You are currently viewing 2020–2021: SolarWinds, Colonial Pipeline & the Ransomware Wave

2020–2021: SolarWinds, Colonial Pipeline & the Ransomware Wave

  • Post author:
  • Post category:Security
📋 Key Takeaways
  • The World in 2020
  • 23. The SolarWinds Supply-Chain Attack (2020) — The Most Sophisticated Espionage Campaign Ever Seen
  • 24. The Colonial Pipeline Ransomware Attack (2021) — The East Coast Runs Dry
  • 25. The JBS Ransomware Attack (2021) — $11 Million to Keep Meat Flowing
  • 26. The Kaseya / REvil Attack (2021) — 1,500 Businesses in One Weekend
16 min read · 3,126 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

2020–2021: SolarWinds, Colonial Pipeline & the Ransomware Wave

← Back to the full list · Previous: Part 4 — 2016–2019

The World in 2020

The pandemic emptied offices into home networks overnight, and attackers followed the opportunity. Two trends peaked simultaneously. Supply-chain compromise matured from theory (Titan Rain’s heirs, XZ’s future) into practice: instead of attacking 18,000 targets, attack one vendor they all trust. And ransomware became infrastructure warfare: crews stopped encrypting laptops for petty bitcoin and started shutting pipelines, meat plants, and hospital networks, discovering that governments will negotiate with you if the lights (or the gasoline) go out.

The four attacks in this part — one espionage operation and three ransomware events — between them forced a US presidential executive order, new federal disclosure rules, TSA security directives, a superpower summit confrontation, and the first truly mainstream realization that cybersecurity is national security.


23. The SolarWinds Supply-Chain Attack (2020) — The Most Sophisticated Espionage Campaign Ever Seen

Attacker Russia’s SVR foreign intelligence service (APT29, “Cozy Bear” / “Nobelium”) — formally attributed by the US and UK in April 2021
Targets SolarWinds’ Orion software customers: the US Treasury, State, Commerce, Homeland Security and Energy departments, plus FireEye, Microsoft, Intel, Cisco, VMware, and many others
Method Implanting a backdoor (“SUNBURST”) inside SolarWinds’ own build system, distributed as a signed software update
Damage ~18,000 customers exposed to the trojanized update; roughly 100 organizations deeply penetrated
Cost Never totaled; a generational overhaul of US federal cybersecurity and software-supply-chain policy

How the attack unfolded

On December 8, 2020, the cybersecurity firm FireEye — one of the world’s best incident-response teams — announced it had been hacked and its own red-team testing tools stolen. It was a humbling disclosure from a company that investigates everyone else’s breaches. But FireEye’s honest, detailed account ignited a firestorm of investigations across government and industry, and within days the picture that emerged dwarfed FireEye’s loss: the intruders hadn’t attacked FireEye directly at all. They had come through SolarWinds.

SolarWinds, a Texas software company, sold Orion, a network-monitoring platform used by over 30,000 organizations — including nearly all US federal agencies and half the Fortune 500. At some point in 2019, Russia’s SVR compromised SolarWinds’ software build system: the secure pipeline that compiles source code into trusted, digitally signed updates. Into that pipeline they inserted SUNBURST, a backdoor embedded inside Orion.Core.BusinessLayer.dll — a core component of the product itself. Between March and June 2020, SolarWinds shipped the poisoned code to customers as routine, signed updates (versions 2019.4 through 2020.2.1). Roughly 18,000 organizations downloaded and installed it, their trust in the vendor’s digital signature weaponized against them.

The implant’s design remains the gold standard of stealth:

  • It lay dormant for one to two weeks after installation — defeating dynamic sandbox analysis that watches for only minutes.
  • It then checked whether the machine was worth attention: if the victim organization was interesting, it quietly beaconed out through DNS, disguising traffic as the Orion application’s normal communications, hiding behind domains (some resolving to legitimate US infrastructure) and matching SolarWinds’ own protocols.
  • For chosen targets, the attackers escalated with second-stage implants (TEARDROP, RAINDROP) delivering Cobalt Strike — living almost entirely in memory, leaving nearly no disk forensics.
  • They monitored each other’s tradecraft, moved slowly, and kept traffic volumes imperceptible — designed never to trip the anomaly alarms of the best-funded targets on Earth.

The chosen victims formed a strategic map: the US Treasury (including the email of its senior leadership), the State Department, the Commerce Department, the Department of Homeland Security — including CISA itself, the agency charged with defending federal networks — the Department of Energy and its Federal Energy Regulatory Commission, the NIH, the federal courts’ administrative office, and state governments. Abroad and in industry: FireEye, Microsoft (which confirmed its own source code was viewed), Intel, Cisco, VMware, Deloitte, and others. In April 2021, the US and UK formally attributed the campaign to the SVR — the same service behind the 2016 DNC hacks’ sister unit — noting the operation’s patient, low-and-slow espionage character.

The initial entry into SolarWinds remains publicly unresolved: investigators explored everything from compromised credentials (an infamous, separately-reported weak password on a SolarWinds update server) to insider-adjacent access, and no definitive public account has closed the question. In a sense, that ambiguity is part of the lesson.

The damage

Microsoft’s president Brad Smith called it “the largest and most sophisticated attack the world has ever seen.” No data loss totals were ever published — this was espionage, theft of insight rather than mass exfiltration of databases — but the strategic cost was enormous: presumed long-term visibility into unclassified but sensitive US government communications, and the demonstrated ability to live undetected inside the most defended networks in the world for nine months, discovered only because one victim (FireEye) noticed something odd when a single employee’s account registered a new MFA device.

Aftermath & lessons

  • The US response in April 2021: formal attribution, sanctions, and the expulsion of ten Russian diplomats, followed by Executive Order 14028 — the most significant federal cybersecurity directive in decades, mandating zero-trust architectures, MFA, encryption, and software supply-chain security (SBOMs) across the government.
  • SEC vs. SolarWinds (2023): the SEC sued the company and, extraordinarily, its CISO personally, alleging fraud for overstated security claims. The novel theory — that a security executive’s public statements can be securities fraud — sent a chill through the CISO profession and remains contested in the courts.
  • The attack defined the modern supply-chain threat model: trust relationships (vendors, updates, signatures, build systems) are now primary attack surfaces. Every major software vendor subsequently invested in build-system hardening, two-person review, and provenance signing.

The core lesson: when you install a vendor’s signed update, you are trusting their entire engineering organization and everyone with access to it. The SVR didn’t break 18,000 locks — it picked one, and 18,000 doors opened.


data-hmmnm-seam="2">

24. The Colonial Pipeline Ransomware Attack (2021) — The East Coast Runs Dry

Attacker DarkSide — a Russia-based ransomware-as-a-service operation
Target Colonial Pipeline — 5,500 miles of pipeline carrying ~45% of the US East Coast’s fuel
Method One leaked password on a dormant VPN account, unprotected by MFA
Damage Six-day pipeline shutdown; fuel emergencies across the Southeast; thousands of dry gas stations
Cost ~$100M+ impact to Colonial; $4.4M ransom paid, ~$2.3M recovered by the FBI

How the attack unfolded

On May 7, 2021, a Friday, ransomware began encrypting the IT systems of Colonial Pipeline, the artery that moves gasoline, diesel, and jet fuel from Gulf Coast refineries to New York Harbor — roughly 45% of the East Coast’s supply. Colonial’s operators made the consequential decision: shut the pipeline down entirely, fearing the intruders could pivot from billing systems into operational control. It was the safe call, and it turned a corporate IT incident into a national event.

The entry vector, revealed in Congressional testimony and confirmed by the company, was almost painful in its simplicity: a password for a remote-access VPN account — an account for an employee who no longer even worked there, left active on the internet-facing system — without multi-factor authentication. The password had appeared in a leak of breached credentials elsewhere; DarkSide’s affiliates (or an initial-access broker feeding them) simply tried it. Not a zero-day. Not a nation-state. A dead account and a missing MFA setting.

The attacker, DarkSide, was a “ransomware-as-a-service” franchise operating from Russia with a professional brand: it published press releases, claimed to avoid hospitals and nonprofits (its “code of ethics” was a marketing gimmick), and split proceeds with affiliates who conducted intrusions. Beyond encryption, DarkSide stole nearly 100 GB of data for standard double extortion.

The societal cascade was instant. With the pipeline dark, panic buying emptied stations across the Southeast: within days, thousands of gas stations in states like North Carolina, Virginia, and Georgia ran out; roughly 70–80% of stations in some areas were dry at the peak; the national average gasoline price crossed $3 for the first time since 2014; governors declared states of emergency; even airline fueling was adjusted. The images of lines around the block and plastic bags over pumps did more for ransomware awareness in one week than a decade of warnings.

Colonial’s CEO Joseph Blount authorized a ransom payment of ~75 bitcoin (~$4.4 million) within hours of the attack — a decision he defended to the Senate: uncertain whether the intruders had reached operational systems and facing a national fuel emergency, he judged paying necessary “for the country.” The pipeline restarted on May 12, after six days. Then a rare counterpunch: on June 7, the DOJ announced it had recovered ~$2.3 million of the ransom — about 63.7 of the bitcoins — after tracking the attackers’ wallet and obtaining its private key (reportedly following an FBI operation against DarkSide’s infrastructure).

DarkSide itself announced its dissolution days after the attack — claiming (implausibly) that US pressure had made operations impossible, losing police attention, and reportedly stiffing its own affiliates on the way out — and its members promptly rebranded, as such crews always do.

The damage

Colonial reported material financial impact (later filings quantified the disruption in the tens of millions; estimates including response, insurance, and lost margin ran near or above $100 million). The macro-damage was the point: for the first time since ransomware’s rise, an attack on one company produced a visible consumer crisis across half a country — lines, shortages, price spikes — and forced the question of whether pipelines, hospitals, and food processors needed wartime-level cyber regulation.

Aftermath & lessons

  • TSA Pipeline Security Directives followed within weeks: mandatory incident reporting, cybersecurity assessments, and the designation of a cybersecurity coordinator; the voluntary era for pipeline security ended. Similar rules spread across surface transportation and beyond.
  • The attack supercharged the ransomware national-security agenda: it was a centerpiece of Biden’s June 2021 Geneva summit message to Putin — safe harbor for ransomware crews would be treated as a national-security problem between states — and of the May 2021 Executive Order 14028.
  • Every security team on Earth acquired a new archetype: the dormant account. Offboarding gaps — accounts that outlive their humans — became a first-order audit item, alongside MFA on literally every externally exposed service.

The core lesson: a $4.4 billion company running critical infrastructure was entered with one leaked password. The gap between “critical” and “protected” is organizational, not technological — and panic buying multiplies any outage you fail to prevent.


data-hmmnm-seam="3">

25. The JBS Ransomware Attack (2021) — $11 Million to Keep Meat Flowing

Attacker REvil (Sodinokibi) — a Russian-linked ransomware operation
Target JBS — the world’s largest meat processor (US, Australia, Canada operations)
Method Ransomware encrypting production-support systems over a holiday weekend
Damage Worldwide plant slowdowns and shutdowns; US beef and pork capacity disrupted
Cost $11 million ransom paid in bitcoin, despite successful restoration from backups

How the attack unfolded

Three weeks after Colonial Pipeline, on the Memorial Day weekend of May 29–30, 2021, ransomware struck the food supply. JBS — a Brazilian company that is the largest meat processor on Earth, handling roughly a fifth of American beef and pork — suffered infections across its US plants (forcing shutdowns or slowdowns at multiple beef facilities, including the largest in the country), its Australian operations (47 sites affected, including the biggest meatworks there), and Canadian plants. Slaughter lines stopped; wholesale meat prices braced for a shock; the White House publicly announced that a Russia-based group (REvil) was responsible and that it had raised the matter with Moscow.

The attackers were REvil — at that moment the most feared ransomware brand in the world (their July Kaseya attack, below, was still ahead of them), running a criminal franchise from Russian safe harbor with a reputation for ruthless double extortion and record demands.

JBS responded fast and well on the operational side: plants came back online within days, largely thanks to restored backups and segmented systems — by most accounts the company’s recovery was a success story. And then came the part that made the case famous: despite having restored operations, JBS paid an $11 million ransom in bitcoin anyway. CEO Andre Nogueira explained the reasoning plainly: the company could not guarantee the attackers hadn’t retained access, couldn’t be certain stolen data wouldn’t be leaked, and judged $11 million a cheap price against even one more day of global disruption. “We felt this decision had to be made to mitigate any potential risk for our customers,” he said — a perfect articulation of why ransomware works even against prepared victims.

The damage

The direct disruption was measured in days rather than weeks (prices wobbled but didn’t collapse), which — given the target — counts as a near miss. The $11 million payment, however, fed the central policy dilemma: JBS did everything right operationally and still concluded paying was rational. Each such payment funds the next attack; each refusal risks the next blackout. Governments spent 2021–2022 wrestling with exactly this, and JBS became the exhibit for why “just don’t pay” is not a strategy an individual company can adopt alone.

Aftermath & lessons

  • Presidential summit pressure: At the June 16, 2021 Geneva summit, Biden handed Putin a list of 16 critical-infrastructure sectors that were to be off-limits, with JBS and Colonial as the fresh exhibits. In January 2022, Russia’s FSB — in a startling exception to its usual safe-harbor practice, and at US request — announced the dismantling of REvil and the arrest of 14 members, attributing the decision to “the operational compatibility of the Russian and US security services.” The group’s leadership walked free later, but the point was made: ransomware had become a great-power diplomatic issue.
  • A REvil affiliate, Yaroslav Vasinskyi (arrested in Poland in October 2021 and extradited), was sentenced in the US in April 2024 to over 13 years in prison — for the Kaseya attack — one of the longest ransomware sentences ever.
  • Food and agriculture were formally treated as critical infrastructure targets afterward (the sector’s designation predates this, but enforcement attention and guidance multiplied).

The core lesson: backups protect your operations, but they don’t erase the attacker’s leverage over your stolen data. Until extortion risk itself is addressed — by policy, sanctions, and disrupting the ecosystem — even the best-prepared victim can rationally pay.


data-hmmnm-seam="4">

26. The Kaseya / REvil Attack (2021) — 1,500 Businesses in One Weekend

Attacker REvil ransomware operation
Targets Managed service providers (MSPs) running Kaseya VSA — and their downstream small-business clients
Method Zero-day authentication-bypass exploit in Kaseya VSA, delivering ransomware as a fake software update
Damage Up to ~1,500 downstream businesses encrypted across ~17 countries; an 800-store grocery chain closed
Cost Ransom demands from ~$5M (individual) to $70M (universal decryptor); full restoration took weeks

How the attack unfolded

On Friday, July 2, 2021 — the start of the July 4th holiday weekend, when staffing was thin — REvil detonated the most creative supply-chain ransomware attack yet seen. Their target was Kaseya VSA, remote-monitoring-and-management software used by managed service providers (MSPs) — the IT outsourcers that run networks for hundreds of thousands of small and mid-sized businesses.

REvil exploited a zero-day vulnerability (an authentication bypass, CVE-2021-30116) in Kaseya’s on-premises VSA servers. With it, they turned MSPs’ own management infrastructure against their clients: through each compromised VSA server, they pushed to every managed endpoint what appeared to be a legitimate “Kaseya VSA Agent Patch — Critical Enhancement” — signed, staged, and deployed through the exact channel administrators use for trusted updates. It was, in effect, a miniature SolarWinds executed by criminals in 48 hours: poison the management layer, own everything beneath it.

The cascade was immediate and global. Kaseya (and its CEO, Fred Voccola) responded by telling all customers to shut down their VSA servers immediately — self-amputating their own management tooling to stop the bleeding. An estimated 50–60 MSPs were directly hit, and with them up to ~1,500 downstream businesses across at least 17 countries.

The most visible casualty was half a world from Kaseya’s Miami headquarters: Coop, one of Sweden’s largest grocery chains, discovered its cash registers were managed through a Swedish MSP that used VSA via a reseller — and roughly 800 stores closed for days, unable to run their tills, in the most tangible consumer impact of any ransomware event until Colonial. Schools in New Zealand and Sweden, pharmacies, dental practices, small governments, and countless SMBs were similarly locked.

REvil, sensing history, priced accordingly: $70 million for a universal decryptor (later softened to $50 million), alongside per-victim demands starting around $5 million — aimed at MSPs’ cyber-insurance payouts, with individual affected end-customers offered relative crumbs. Kaseya worked frantically: within days it had a patch, and within about three weeks it announced it had obtained a universal decryption tool from a “trusted third party” — widely reported to be a negotiated channel to REvil itself — and deployed it to all affected customers. Kaseya denied paying the $70M figure; the actual price, if any, was never disclosed.

Then came the final twist, revealed in late-2021 reporting: the FBI had obtained a decryption key relatively early in the incident — but delayed sharing it for days or weeks while it covertly worked to disrupt REvil’s infrastructure, judging that killing the ransomware operation was worth more than immediately unlocking victims. The operation (reportedly a US Cyber Command effort in the wake of the group’s earlier attacks) contributed to REvil’s mysterious October 2021 disappearance — its servers vanished after an apparent takedown — and to the January 2022 Russian arrests. The policy debate over that trade-off — save today’s victims vs. destroy tomorrow’s attacker — remains unresolved.

The damage

The victims were mostly small businesses without incident-response retainers, making the aggregate cost impossible to tally, though estimates ran to tens of millions. Structurally, the damage was to an entire industry’s self-image: MSPs — the quiet plumbing of the small-business internet — realized they had become the supply chain, and that their management tools were single points of catastrophic failure.

Aftermath & lessons

  • CISA issued emergency guidance for MSPs and RMM (remote monitoring and management) hardening; MSP-security standards (segmentation, per-client isolation, MFA on consoles, zero-trust between management plane and endpoints) became contract requirements from insurers within a year.
  • The attack, stacked on SolarWinds seven months earlier, completed the supply-chain decade’s argument: the most valuable target in any ecosystem is the thing everyone else depends on. Software vendors, MSPs, CAs, libraries — concentration is the attack.
  • REvil’s arc — audacious apex, mysterious takedown, Russian arrests under US pressure — became the template narrative of state action against ransomware crews… and of how quickly successors (BlackCat, LockBit, RansomHub) fill any vacuum.

The core lesson: trust pipelines are attack pipelines. If your management tool can push software to a thousand clients, so can your attacker — and “we’re too small to target” died the day the target became the tool itself.


Next in the series: Part 6 — 2022–2024: Lapsus$, Change Healthcare & the XZ Backdoor →

data-hmmnm-seam="end">