DarkSide was the ransomware associated with the 2021 attack that forced Colonial Pipeline to shut down its operations.
Colonial Pipeline disclosed the attack in May 2021 and temporarily halted pipeline operations as it contained the incident. The company transports refined petroleum products across a large section of the eastern United States, so the shutdown contributed to fuel shortages, long lines, and emergency measures in affected areas.
DarkSide operated as a ransomware-as-a-service group. This model separates the developers who maintain ransomware from affiliates who break into victims’ networks and carry out attacks. The criminals typically threaten both encryption and publication of stolen data.
The incident is often discussed as a critical-infrastructure attack, although the immediate operational shutdown was a defensive response to compromised corporate information systems rather than a direct physical destruction of the pipeline.