Key Judgments
- [CONFIRMED] – US pipeline infrastructure spans more than 2.7 million miles carrying natural gas, oil, and other hazardous liquids, regulated under a structure that splits authority between the Transportation Security Administration (physical and cybersecurity oversight, via a May 2021 security directive) and the Federal Energy Regulatory Commission (economic regulation, with cybersecurity rulemaking authority only recently proposed) – an arrangement this dossier assesses reflects pipelines’ historical classification as a transportation and economic asset rather than critical digital infrastructure, a classification the sector’s actual risk profile has outgrown.
- [CONFIRMED] – The May 2021 Colonial Pipeline ransomware attack – which forced a precautionary full shutdown of the 5,500-mile system carrying 45% of the East Coast’s gasoline, diesel, and jet fuel – remains the reference case shaping pipeline cybersecurity policy five years later, despite the attack having compromised Colonial’s business network rather than its operational technology directly; the company shut down proactively out of uncertainty about the intrusion’s scope.
- [CONFIRMED] – CISA and the FBI jointly confirmed in 2021 that a Chinese state-sponsored spear-phishing campaign, active from 2011 to 2013, had compromised 13 of 23 targeted US natural gas pipeline operators, with three more nearly compromised and seven unaware of the intrusion’s extent until notified. The agencies assessed the campaign’s objective as developing “cyberattack capabilities against US pipelines to physically damage pipelines or disrupt pipeline operations” – not conventional espionage or data theft.
- [CONFIRMED] – This series’ prior Volt Typhoon findings extend into the pipeline sector specifically: Canadian and UK authorities have separately warned the group may have held access to critical infrastructure systems, potentially including pipeline operators, for as long as five years, and a 2019 Office of the Director of National Intelligence threat assessment concluded China has the capability to disrupt US natural gas pipelines for periods of “up to several weeks.”
- [ASSESSED] – CommandEleven Intelligence assesses natural gas infrastructure carries a compounding vulnerability this series’ other sectors do not share to the same degree: it is both a target in its own right and a critical input to the electricity grid examined in this series’ prior installment, since gas-fired generation supplies a substantial share of US electricity – meaning a successful pipeline disruption carries a realistic secondary cascading risk into grid stability that this dossier’s prior sector-by-sector approach must account for explicitly rather than treating each sector as fully independent.
The Threat Surface: Vast Network, Split Oversight
The natural gas pipeline network’s regulatory structure is itself a notable vulnerability. Unlike the electrical grid, where NERC’s Critical Infrastructure Protection standards impose mandatory, audited cybersecurity requirements, pipeline cybersecurity oversight sits primarily with the TSA – an agency whose core mission and institutional expertise is transportation security, not industrial control systems or energy infrastructure. This is a legacy of pipelines’ historical regulatory classification as a transportation and economic asset; TSA’s authority in this space traces to a security directive issued only in May 2021, in direct response to the Colonial Pipeline attack examined in Section II, rather than to a longer-standing, purpose-built cybersecurity framework. FERC has more recently proposed its own cybersecurity rulemaking specifically for gas pipelines and gas-fired generation facilities, but this dossier’s sourcing does not indicate that rulemaking has been finalized as binding as of this writing. The Interstate Natural Gas Association of America, representing 26 midstream companies operating roughly 200,000 miles of pipeline, has characterized the China-linked threat specifically as real but not currently accelerating – a measured industry position worth noting alongside the federal warnings examined below, which trend more urgent.
The Landmark Case: Colonial Pipeline
No single incident has shaped pipeline security policy as thoroughly as the May 2021 Colonial Pipeline attack, and it remains the reference case cited in congressional commentary as recently as April 2026. The ransomware group DarkSide compromised Colonial’s business network – not its operational technology controlling the physical pipeline – but Colonial shut down its entire 5,500-mile system out of precaution, uncertain how far the intrusion had spread. The consequences were immediate and visible: the pipeline carries roughly 45% of the gasoline, diesel, and jet fuel consumed on the East Coast, and the shutdown produced fuel shortages and price spikes across the region within days. The Georgetown Environmental Law Review has characterized the episode as a pipeline-sector “Pearl Harbor moment” – the incident that converted pipeline cybersecurity from a specialist concern into a mainstream policy priority, directly producing the TSA security directive examined.
- [ASSESSED] – This dossier assesses the Colonial Pipeline case illustrates an important distinction relevant to every sector in this series: catastrophic real-world disruption does not require an attacker to actually compromise operational technology. A business-network intrusion alone, combined with reasonable operator caution about the intrusion’s scope, was sufficient to take a system carrying nearly half the East Coast’s refined fuel supply offline.
The China Dimension: A Decade of Warnings

Natural gas pipelines have faced sustained, specifically-documented Chinese state-sponsored targeting longer than this series’ other sectors. CISA and the FBI jointly confirmed in 2021 that a spear-phishing campaign running from 2011 to 2013 had targeted 23 US natural gas pipeline operators, confirming 13 compromises, three near-compromises, and seven operators who remained unaware of the intrusion’s full extent until federal notification years later. Critically, the agencies’ own assessment of the campaign’s purpose was not conventional espionage: the stated objective was developing capability “to physically damage pipelines or disrupt pipeline operations” – a pre-positioning logic directly consistent with FBI Director Wray’s later characterization of Volt Typhoon’s objective against the electrical grid, examined in this series’ prior installment.
That consistency extends forward: this series’ Volt Typhoon findings are not confined to electric utilities. Canadian and UK authorities have separately warned the group may have held access to critical infrastructure systems – potentially including pipeline operators – for as long as five years, and a 2019 ODNI threat assessment concluded China retains the capability to disrupt US natural gas pipelines for “up to several weeks” in a serious crisis scenario. This dossier assesses natural gas has been a documented, sustained Chinese state-sponsored target for over a decade, with the strategic logic – pre-positioning for disruption during a future crisis, not day-to-day sabotage – remaining consistent across that entire period.
The Grid Interdependency

Natural gas’s risk profile compounds with the electricity grid examined in this series’ prior installment in a way no other pairing of sectors in this series does as directly: gas-fired power plants supply a substantial share of total US electricity generation, meaning a successful pipeline disruption does not stay contained to gas-dependent end uses (home heating, industrial processes) but can cascade directly into grid stability.
- [ASSESSED] – This dossier assesses this interdependency is likely underweighted in public risk discussion relative to its actual significance – most public commentary examines pipeline security and grid security as separate questions, when a sufficiently severe and sustained pipeline disruption would functionally become a grid security event as gas-fired generation capacity came offline. This dossier does not have a specific quantified estimate of what scale or duration of pipeline disruption would be required to meaningfully affect grid stability, and flags that as a genuine analytical gap rather than asserting a specific threshold.
The Government Response
Federal response since Colonial Pipeline has been substantial but arguably still catching up to the sector’s actual risk profile. TSA’s May 2021 security directive requires pipeline operators to report cyber incidents to CISA and maintain an onsite cybersecurity coordinator – a meaningful baseline, but one imposed reactively rather than as a mature, purpose-built framework comparable to NERC CIP’s grid standards. FERC’s more recent proposed rulemaking specifically for gas pipelines and gas-fired generation represents an attempt to close that gap, though this dossier’s sourcing does not confirm finalization. DOE’s Cyber Testing for Resilient Industrial Control Systems program offers a voluntary partnership track for energy-sector manufacturers, separate from mandatory TSA/FERC requirements. Colonial Pipeline itself has since hired its first dedicated Chief Information Security Officer – a specific, verifiable post-incident reform this dossier notes as illustrative of the broader industry shift toward treating cybersecurity as a standing operational requirement rather than an occasional compliance exercise.
Assessment
[ASSESSED] – Natural gas infrastructure combines two characteristics this dossier assesses as particularly concerning in combination: a documented, decade-plus history of sustained Chinese state-sponsored targeting explicitly oriented toward physical disruption capability rather than espionage, and a regulatory framework that only began meaningfully addressing pipeline-specific cybersecurity in 2021, years after that targeting history had already been established. The sector’s interdependency with the electrical grid examined in this series’ prior installment means pipeline security cannot be fully evaluated in isolation – a genuinely severe pipeline event would not stay contained to the gas sector alone.
Series Continuity
The next installment in this series examines communications infrastructure – telecommunications and internet backbone systems that function both as a target in their own right and as the enabling layer for coordinated attacks across every other sector this series has examined, including the pipeline and grid control systems discussed here.
Sourcing Base (Confidence-Tiered, with Links)
CONFIRMED – Primary/Official Record & Direct Reporting:
- CISA, “Pipeline Cybersecurity Fact Sheet“
- CISA, “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years” (ODNI China capability assessment quote)
- Congressional Research Service, “Pipeline Cybersecurity: Federal Programs” (Congress.gov, R46903)
- Natural Gas Intelligence, “Is US Natural Gas Infrastructure a Target for Cyberattacks? FBI Director Puts Industry on High Alert” (23-operator campaign detail, INGAA statement, Volt Typhoon Canada/UK warning)
- US GAO, “Colonial Pipeline Cyberattack Highlights Need for Better Federal and Private-Sector Preparedness“
- Cybersecurity Dive, “How the Colonial Pipeline attack instilled urgency in cybersecurity“
ASSESSED – Credible Secondary Reporting:
- Washington Times, Rep. Randy Weber op-ed, “In the face of growing cyber threats, pipeline security must be a priority,” April 21, 2026
- Georgetown Environmental Law Review, “Cybersecurity Policy Responses to the Colonial Pipeline Ransomware Attack“
- S&P Global Commodity Insights, “Colonial attack highlights particular vulnerability of pipelines from cyber threats”
Excluded from this dossier: Specific technical detail on pipeline SCADA architecture or control-system exploitation methodology beyond what is necessary to establish the general vulnerability pattern. This dossier treats such detail as unsuitable for public release.
Protecting Your Household from Natural Gas Disruption: A $500 Baseline
This section is general emergency-preparedness guidance, modeled on standard FEMA and Ready.gov household-resilience recommendations. It is not specific to any threat actor or incident, and does not depend on or respond to classified or sensitive information.
- Alternative heating capacity (≈$150-250): For households relying on natural gas heat, an electric space heater (safe to use if grid power remains available) or, where appropriate for local climate and building type, an indoor-rated propane heater with proper ventilation, provides a fallback during a gas-supply disruption. Always follow manufacturer ventilation guidance – indoor combustion heating carries genuine carbon monoxide risk without it.
- Alternative cooking capacity (≈$40-75): A single-burner electric hot plate or an outdoor-only propane/butane camp stove covers basic cooking needs if gas service is interrupted. Never use an outdoor-rated stove indoors.
- Carbon monoxide detectors (≈$25-40 per unit): Essential if using any backup combustion-based heating or cooking equipment, and good practice regardless of any specific threat scenario.
- Know your utility’s outage/safety notification system: Gas utilities typically have a distinct emergency shutoff and leak-reporting process from electric utilities; knowing your specific provider’s procedure in advance costs nothing.
- A basic emergency plan: As with the water and electricity installments in this series, FEMA’s Ready.gov provides free household emergency-planning resources applicable across all utility-disruption scenarios.
CommandEleven Intelligence is not a licensed emergency-preparedness authority; this guidance reflects publicly available FEMA/Ready.gov recommendations and general good practice, not a CommandEleven Intelligence-specific assessment of any household’s individual risk.