DarkSide first reached Colonial Pipeline on 29 April 2021 by logging into a legacy corporate VPN with an employee username and password and no one-time passcode. According to Mandiant’s Charles Carmakal in House testimony, that single-factor VPN login is the earliest evidence of compromise. CEO Joseph Blount told the Senate the legacy VPN used only single-factor authentication. Public reporting does not establish how the password was obtained. The inactive account was still enabled. DarkSide ransomware disrupted operations beginning 7 May 2021, with roughly 100 GB reported exfiltrated and pipeline operations halted by Colonial.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did DarkSide get into Colonial Pipeline?
DarkSide’s earliest documented foothold on Colonial Pipeline was a successful login to a Colonial VPN on 29 April 2021. According to Mandiant’s Charles Carmakal, the actor used a legacy VPN profile with an employee username and password and without a one-time passcode. That opened a corporate network path before ransomware activity beginning 7 May 2021.
Did the Colonial VPN require MFA?
No. CEO Joseph Blount told the Senate the legacy VPN Colonial used for that path had only single-factor authentication. The login that Mandiant tied to earliest compromise completed on password alone. There was no OTP or other second factor on that profile at the time of the 29 April 2021 access.
How did attackers get the Colonial employee password?
Public reporting does not establish how the Colonial employee password was obtained. Contemporaneous discussion floated a leak corpus and other guesses; none of that is proven in the testimony and intake facts used here. What is documented is use of the username and password on a legacy VPN that did not demand a one-time passcode, on an account that was inactive and still enabled.
Would MFA have stopped the Colonial ransomware and data theft?
MFA on that VPN login would have blocked the password-only tunnel that was the documented initial access. It would not have undone ransomware deployment, lateral work, or the reported ~100 GB exfiltration after the attacker already held a live VPN session on the corporate network. Closing the single-factor VPN gate is the authentication lesson. Stopping post-login malware and encryption is a separate containment problem.
Why did an inactive Colonial VPN account still matter?
The inactive employee account was still enabled on the legacy VPN profile, so a valid password could complete single-factor login without a live daily user in the loop. Dormant workforce VPN identities with password-only auth are a standing remote door. Public reporting does not name a helpdesk reset, TAP, spoofed page, or AiTM kit for this entry; the proven failure is single-factor legacy VPN access left reachable.