Worked example · 2021-05
Colonial Pipeline ransomware extortion payment — 2021-05
Summary
On 2021-05-07, Colonial Pipeline Company — operator of the largest refined-products pipeline system in the United States (~5,500 miles, ~2.5M barrels/day) — was hit by a DarkSide ransomware attack that encrypted its corporate IT network. Colonial proactively shut down pipeline operations, causing a multi-day disruption to East Coast fuel supply.
Colonial's CEO authorised a 75 BTC payment (~$4.4M) to a DarkSide-provided Bitcoin address. The FBI's New York Field Office, working with the DOJ's Ransomware and Digital Extortion Task Force, traced the payment through the Bitcoin transaction graph and identified a DarkSide-controlled address whose private key was recovered via an undisclosed method. On 2021-06-07, the FBI executed a seizure warrant and recovered 63.7 BTC.
The DarkSide group operated under a RaaS model: affiliates deployed the ransomware and received 75-85% of payments; the DarkSide core team received 15-25% and provided the ransomware infrastructure, payment infrastructure, and negotiation support. The affiliate-split structure leaves a detectable on-chain two-hop fingerprint.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2021-05-07 | Colonial Pipeline corporate IT network encrypted by DarkSide ransomware | (incident) |
| 2021-05-07 | Colonial Pipeline shuts down operations (~45% East Coast refined-product supply affected) | (operational impact) |
| 2021-05-07 | Colonial pays |
T5.008 (ransomware extortion payment) |
| 2021-06-07 | FBI seizes 63.7 BTC from DarkSide-controlled address via private-key recovery | T5.008 (post-payment seizure) |
| 2021-06-08 | DOJ announces seizure; Deputy AG Monaco confirms FBI traced and recovered the payment | (law enforcement) |
Public references
- FBI affidavit for seizure warrant: In re: Seizure of 63.770168 Bitcoin (E.D. Cal., June 2021).
- DOJ press release: "Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside" (2021-06-07).
- CISA Alert AA21-131A: DarkSide Ransomware — Best Practices for Preventing Business Disruption from Ransomware Attacks.