2021 was the year ransomware stopped being an IT problem and started being a business continuity and public safety problem. Ransomware itself had also evolved into a service industry of its own: rather than one group building and operating every attack, ransomware-as-a-service arrangements let developers license their tools to affiliates who carried out the actual intrusions, splitting the payout. That model, combined with double extortion (encrypting a victim’s systems and threatening to leak stolen data even if the ransom was paid), meant more actors could run large-scale attacks with less technical skill of their own. A look back at some of the year’s most significant incidents shows the range of what was at stake:
- Colonial Pipeline: an attack on a major US fuel pipeline operator forced the company to proactively shut down its own pipeline system as a precaution, since it couldn’t confirm the ransomware hadn’t spread into operational systems. That shutdown, not the attack itself, is what caused days of fuel shortages and panic buying across the Southeast and East Coast. The company paid a multi million dollar ransom in cryptocurrency to regain access, and the incident was significant enough that it helped drive a federal executive order tightening cybersecurity requirements for critical infrastructure operators.
- JBS: the world’s largest meat processor paid millions after an attack shut down operations across several countries, including US beef and pork processing plants, disrupting a meaningful share of North America’s meat supply chain for several days until systems were restored.
- Microsoft Exchange Server: a set of previously unknown vulnerabilities in on-premises Exchange mail servers let attackers gain full administrative access to affected servers, initially used by a state-linked group for espionage before the flaws were rapidly copied and mass-exploited by other actors once they became public, ultimately affecting tens of thousands of organizations worldwide before patches caught up. It became a case study in how fast a single disclosed vulnerability can be weaponized at internet scale.
- CNA Insurance: one of the largest US insurers had its own network disrupted, including internal email and other business systems, forcing it to operate manually for a period while it rebuilt affected infrastructure, a reminder that even organizations whose entire business is assessing other people’s risk aren’t exempt from their own.
- Florida water treatment facility: attackers remotely accessed the plant’s control system and briefly attempted to raise chemical treatment levels to unsafe concentrations. A plant operator noticed the unauthorized change happening in real time and reversed it before it reached the water supply, but the incident stands as one of the clearest public examples of a cyber intrusion reaching directly into physical safety rather than just data or IT systems.
- Acer, Bombardier, Accellion, a Scottish university, and an Australian broadcaster rounded out a year where ransom payments, supply chain compromises, and operational shutdowns hit organizations of every size and sector, spanning manufacturing, aviation, higher education, and media.
The throughline across all of these: attackers increasingly went after the systems and vendors an organization depends on to function, not just the data it stores. A pipeline company, a meat processor, and a water treatment facility don’t hold especially attractive data by breach standards, but each one runs infrastructure that has no acceptable downtime, which makes them exactly the kind of target that can pay a ransom quickly just to get moving again. That same logic extends to the supply chain incidents on this list: compromising one shared vendor or piece of software can reach dozens of downstream organizations that never had a direct relationship with the attacker at all.
For an IT Director, the lesson isn’t that any one of these specific incidents will repeat exactly. It’s that the categories they represent, operational technology that can’t tolerate downtime, widely used enterprise software with a single point of failure, and vendors who sit in the middle of a supply chain, are permanent categories of risk, not one-off headlines. That’s the same reasoning behind why incident response and tested recovery plans matter as much as prevention, because at this scale, some of these organizations were always going to be targeted eventually, and the difference between a bad week and a bad year came down to how fast and how cleanly they could respond once it happened.
Related reading: A Wake-Up Call for Critical Infrastructure Security