

On 7 May 2021 a ransomware attack forced Colonial Pipeline to halt fuel deliveries across the southeastern United States, triggering panic buying and a $4.4 million ransom payment. The incident remains one of the clearest illustrations of why critical infrastructure security demands specific professional discipline.
A single credential, a national shortage
On 7 May 2021 Colonial Pipeline Company discovered that ransomware operated by the DarkSide group had infiltrated its billing systems. Out of caution the company halted the entire 5,500-mile pipeline that carries roughly 45 percent of the fuel consumed on the US East Coast. The shutdown lasted several days and produced fuel shortages, long queues at filling stations and states of emergency in several states.
The intrusion reportedly began with a single compromised password for a virtual private network account that lacked multi-factor authentication, tied to a legacy system that was not actively in use but had not been decommissioned. Colonial's chief executive, Joseph Blount, later told Congress the company authorised payment of a $4.4 million ransom, of which the Department of Justice subsequently recovered roughly $2.3 million in bitcoin.
“A corporate IT incident produced a physical, national-scale disruption — and the pipeline itself was never actually compromised.”
IT breach, OT consequence
Colonial's operational technology, the systems that physically control pumps and valves, was not itself compromised. The pipeline was shut down as a precaution because the company could not be confident the ransomware would not spread from its corporate IT network into the systems used for billing customers by volume, which are themselves intertwined with operational metering. That distinction mattered less to the public than the outcome: a corporate IT incident produced a physical, national-scale disruption.
The episode accelerated federal action. The Transportation Security Administration issued its first cybersecurity directives for pipeline operators within weeks, mandating incident reporting to CISA and, later, more prescriptive requirements for network segmentation and contingency planning — obligations that a decade of voluntary guidance had failed to produce.
The persistent IT/OT divide
Colonial Pipeline was not an outlier. Surveys of utilities and industrial operators conducted in the aftermath consistently found that many organisations still lacked network segmentation between corporate IT and industrial control systems, still permitted single-factor remote access, and still had incomplete asset inventories of their OT environments.
- Segment IT and OT networks and treat any bridging system as high-risk.
- Enforce multi-factor authentication on all remote access, with no legacy exceptions.
- Maintain a current inventory of OT assets and their exposure.
- Rehearse manual fallback operating procedures, not only IT recovery.
What the Society advises
The Society urges practitioners working across critical infrastructure to treat OT security as a distinct discipline requiring its own competence, not an extension of enterprise IT practice. Engineers should decommission unused access paths as rigorously as they patch known vulnerabilities, and organisations should ensure that professionals with authority over industrial systems hold current, verifiable credentials.
The Society continues to recommend mandatory incident disclosure for critical infrastructure operators, continuing professional development in industrial control system security, and clear lines of accountability between corporate leadership and the engineers responsible for physical safety systems.
Join the professional body behind this work
ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.
Become a memberMore from ACS Insights
Optimus: a humanoid robot from prototype to production line
Four years from an AI Day slide to a converted Fremont assembly line — and still no commercial sale.
AnalysisGrok, Colossus and the compute arms race
xAI built a 100,000-GPU cluster in 122 days, doubled it, and merged twice. The externalities arrived with the electricity.
ArticleA national consortium to build trust in AI
ACS joins federal partners, universities and industry to strengthen assurance practice for high-impact AI systems.