Case Study – “The Colonial Pipeline Attack“
Introduction
On May 7, 2021, the United States East Coast experienced a multi-million dollar ransomware attack on the Colonial Pipeline. The cyberattack came from a group called Darkside. This pipeline carried millions of gallons of fuel all along the East Coast. Joe Biden issued a state of emergency, and in response, Americans panicked racing to fill up gas cans or whatever they could store fuel. Although the shutdown only lasted about a week, the impact it left on America was long lasting. Once the hackers entered Colonial Pipeline’s network, they likely used their access privileges to move laterally across the network’s infrastructure. During their intrusion, they stole approximately 100 gigabytes of data in two hours (INSURICA, 2024)
Analysis
With their sophisticated technological skills, the hackers were able to infiltrate one of largest oil productions in the country. A viewpoint from the social science perspective, is that this attack was not infiltrated by just a computer system hacking into another, but a human-led cyberattack. This attack was coordinated by individuals with a motive set out for a profitable large sum. The huge concern came about when the group was able to hack into the system because the organization failed to secure their facility. “In May of 2021, a hacker group known as DarkSide gained access to Colonial Pipeline’s network through a compromised VPN password. This was possible, in part, because the system did not have multifactor authentication protocols in place. This made entry into the VPN easier since multiple steps were not required to verify the user’s identity” (INSURICA, 2024).
Solution
Although this brought about significant challenges for the American people because they were stressed about how they would make it throughout the work and school week without fuel, it also brought about valuable lessons. The challenges will come if we aren’t willing to change our behavior. This incident highlights the risks we can face if we do not have stronger cybersecurity practices and improve our digital hygiene. “The good news is that since that event, the Biden-Harris Administration has made significant strides in our collective cyber defense, harnessing the full power of the U.S. government to address the full spectrum of the threat. At the Cybersecurity and Infrastructure Security Agency (CISA), we have been laser focused on improving resilience across our Nation’s critical infrastructure” (Easterly & Fanning, 2023). From a social science perspective, the government should establish clear and effective methods of making sure the public is aware of attacks on U.S. soil so there will be less confusion and panic.
Reflection
It is essential to incorporate technology and social sciences to mitigate these types of cyberattacks. To see this as just a technological issue, would be an inadequate mindset because it is always human activity that plays a critical role. “Finally, we need to normalize cyber risks for the general public with the recognition that cyber-attacks are a reality for the foreseeable future. We cannot completely prevent attacks from happening, but we can minimize their impact by building resilience into our infrastructure and into our society” (Easterly & Fanning, 2023).
Conclusion
In conclusion, the cyberattack on the Colonial Pipeline brought about vulnerabilities and concerns in the technological and social sciences fields. The ransom was paid, however, the concerns are still there whether we will face future attacks such as this one. “Although it may seem like making payments allows for a faster incident recovery process—what the company’s leadership decided in this case—paying the ransom can lead to future cybersecurity concerns and other issues” (INSURICA, 2024). The good thing is, it highlighted where organizations went wrong and can now have a better plan in place to, hopefully, prevent or at least protect software from hackers.
Reference:
INSURICA. (2024). Cyber case study: Colonial pipeline ransomware attack. INSURICA. https://insurica.com/blog/colonial-pipeline-ransomware-attack/
Easterly, J., & Fanning, T. (2023, May 7). The attack on the colonial pipeline: What we’ve learned & what we’ve done over the past two years. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years