# Iranian Hackers Target US Fuel Infrastructure: ATG System Breaches Signal Expanding Cyber Campaign


Threat actors operating from Iran have successfully compromised automatic tank gauge (ATG) systems monitoring fuel supplies at gas stations across the United States, according to sources familiar with the incident. The breaches demonstrate Iran's persistent focus on critical infrastructure vulnerabilities and underscore a decade-long warning from cybersecurity experts that poorly secured fuel management systems represent a significant national security risk.


## The Incident: What Happened


Iranian-linked attackers exploited ATG systems that were exposed directly to the internet without adequate password protections, enabling them to access and manipulate fuel tank monitoring displays at multiple locations serving gas stations nationwide. The attackers altered the digital readings displayed by these systems, changing what appeared on the gauge displays to show different fuel levels than what was actually present in the tanks.


However, the scope of the attack remained limited in immediate impact: the attackers were able to change the display readings but did not gain access to the actual fuel supply mechanisms themselves. No fuel was reported missing or diverted, and no operational disruption occurred at the affected gas stations during the incident.


The breaches were publicly disclosed Friday in a report citing multiple sources with knowledge of the intrusions. While a definitive forensic attribution remains challenging, investigators believe the attacks align with Iran's established pattern of targeting critical energy infrastructure, particularly fuel systems.


## Background: A Year of Rising Tensions


Understanding this incident requires examining the geopolitical context. The United States and Israel remain engaged in an ongoing conflict with Iran that has periodically escalated over the past year. While active military operations are currently on pause due to a fragile ceasefire arrangement, the underlying tensions remain acute.


A particularly significant factor: Iran orchestrated the closure of the Strait of Hormuz, a critical chokepoint through which approximately one-third of global maritime oil trade flows. This action represents a direct response to sanctions and military pressure. The closure has contributed to volatile oil prices that have climbed significantly higher than historical norms, creating economic ripple effects:


  • Global fuel costs have risen across shipping, aviation, and transportation industries
  • Supply chain disruptions have compounded inflationary pressures worldwide
  • Energy-dependent sectors face increased operational costs and margin pressures

  • In this context, Iranian cyber operations targeting US fuel infrastructure carry both tactical and strategic significance. Even failed or contained breaches send a message about Iran's capability and intent to disrupt American energy systems.


    ## Technical Details: How ATG Systems Work and Where They Fail


    Automatic tank gauge systems represent the nervous system of gas station operations. These devices continuously monitor:


  • Fuel inventory levels in underground storage tanks
  • Temperature and pressure conditions
  • Fuel quality metrics
  • Alarm conditions (low inventory, overfill risks, equipment malfunction)

  • Traditional ATG systems were designed primarily for local area network (LAN) operation, with readings accessible to station managers through closed systems. However, as operational technology has modernized and remote management capabilities have become standard, many ATG systems have been connected to the public internet to enable:


  • Centralized monitoring across multiple locations
  • Automated inventory management and reporting
  • Predictive maintenance alerts
  • Real-time supply chain coordination

  • The vulnerability lies in legacy security practices. Many ATG systems:


  • Operate with default or weak password protections
  • Lack encryption for data in transit
  • Feature minimal or no multi-factor authentication
  • Were deployed years ago before security became a design priority
  • Are managed by third-party vendors who may not prioritize security updates

  • The ability to alter display readings, even without access to the fuel itself, creates operational chaos—a primary objective of infrastructure attacks.


    ## A Warning Ignored: The Decade-Long Vulnerability


    This is not the first warning about ATG vulnerabilities. For more than ten years, cybersecurity researchers have documented the risks posed by internet-connected fuel tank systems.


    Most notably, last year's RSA Conference 2025 included a dedicated session analyzing the cascading effects of potential ATG attacks. Security researchers demonstrated that a sophisticated attacker controlling ATG systems could:


  • Trigger false inventory alerts that disrupt supply logistics
  • Create display inconsistencies that confuse automated ordering systems
  • Manipulate readings to initiate unnecessary emergency procedures
  • Cascade disruption across interconnected fuel distribution networks

  • These aren't hypothetical concerns—they're documented technical capabilities that translate into real operational consequences for fuel distribution.


    ## Iran's Cyber Capabilities and Track Record


    Iran has invested significantly in developing cyber warfare capabilities and has demonstrated consistent interest in targeting critical infrastructure. Notable historical incidents include:


    | Year | Target | Attack Type | Outcome |

    |------|--------|------------|---------|

    | 2010 | Nuclear enrichment facilities | Stuxnet malware | Disrupted centrifuge operations |

    | 2012 | Oil and gas sector | DDoS attacks | Website defacements, service disruptions |

    | 2019 | Aerospace and defense | Credential theft | Network reconnaissance |

    | 2023-2026 | Energy infrastructure | Network penetration | Ongoing reconnaissance and access |


    The Iranian government has framed cyber operations as a legitimate response to sanctions and military threats. Recent operations show increasing sophistication in targeting critical infrastructure that supports national economies.


    ## Implications for the Energy Sector


    This incident carries several important implications:


    Operational Risk: Energy companies managing distributed networks of fuel storage and distribution points face the reality that legacy infrastructure remains vulnerable. Even "contained" breaches that don't result in fuel loss can disrupt operations through false readings and triggered alarms.


    Supply Chain Vulnerability: Gas stations, truck stops, and fuel distribution centers operate on thin margins with just-in-time inventory practices. Manipulated tank readings could trigger cascading logistical failures across regional or national supply chains.


    Escalation Potential: While current breaches involved display manipulation, they prove that Iranian threat actors can penetrate fuel infrastructure defenses. Future attacks could target more critical control systems or attempt destructive payload deployment.


    Defensive Gaps: The widespread existence of exposed, poorly-secured ATG systems suggests inadequate security assessment and remediation across the fuel distribution sector.


    ## Recommendations for Organizations


    Energy companies and fuel distributors should implement immediate defensive measures:


  • Conduct a complete inventory of all internet-connected ATG systems and related SCADA equipment
  • Isolate ATG systems from the public internet whenever possible; use VPN or private network access instead
  • Enforce strong authentication across all monitoring platforms, including multi-factor authentication
  • Update firmware and software on all ATG devices to the latest available versions
  • Monitor for unauthorized access and implement real-time alerting for anomalous system behavior
  • Segment networks to prevent compromised ATG systems from providing entry points to critical operational technology
  • Conduct security assessments with qualified ICS/OT security specialists familiar with fuel infrastructure

  • ## HackWire Analysis


    This incident represents a significant turning point in how we should view attacks on fuel infrastructure. For a decade, security researchers have warned about ATG vulnerabilities in academic papers and conference presentations. Those warnings were absorbed by a thin layer of security professionals but largely ignored by the energy industry at large. Now, a nation-state has demonstrated working capability against these systems—and the response hasn't been a massive industry mobilization, but rather scattered reporting and limited immediate action.


    What makes this particularly concerning is the *timing*. Iran's closure of the Strait of Hormuz has already disrupted global oil markets. Economic damage from that geopolitical move is already flowing through supply chains and price mechanisms. A sustained cyber campaign against US fuel infrastructure—even one that "only" manipulates readings—could amplify that economic impact by creating localized distribution chaos, triggering unnecessary supply chain acceleration, or forcing fuel refiners and distributors into costly emergency procedures.


    The real danger isn't that attackers will drain fuel tanks remotely. It's that they'll make fuel distribution systems *behave* unreliably enough to create cascading logistical failures. A fuel company trusting automated readings that are being spoofed by an attacker might over-order at some locations and under-supply at others, creating artificial shortages and excess inventory simultaneously. In a sector with razor-thin margins and just-in-time logistics, that kind of chaos translates directly into costs for consumers and competitive disadvantage for unprepared operators.


    The window to remediate this vulnerability is closing. The sector needs to treat ATG system exposure with the same urgency it would a confirmed fuel loss—because the geopolitical conditions that make Iran a credible threat are not improving.


    — HackWire Editorial


    ## Recommendations for Defenders


    Organizations across the fuel and energy sectors should prioritize:


    1. Immediate vulnerability assessment of all publicly accessible industrial control systems

    2. Network segmentation to isolate critical infrastructure from internet-facing systems

    3. Enhanced monitoring and logging to detect unauthorized access or system modifications

    4. Incident response planning specific to ICS/OT environments

    5. Information sharing with CISA and sector-specific ISACs to improve collective defense


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Critical Infrastructure](https://www.hackwire.news/category/critical-infrastructure)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)