As much as I would wife the shit out of Boebert, I think she needs to stfu about that one. That's not how the internet works, Lauren.Originally Posted by dilbert firestorm
This wasn't even a targeted attack, it was a wide net campaign that just happened to hook a big fish:

Since the specific make/model of the ransomware was a known quantity, I'll make a personal guess that the infection was sourced from someone falling for a phishing campaign that came through their personal email which they were checking via a work machine, unless Colonial's systems are literally decades (plural) behind.
Though I do question the logic of shutting down industrial control systems over a ransomware attack. ICS is a very specialized subset of computing that not many attackers are versed in, and it's unlikely the software used would would meaningfully impact it. Rather, I think the hardest impact is on logistical systems that handle routing and accounting.