Shortly after 5am on Friday 7 May 2021, an employee in Colonial Pipeline's control room found a ransom note on a computer screen. Within little more than an hour, the company had done something it had never done before: shut down its entire pipeline system — 5,500 miles from Houston to New Jersey, carrying roughly 45% of the fuel consumed on the US East Coast. The ransomware, DarkSide's, had reached only the IT and billing side of the business; Colonial switched off the operational side itself, as a precaution, unsure how deep the intrusion went. The attackers had reportedly also taken nearly 100 gigabytes of data the day before, by way of leverage.
What followed owed less to fuel logistics than to human nature. The outage itself might have been absorbed; the panic was not. By Tuesday 11 May, panic buying had emptied 71% of petrol stations in Charlotte, North Carolina; by Friday, 87% of stations in Washington DC were dry. The national average petrol price crossed $3 a gallon for the first time since 2014, the federal road regulator relaxed driving-hours rules for fuel tankers across 17 states and the District of Columbia, and the US Consumer Product Safety Commission felt obliged to say, in public: "Do not fill plastic bags with gasoline." Colonial restarted the line at 5pm on 12 May; deliveries took several more days to normalise.
The company had also, quietly, already paid. On the day of the attack, chief executive Joseph Blount authorised a ransom of 75 bitcoin, then worth about $4.4 million — and the decryptor it bought ran so slowly that restoration leaned on Colonial's own backups anyway. Blount confirmed the payment to the Wall Street Journal on 19 May: "I know that's a highly controversial decision," he said, but "it was the right thing to do for the country." How the attackers entered emerged in June, when Mandiant told Congress that the earliest evidence of compromise was a 29 April login to a legacy VPN profile — no multi-factor authentication, and a password that had already surfaced in a leaked batch elsewhere.
DarkSide spent the rest of the week discovering what it had done. On 10 May the gang posted a statement describing itself as "apolitical" and insisting its goal was "to make money, and not creating problems for society". The same week, one of its affiliates reportedly collected a separate $4.4 million from the chemicals distributor Brenntag — a figure drawn from the negotiation chats, which the company never confirmed. On 13 May the operators told affiliates they had lost access to their blog and payment servers and were closing under American pressure — an exit researchers immediately read as a rebrand in waiting. Washington moved regardless: Executive Order 14028, signed 12 May, rewrote federal software-security rules, and on 27 May the TSA ordered pipeline operators to report incidents to CISA within 12 hours.
Ireland pulls the plug on itself
At 4am on Friday 14 May, Ireland's Health Service Executive was alerted to Conti ransomware detonating across its network, and made the hardest call available: it switched off its own national IT systems, everywhere, to stop the spread. Hospitals reverted to paper. Outpatient and radiology appointments were cancelled wholesale, radiotherapy was interrupted for 513 cancer patients, and the COVID-19 test referral system went offline mid-pandemic. The same attackers had tried Ireland's Department of Health the day before, and been stopped. Their demand — close to $20 million, a figure that comes from the criminals' own negotiation chat, not the state — was refused; the Taoiseach said no ransom would be paid. On 20 May the gang handed over a working decryption key anyway, while still threatening to sell patient data, and Dublin's High Court granted an injunction against sharing it. By 28 May the HSE had confirmed records of 520 patients had appeared online. PwC's review later traced everything to a phishing email opened on 18 March — eight weeks of quiet access. Restoration ran into September; costs passed €100 million and kept climbing.
A $40 million receipt
The month's quietest story carried its biggest number. On 20 May, Bloomberg reported that CNA Financial — one of the largest commercial insurers in the United States, and itself a seller of cyber cover — had paid $40 million at the end of March to regain control of its network after an attack detected on 21 March. The figure comes from people familiar with the negotiation, not from the company: CNA declined to discuss the ransom, saying only that it had followed the law, consulted the FBI, and heeded the US Treasury's ransomware guidance. The malware, Phoenix Locker, was assessed by researchers as a descendant of Hades, code linked to the sanctioned Russian group Evil Corp — which is exactly why the sanctions question hung over the payment. If the reporting is right, it was the largest ransom ever disclosed at the time, roughly nine times what Colonial paid that same spring. The insurance industry could read its own actuarial tables: in early May, AXA had announced it would stop reimbursing ransom payments under new policies in France.
Ten years of passengers, one supplier
On 21 May, Air India finally put numbers on something passengers had known only in outline since March: the breach of SITA, the Geneva-based provider that processed the airline's passenger data, had exposed the records of around 4.5 million Air India passengers, registered over nearly a decade from August 2011 to February 2021. The fields ran from names, dates of birth and contact details to passport numbers, ticket data and frequent-flyer records, plus some payment-card data — though not CVV numbers, which SITA did not hold. SITA had disclosed the incident in early March and Air India had issued a brief first notice within weeks; the full accounting took almost three months. The airline said the affected servers had been secured, that it had found no evidence of misuse, and advised passengers to change passwords all the same.
The same week showed what exposure looks like once it stops being abstract. On 22 May, the security researcher Rajshekhar Rajaharia reported that data from the Domino's India breach — a claimed 13 terabytes covering some 18 crore orders — had been put behind a purpose-built search engine on the dark web: type in a phone number, and out came names, addresses and the GPS coordinates of past deliveries. Alon Gal of Hudson Rock had flagged the same dataset for sale a month earlier. Jubilant FoodWorks, the franchise's operator, acknowledged an information-security incident but denied that financial data was involved, saying it does not store card details; the seller's claim of a million card records was never verified. Order history, it turned out, is location history — and in May 2021 India had no data protection law to say so.
LaMDA, MUM and a quiet new laboratory
At its I/O conference on 18 May 2021, Google introduced LaMDA, a conversational model trained on dialogue, and demonstrated it by having the system field questions in the persona of Pluto, then of a paper aeroplane. Alongside it came MUM, a multimodal model Google said was trained across more than 75 languages and built for complex, multi-part queries — both pitched as futures for Search and Assistant rather than as shipping products. A week later, on 25 May, Microsoft announced its first product feature built on OpenAI's GPT-3, turning plain English into working Power Fx formulas inside Power Apps. And on 28 May a new laboratory surfaced: Anthropic, founded by the siblings Dario and Daniela Amodei with other former OpenAI researchers, announcing a $124 million Series A led by the Skype co-founder Jaan Tallinn and a research mission built around safety. LaMDA went on to make stranger headlines — the June 2022 edition covers the engineer who declared it sentient — while the quiet newcomer grew into one of the field's principal laboratories.
Codecov's fallout reaches Rapid7
The defenders spent the month learning the supply-chain lesson first-hand. On 13 May 2021, Rapid7 disclosed that the compromise of Codecov's Bash Uploader — a code-coverage script found altered in April — had reached its own estate: attackers accessed a small subset of source-code repositories holding internal tooling for its managed detection and response service, along with some internal credentials, all since rotated, and alert-related data for a subset of MDR customers, each of them notified. The script had run on a single CI server; one trusted tool proved enough. Consolidation continued regardless: Cisco announced on 14 May that it would buy Kenna Security, folding risk-based vulnerability management into its SecureX platform. And the month's frankest assessment of endpoint security came from Cupertino, where Craig Federighi told the Epic Games trial on 19 May that there was "a level of malware on the Mac that we don't find acceptable". Rapid7's plain, early disclosure aged well — the pattern of trusted tooling as a way in aged rather worse, recurring for the rest of the decade.
⏳ Time capsule — May 2021
- An 11-day conflict between Israel and Hamas ended when an Egyptian-brokered ceasefire took effect on 21 May.
- Måneskin won the Eurovision Song Contest for Italy in Rotterdam on 22 May — the country's first victory in 31 years.
- Belarus forced Ryanair Flight 4978 to land in Minsk on 23 May and arrested the dissident journalist Roman Protasevich.
- Bitcoin fell roughly 30% in a single day on 19 May, dropping to about $30,000, days after Tesla stopped accepting it over environmental concerns.
The month it reached the kitchen table
May 2021 is the month ransomware acquired a reference image — a queue of cars, a plastic bag of petrol — and the policy response that image made possible. Executive Order 14028 seeded the software-security requirements US agencies still buy under; the TSA's emergency directive became the template for regulating critical infrastructure by decree. DarkSide's "shutdown" proved to be the rebrand researchers predicted: BlackMatter within months, then ALPHV/BlackCat, whose 2024 attack on Change Healthcare — the month American healthcare stopped getting paid, covered elsewhere in this archive — ended in an exit scam that made DarkSide's look genteel. And Conti, which had switched off a nation's health service, imploded a year later, its own chat logs leaked after it sided with Russia's invasion of Ukraine.
The ledger closed in ways nobody guessed that month. In June the US Justice Department clawed back 63.7 of Colonial's 75 bitcoin — the June edition tells that story — and recovery, exchange sanctions and payment bans entered the toolkit, until by 2025 Britain was proposing to bar its public sector from paying at all. Ireland's HSE spent years and well over €100 million rebuilding, and became the cautionary case study every health service now cites. Air India was handed to the Tata Group eight months after its disclosure; India got its data protection law in 2023. The Vault continues backwards from here, and May 2021 is the month the rest of the archive keeps pointing to.