Colonial Pipeline CEO acknowledges $4.4M ransomware payment

Joseph Blount tells WSJ, ‘It was the right thing to do for the country’

Colonial Pipeline Reportedly Paid Nearly $5 Million in Ransom to Hackers.According to Bloomberg, Colonial Pipeline Co. paid the ransom in difficult-to-trace cryptocurrency within hours after the attack, .which contradicts earlier reports that the company had no intention of paying any extortion fee.The hackers, which the FBI said are linked to a group called DarkSide located in either Russia or Eastern Europe, specialize in digital extortion.A source familiar with the company’s efforts stated the hackers provided a decrypting tool upon receiving the payment, .though the tool operated so slowly that Colonial continued using its own system to restore operations.Colonial said it began to resume fuel shipments Wednesday evening

The CEO of Georgia-based Colonial Pipeline said he approved paying more than $4 million to the Russian-based hackers who cyberattacked his company because “it was the right thing to do for the country.”

In an interview published Wednesday by The Wall Street Journal, Joseph Blount said he authorized the ransom payment of $4.4 million because executives were unsure how badly the cyberattack had breached its systems or how long it would take to bring the pipeline back.

“I know that’s a highly controversial decision,” Blount said. “I didn’t make it lightly. I will admit that I wasn’t comfortable seeing money go out the door to people like this. But it was the right thing to do for the country.”

Colonial Pipeline announced last Thursday it resumed product delivery. (Image: Colonial Pipeline)

icon to expand image

The interview is the first time Blount or the company has acknowledged paying the ransom. He also said it will take months and cost the company “tens of millions of dollars” to fully repair the damage and restore all of its business systems.

The May 7 cyberattack locked up the company’s computer systems. The hackers didn’t take control of pipeline operations, but the Alpharetta-based company shut it down to prevent malware from affecting industrial control systems.

The Colonial Pipeline stretches from Texas to New Jersey and delivers about 45% of the gasoline consumed on the East Coast. The shutdown has caused shortages at the pumps throughout the South and emptied stations in the Washington, D.C., area.

On Tuesday, Colonial Pipeline was hit with a service interruption that was not the result of ransomware or another cyberattack. However, the company brought its systems back online within a few hours.

Blount told The Wall Street Journal an employee found a ransom note from hackers on a control-room computer on the morning of May 7. President Joe Biden said U.S. officials do not believe the Russian government was involved, but said “we do have strong reason to believe that the criminals who did the attack are living in Russia.”

Much of the U.S. pipeline infrastructure, including Colonial, is privately owned. The chairman of the Federal Energy Regulatory Commission, which oversees interstate pipelines, said this week the U.S. should establish mandatory cybersecurity standards for pipelines similar to those in the electricity sector.

“Simply encouraging pipelines to voluntarily adopt best practices is an inadequate response to the ever-increasing number and sophistication of malevolent cyber actors,” FERC Chairman Richard Glick said.

The ransomware attack should play a role as Congress considers Biden’s $2.3 trillion infrastructure proposal, U.S. Energy Secretary Jennifer Granholm said last week.