• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Cybersecurity

Ransomware attackers see a big target in Big Energy

By
Katherine Dunn
Katherine Dunn
Down Arrow Button Icon
By
Katherine Dunn
Katherine Dunn
Down Arrow Button Icon
May 10, 2021, 11:46 AM ET

As the shutdown of Colonial Pipeline’s critical infrastructure stretches into a third day, oil and gas prices were shrugging off the prospect of a potential supply crunch. But it isn’t the risk of a gasoline shortage that is giving the industry the jitters.

For years, cybersecurity experts and the U.S. government have been warning the energy industry that it remains all too vulnerable to the kind of ransomware cyberattack that knocked Colonial offline over the weekend.

Those warnings, in fact, included an alert just last year—as the pandemic was spreading around the globe—about another, unnamed U.S. pipeline system affected by a ransomware attack. The U.S. Cybersecurity and Infrastructure Security Agency reported that a spear-phishing attack had gained access to the IT systems at a natural gas compression facility, unleashing ransomware internally that resulted in the company losing sight of some of its own systems. While it didn’t lose control of its operations, the company had to shut down its pipeline network for two days.

The alert highlighted warnings that the operator didn’t have in place a specific emergency plan to deal with cyberattacks and that it had gaps in its knowledge about how to manage them. The U.S. agency that investigated the attack said that it “encourages asset owner operators across all critical infrastructure sectors to review the…threat actor techniques and ensure the corresponding mitigations are applied.”

In other words: Get ready.

Russians suspected

It was a prescient warning. On Monday, a Russian network called DarkSide claimed responsibility for the attack on the pipeline—which runs from the Gulf Coast and provides 45% of the East Coast’s fuel supply—in an apparent effort to extort a ransom payment from the operator, Colonial Pipeline.

“It’s not often that hackers manage to hit such crucial oil infrastructure such as Colonial’s pipelines in the U.S.,” says Louise Dickson, oil markets analyst at Norway’s Rystad Energy consultancy.

Nonetheless, on Monday morning, oil prices were feeling bearish, dragged down by the larger picture of flagging demand in Asia and India owing to the pandemic: Brent was down 1.11%, and WTI was down 1.28% on Monday morning, while the main U.S. gasoline futures contract was down 0.51%.

Though it wouldn’t affect supplies if the pipeline isn’t back online for a few days, a more prolonged outage could lead to increased prices, Dickson notes. However, the real issue here isn’t a prospective supply shortage: The U.S. can draw from its ample inventories, as the Biden administration has loosened the rules to allow for fuel to be transported by road instead. The East Coast can also pull cargo of gasoline and diesel across the Atlantic from refineries in Europe.

The bigger risk is that the Colonial Pipeline outage is a mere warning shot. For years, experts and industry insiders have warned that the energy sector is underinvesting in cybersecurity given the scale and complexity of the attacks on its systems—multiple attacks, per day—much of it on critical infrastructure. Some energy majors have themselves admitted that managing the scale and sophistication of the attacks they see is a major challenge, and some of those attacks have been successful. Pemex, the Mexican state energy company, was hit by a high-profile attack in late 2019, when hackers demanded $5 million in Bitcoin as ransom.

Particularly vulnerable

Though such attacks have hit everything from hospital networks to the U.S. government, the energy industry is particularly vulnerable. In a 2020 article, McKinsey warned that utilities and gas companies were more at risk because of their complexity, with geographically diverse, overlapping networks of both physical and cyber infrastructure.

Siemens Energy warned last year that it was the intensity of the sector’s operational systems that also put it at risk: Operational digital infrastructure runs 24/7, with virtually no downtime.

There are also plenty of motives, McKinsey warned. They include state-backed, geopolitically motivated attacks—including a famous attack on a Saudi petrochemical facility that the Saudi government attributed to Iran; economically motivated attacks designed to extort money from desperate companies; and “hacktivist” attacks intended as a protest against the energy industry.

The worry now is that the Colonial Pipeline outage is just the beginning.

More must-read stories from Fortune:

  • A Chinese province powered 8% of all Bitcoin mining. Then the government gave miners 2 months to get out
  • Everything to know about Biden’s $3,000 child tax credit—including when the money should arrive
  • Forget vaccine jabs—next-generation COVID-19 pills and nasal sprays are on their way
  • Bitcoin, Tesla, Ethereum: When should you take profits on your biggest investing winners?
  • The 2021 Fortune/IBM Watson Health 100 Top Hospitals
Our mission to make business better is fueled by readers like you. To enjoy unlimited access to our journalism, subscribe today.
About the Author
By Katherine Dunn
LinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in

Nicholas Thompson
C-SuiteBook Excerpt
I took over one of the most prestigious media firms while training for an ultramarathon. Here’s what I learned becoming CEO of The Atlantic
By Nicholas ThompsonDecember 13, 2025
2 hours ago
Sarandos
Arts & EntertainmentM&A
It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner
By Nick LichtenbergDecember 13, 2025
3 hours ago
Lauren Antonoff
SuccessCareers
Once a college dropout, this CEO went back to school at 52—but she still says the Gen Zers who will succeed are those who ‘forge their own path’
By Preston ForeDecember 13, 2025
3 hours ago
Oracle chairman of the board and chief technology officer Larry Ellison delivers a keynote address during the 2019 Oracle OpenWorld on September 16, 2019 in San Francisco, California.
AIOracle
Oracle’s collapsing stock shows the AI boom is running into two hard limits: physics and debt markets
By Eva RoytburgDecember 13, 2025
4 hours ago
Asiathe future of work
The CEO of one of Asia’s largest co-working space providers says his business has more in common with hotels
By Angelica AngDecember 12, 2025
11 hours ago
EconomyFederal Reserve
Trump names Warsh, Hassett as top Fed contenders, WSJ says
By Jennifer A. Dlouhy and BloombergDecember 12, 2025
14 hours ago

Most Popular

placeholder alt text
Economy
Tariffs are taxes and they were used to finance the federal government until the 1913 income tax. A top economist breaks it down
By Kent JonesDecember 12, 2025
1 day ago
placeholder alt text
Success
Apple cofounder Ronald Wayne sold his 10% stake for $800 in 1976—today it’d be worth up to $400 billion
By Preston ForeDecember 12, 2025
23 hours ago
placeholder alt text
Success
40% of Stanford undergrads receive disability accommodations—but it’s become a college-wide phenomenon as Gen Z try to succeed in the current climate
By Preston ForeDecember 12, 2025
22 hours ago
placeholder alt text
Economy
For the first time since Trump’s tariff rollout, import tax revenue has fallen, threatening his lofty plans to slash the $38 trillion national debt
By Sasha RogelbergDecember 12, 2025
18 hours ago
placeholder alt text
Economy
The Fed just ‘Trump-proofed’ itself with a unanimous move to preempt a potential leadership shake-up
By Jason MaDecember 12, 2025
16 hours ago
placeholder alt text
Success
At 18, doctors gave him three hours to live. He played video games from his hospital bed—and now, he’s built a $10 million-a-year video game studio
By Preston ForeDecember 10, 2025
3 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.