
Ransomware attackers used compromised password to access Colonial Pipeline network
CNN
Ransomware attackers gained access to Colonial Pipeline's computer networks in April using a compromised password, according to the company and a cybersecurity firm it hired -- leading to the deliberate shutdown of one of America's most important fuel distribution companies and the panic gas buying that ensued for days.
The password had been linked to a disused virtual private networking account used for remote access, FireEye confirmed to CNN, and the account was not guarded by an extra layer of security known as multi-factor authentication. Bloomberg first reported the password vulnerability following interviews with Charles Carmakal, senior vice president at Mandiant — the forensic division of FireEye — and Joseph Blount, Colonial's CEO.More Related News

Defense Secretary Pete Hegseth risked compromising sensitive military information that could have endangered US troops through his use of Signal to discuss attack plans, a Pentagon watchdog said in an unclassified report released Thursday. It also details how Hegseth declined to cooperate with the probe.












