# Cyberattackers Targeting Fuel Tank Gauges at US Gas Stations and Industrial Sites


A coordinated warning from eight federal agencies reveals an active campaign exploiting vulnerable automatic tank gauge systems—equipment that monitors everything from fuel to hazardous chemicals. The threat is straightforward: compromise these systems and you can manipulate readings, disable safety alerts, or disrupt supply chains from a remote connection.


## The Threat: What Tank Gauges Do and Why They Matter


Automatic tank gauges (ATGs) are simple in concept but critical in function. These electronic monitoring systems sit atop storage tanks at gas stations, chemical plants, and industrial facilities. Sensors measure liquid levels and feed data to displays and broader control systems—allowing operators to track inventory, detect leaks, and identify abnormal conditions without physically checking tanks.


The simplicity of ATGs is also their weakness. Many models were designed decades ago when internet connectivity wasn't a primary concern. Today, operators often expose these devices to remote access for convenience—allowing technicians to check readings from offices or enabling remote diagnostics from vendors.


This week, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), Department of Energy (DoE), Environmental Protection Agency (EPA), Transportation Security Administration (TSA), Department of Transportation (DOT), and US Department of Agriculture (USDA) issued a joint notice warning organizations about "active malicious cyber activity" targeting ATG systems across the country. The agencies provided no attribution but referenced concerns about unauthorized access, altered readings, and disabled safety functions.


## Background and Context: A Known but Neglected Vulnerability


Automatic tank gauges have been security afterthoughts in critical infrastructure. The systems predate modern cybersecurity standards and often lack basic hardening: default credentials, unpatched firmware, and unencrypted communications are common. Because ATGs are typically air-gapped or low-priority compared to operational technology networks, they've received minimal attention from defenders.


Last month, security researchers published reports linking gas station attacks in multiple states to threat actors with suspected connections to Iran. The targeting pattern suggested reconnaissance activity—attackers probing defenses to identify which facilities use exposed ATG systems. The volume and coordination raised red flags with federal agencies, prompting this week's public warning.


The timing is significant. Supply chain disruptions, fuel price volatility, and regional power shortages have already strained energy infrastructure. A coordinated campaign targeting tank monitoring systems could amplify these pressures by creating visibility gaps, causing operational confusion, or triggering unwarranted evacuations.


## Technical Details: How the Attacks Work


ATG systems communicate over networks using older protocols—Modbus, DNP3, and proprietary vendor schemes—many of which transmit data without encryption or authentication. Attackers exploit this by:


  • Scanning for exposed devices: Public internet-scanning tools like Shodan identify ATG systems with open ports and default web interfaces
  • Accessing unpatched firmware: Vendors release security updates infrequently; many deployed systems run versions years out of date
  • Leveraging default credentials: Technician accounts and maintenance logins often use unchanging default passwords
  • Manipulating readings: Once authenticated, attackers can send commands to falsify tank levels, trigger false alarms, or disable sensor inputs

  • The consequences extend beyond false inventory counts. Consider a fuel distribution terminal: if attackers alter pump control settings, they could redirect product to unauthorized destinations. At a chemical facility, disabled leak alerts could allow dangerous conditions to develop undetected. In the worst case, compromised safety interlocks could create conditions for spills, fires, or explosions.


    One critical weakness: many facilities don't monitor ATG networks for anomalous traffic. Attackers can often operate undetected for weeks, gathering data on system architecture and control parameters before executing an attack.


    ## Who's at Risk


    The threat affects a broad range of targets:


    | Sector | Primary Risk |

    |--------|--------------|

    | Fuel Distribution | Pump manipulation, product diversion, supply disruption |

    | Chemical Manufacturing | Leak alerts disabled, tank overflow, contamination |

    | Utilities | Water system disruption, hazardous chemical exposure |

    | Agriculture | Fertilizer and pesticide tank compromise |

    | Transportation | Refueling infrastructure compromise |


    Geographically, the current campaign appears concentrated in the US, but the underlying vulnerabilities are global. Any facility using internet-exposed ATGs is potentially exposed.


    ## Implications for Defenders


    Successful ATG compromise creates several operational nightmares:


    Visibility Loss: Operators lose accurate tank readings, forcing manual inventory counts and creating uncertainty about supply levels.


    Safety Degradation: Disabled alerts for abnormal tank conditions—unusual pressure, temperature, or level changes—could allow dangerous situations to develop undetected.


    Supply Chain Disruption: False readings or pump manipulation could misdirect shipments, create billing disputes, and interrupt fuel supply chains.


    Regulatory Exposure: Operators are responsible for maintaining safety systems. Compromised equipment could trigger EPA or OSHA investigations.


    Geopolitical Risk: Attribution to state-linked actors raises questions about whether this is reconnaissance for a larger operational campaign.


    ## Federal Response and Defender Recommendations


    The joint agency notice recommends immediate steps:


  • Audit network architecture: Identify all ATG systems and map their network connections. Determine which systems have direct internet access.
  • Implement segmentation: Place ATG systems on isolated networks with strict egress controls. Require VPN or air-gapping for remote access.
  • Update firmware: Deploy vendor patches immediately. If patches are unavailable, escalate with vendors or consider system replacement.
  • Change default credentials: Replace all default usernames and passwords with strong, unique credentials.
  • Monitor for anomalies: Log all ATG access and commands. Alert on unusual traffic patterns, failed authentication attempts, or unexpected configuration changes.
  • Require authentication: Disable anonymous access. Implement multi-factor authentication for remote connections.
  • Encrypt communications: Upgrade to encrypted protocols where possible, or use VPN tunnels to encrypt traffic between remote and local systems.

  • ## HackWire Analysis


    This campaign represents a significant escalation in targeting critical infrastructure components that defenders typically overlook. ATGs occupy an awkward position in facility security: too specialized for IT teams to understand, too low-profile for operational technology (OT) teams to prioritize. That gap is exactly where attackers are operating.


    What makes this campaign particularly concerning is the breadth of federal coordination in responding. When CISA, FBI, NSA, DoE, EPA, TSA, DOT, and USDA all sign a joint notice, it signals genuine alarm—these agencies don't typically coordinate on isolated incidents. The fact that they're warning publicly suggests the campaign is either widespread enough to demand transparency or sophisticated enough to warrant preemption.


    The pattern also fits a larger strategic picture. Iran-linked threat actors have consistently invested in reconnaissance of US critical infrastructure over the past three years, with particular focus on energy and transportation systems. ATG compromise is valuable reconnaissance—it reveals facility layouts, operator procedures, and network architecture that could inform larger attacks on SCADA systems, control logic, or distribution infrastructure.


    For defenders, the immediate risk is operational disruption rather than catastrophic failure. An attacker with ATG access can create confusion, trigger evacuations, or redirect fuel shipments—all disruptive but not immediately lethal. However, the same access point could be used to gather intelligence for a subsequent, more damaging attack on core control systems.


    Organizations should treat this warning as time-sensitive. The fact that federal agencies are calling out specific threat activity suggests attackers have already been successful at some facilities. If your organization operates industrial tanks of any kind—fuel, chemicals, water, or other liquids—treating ATG security as optional is now a known risk that regulators and plaintiffs' attorneys will certainly examine if something goes wrong.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)