AMLConsensus · course
Programme · Lesson 11.2
Section 11 · Lesson 11.2 · case study

Colonial Pipeline: How the FBI Recovered the Ransom from Extortionists

In the spring of 2021, the largest fuel pipeline on the U.S. East Coast shut down for several days — and lines formed at the gas pumps. The cause was not a terrorist attack or an accident, but a line of malicious code. The company paid the extortionists a ransom of 75 bitcoin, believing the money would dissolve forever into the dark depths of the blockchain. A month later, most of it was recovered. This case is a short but striking demonstration of the principle we discussed in the previous case study: even a ransom in cryptocurrency is traceable — and recoverable.

▶ Video case study: Colonial Pipeline (English narration).

7 May 2021: a country lines up for gasoline

On 7 May 2021 the hacker group DarkSide (operating out of Russia) encrypted the networks of Colonial Pipeline — the operator of the fuel line supplying a significant part of the U.S. East Coast. The ransomware attack paralyzed the company: to avoid risking safety, the operator was forced to halt the flow of fuel.

The consequences went far beyond an IT incident. Fuel supply disruptions triggered panic, lines at gas stations, and rising prices — a rare case where a cyberattack directly hit the everyday lives of millions of people. It was precisely the scale of this blow that turned the Colonial Pipeline case into a showcase proceeding: the state was motivated to respond loudly and visibly.

The ransom: 75 bitcoin

Under the pressure of circumstances, the company made a decision that security experts generally do not recommend, but which in a crisis looked like the only quick way out: to pay the ransom. Colonial Pipeline transferred 75 BTC to the extortionists — about 4.4 million dollars at the time.

From DarkSide's point of view this was a well-honed scheme: encrypt critical infrastructure, demand a ransom in bitcoin — "untraceable," as many think — and vanish. The extortionists' logic rests on the assumption that cryptocurrency is anonymous and that the money received can neither be traced nor recovered. The Colonial Pipeline case publicly demolished that logic.

  1. 7 May 2021 — the attack. The DarkSide group encrypts Colonial Pipeline's networks; the fuel flow stops.A cyberattack on infrastructure escalates into a fuel crisis on the U.S. East Coast.
  2. Ransom payment. The company transfers 75 BTC (~$4.4M) to the extortionists.The extortionists' bet: bitcoin is "anonymous" and the money cannot be recovered.
  3. Tracing the funds. The FBI follows the ransom's movement across the public blockchain, address to address.Every transfer leaves an immutable trail in the open ledger.
  4. Access to the key. Investigators gain access to the private key of a DarkSide affiliate's wallet.The key is the only way to actually seize the coins; the blockchain cannot be undone.
  5. Seizure. By court order, ~63.7–69.6 BTC (~$2.3M) are recovered.Most of the ransom is physically recovered — an unprecedented result for ransomware.

How the FBI turned the situation around

What happened next was something the extortionists did not expect. The FBI did not "look for the money on the darknet" — instead, investigators did exactly what the blockchain allows: they traced the ransom's movement across the public ledger, transaction by transaction, wallet to wallet.

But tracing the path is only half the job. As we already know from the Bitfinex story, seeing the coins on the blockchain and gaining control over them are different things. A bitcoin transfer cannot be undone; to seize the coins, a private key is needed. And here the investigation held a decisive trump card: access to the private key of a wallet belonging to an affiliate (partner) of the DarkSide group. The ransomware-as-a-service model works such that the attack is often carried out not by the "head" group itself but by its affiliate partner, who receives a share of the ransom. It was the wallet of exactly such an affiliate that was accessed.

With the key in hand, investigators, by court order, seized about 63.7–69.6 BTC — roughly 2.3 million dollars, that is, a significant part of the paid ransom. For the world of cyber-extortion, where paid money was traditionally considered irretrievably lost, this was a turning point.

"Today we turned the tables on DarkSide."

— Lisa Monaco, U.S. Deputy Attorney General.

This short phrase — "we turned the tables" — captures the essence of the case precisely. The extortionists counted on the rules of the game being on their side: anonymous crypto, encrypted infrastructure, a helpless victim. But it turned out the other way around: the very cryptocurrency they considered a reliable hiding place became the evidence and the channel for recovering the money.

The scheme of the ransom and its recovery

DarkSide
encrypts Colonial's networks
Ransom 75 BTC
≈ $4.4M
Tracing + key
affiliate's wallet
Recovery
~63.7–69.6 BTC ≈ $2.3M

Why this matters for AML

The Colonial Pipeline case is often recalled when discussing the myth of "untraceable" cryptocurrency. Let's break down what lessons it offers the wallet-screening specialist.

First: a ransomware ransom is a traceable money flow. Unlike a suitcase of cash passed hand to hand, a crypto ransom is recorded forever on the blockchain. This means that funds tied to known extortion campaigns end up in label databases and sanctions lists. A wallet that received coins from such a source carries a toxic "fingerprint" — and a competent AML check is obliged to see it.

Second: the speed of response has grown. Note the timelines. In the Bitfinex case, six years passed between the theft and the seizure. Here — mere weeks passed from the 7 May attack to the announcement of the recovery. Blockchain-analytics tools and coordination between investigators and the industry have reached a level where "hot" money can be traced almost in real time.

Third: the key is still the point of control. As in the Bitfinex case, the physical recovery of the funds became possible only thanks to access to the private key. The blockchain is immutable: a transfer cannot be "rolled back." The only way to actually take the coins is to gain control over the keys of the wallet where they sit. This once again underscores why in compliance it is so important to understand who controls the keys to a given address.

An important note on the details. Open sources cite close but not identical recovery figures (on the order of 63.7–69.6 BTC), because the price of bitcoin and the exact per-wallet arithmetic were calculated differently. For the AML specialist there is a lesson in humility here: work with ranges and primary sources, do not pass off a "neat" single figure as truth. Accuracy in facts is part of professional hygiene.

What this case teaches. Cryptocurrency is not a refuge for extortionists but a piece of evidence that cannot be erased. The public nature of the blockchain turns a ransom into a trail leading to the criminal, and access to the private key makes it possible to recover the money even after it has "left." For screening practice this means: funds tied to ransomware are a high-level red flag, and the very traceability of ransoms makes crypto a less convenient tool for extortion than is commonly believed. The phrase "Today we turned the tables" is not bravado but a precise description of how the ledger's transparency works against the one who counted on it.

What to take away from this lesson

  • Timeline7 May 2021 — the DarkSide attack; ransom of 75 BTC (~$4.4M); within weeks ~63.7–69.6 BTC (~$2.3M) recovered.
  • Recovery mechanismTracing across the public blockchain + access to the private key of a DarkSide affiliate's wallet.
  • SpeedUnlike Bitfinex (6 years), here it was mere weeks: analytics and coordination reached a level of "almost real time."
  • Key quoteLisa Monaco: "Today we turned the tables on DarkSide."

We have examined two cases where the trail led to individual criminals and partners. In the next case study the adversary will be of a different class — a state-run hacker group of an entire country: how Lazarus stole $625M through the Ronin bridge.

The facts are presented from open sources. The materials are for educational purposes.