US recovers $2.3M of ransom paid to Colonial Pipeline hackers

Feds vow to ‘target the entire ransomware ecosystem’ as they seize $2.3M in bitcoin

A gas station in Florida amid the fuel shortages brought on by the ransomware attack on Colonial Pipeline. (Photo: Hayden Dunsel/Shutterstock)

The U.S. Department of Justice has seized $2.3 million worth of Bitcoin paid to the hackers behind the cyberattack that led to the shutdown of Colonial Pipeline in May, federal officials announced on Monday. 

The FBI recovered 63.7 bitcoins that had been paid to members of the DarkSide ransomware gang after a federal judge signed a seizure order. 

“Ransom payments are the fuel that propels the digital extortion engine, and today’s announcement demonstrates that the United States will use all available tools to make these attacks more costly and less profitable for criminal enterprises,” Deputy Attorney General Lisa Monaco said in a statement. “We will continue to target the entire ransomware ecosystem to disrupt and deter these attacks.”

The recovery reflected the increasingly aggressive response of the U.S. government in the face of high-profile ransomware attacks whose impacts have hit wide swaths of the economy, including the transportation and logistics sector. 

The Colonial attack, which shut down the largest source of fuel on the East Coast, came weeks before cybercriminals hit meat processing giant JBS, shutting down multiple plants across the country. 

In a departure from past attacks, the FBI also publicly named the hacking gangs responsible while U.S. officials have publicly likened the threat of ransomware to terrorism. Meanwhile, President Joe Biden is planning to confront Russian President Vladimir Putin on the proliferation of attacks attributed to criminal organizations based in Russia and the region.

The U.S. government has long discouraged companies from paying hackers’ ransom demands, arguing that the stream of money enables the criminals. But victims frequently agree to the payments, particularly when faced with costly operational downtime.  

But in recovering the Colonial payment, which accounted for 85% of the total ransom, federal authorities have now demonstrated the means to deny hackers the proceeds of their crime. 

“We will also continue developing advanced methods to improve our ability to track and recover digital ransom payments,” said Stephanie Hinds, acting U.S. attorney for the Northern District of California.

Click for more FreightWaves articles by Nate Tabak

Upcoming FreightWaves Events
AI

Supply Chain AI Symposium

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

July 15, 2026
The Old Post • Chicago, IL
Register Now
Rail

Future of Rail Symposium

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

July 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga TN
Register Now
FreightTech

F3: Future of Freight Festival

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

October 27, 2026 – October 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
AI Supply Chain AI Symposium Jul 15 • The Old Post • Chicago, IL

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

The Old Post • Chicago, IL Register Now
Rail Future of Rail Symposium Jul 28 • The Signal at Chattanooga Choo Choo • Chattanooga TN

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

The Signal at Chattanooga Choo Choo • Chattanooga TN Register Now
FreightTech F3: Future of Freight Festival Oct 27 – Oct 28 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now

2 Comments

  1. Maria Bennett

    I must say that i had a tough time online during the process of trying to get access to my spouse iPhone 12 pro max, i got scammed along the process so i needed two job now and that’s how to get my funds back and also get access to my spouse mobile, It all ended well with the help of wizardhary AT programmer DOT net who i also whatsapp +1 (807-808) 6168, you can reach him today and have your funds recovered within 16 hours to 24 hours.
    I’m Maria Bennett from South Carolina, Wizard Harry saved my life by helping to recover my funds back, that was my house rent money

Comments are closed.