CISA and Partners Urge Hardening Automatic Tank Gauge Systems
CISA and partner agencies warn that internet-exposed automatic tank gauge systems are being targeted and urge operators to lock them down, patch them, and monitor them.
Intelligence analysis by GPT-5.4 Mini
U.S. agencies say malicious cyber activity is hitting automatic tank gauge systems used across energy, chemical, food, agriculture, and transportation. Their message is simple: keep these systems off the public internet, strengthen credentials, and watch for tampering.
These tank monitors are like digital rulers and alarm bells for fuel and liquid tanks. If a thief breaks in online, they could change the readings or turn off the alarm, so the agencies want owners to lock the doors, change passwords, and keep watch.
Analysis
What CISA and partners found
CISA, the FBI, NSA, DOE, EPA, TSA, DOT, and USDA say they are aware of malicious cyber activity aimed at U.S.-based automatic tank gauge (ATG) systems. These devices are widely used in energy, chemical, food and agriculture, and transportation settings to remotely monitor tank conditions.
The agencies say the activity seen so far involves internet-exposed systems being compromised and then modified through command execution. The government has not attributed the activity to a nation-state or a named threat group.
How attackers could abuse ATG systems
The fact sheet says attackers may reach devices through authentication bypass, hardcoded credentials, OS command execution, SQL injection, and privilege escalation. If successful, they could change network settings, product identifiers, tank volumes, or pump controls. They could also create a denial-of-view condition for tank fill levels, or disable alerts that operators rely on to spot leaks and relay failures.
What operators should do
The guidance focuses on reducing exposure and tightening access. CISA and its partners recommend removing ATG systems from direct internet exposure, especially default serial ports and web interfaces. If remote access is needed, access should be restricted with a firewall, ACL, or VPN.
They also urge operators to replace default passwords immediately, use strong and unique credentials, and enable phishing-resistant multifactor authentication where possible. Where feasible, owners should work with certified service providers to verify configurations, update software, and apply manufacturer patches.
Finally, the agencies want organizations to monitor logs for suspicious access, unexpected alarms, threshold changes, tank label changes, and other modifications, then report suspected incidents to CISA. The overall message is defensive and practical: reduce exposure, harden access, and watch closely for signs of tampering.
Key points
- U.S. agencies say malicious cyber activity is targeting internet-exposed automatic tank gauge systems.
- ATG systems are used to monitor tank levels, temperature, and potential leaks across several critical sectors.
- The guidance warns attackers could change settings, suppress alerts, or cause a denial of view for tank levels.
- The main fixes are to remove public internet exposure, change default passwords, patch systems, and monitor logs.
- Operators are told to report suspicious activity to CISA and work with service providers on hardening.
If operators follow the guidance, many ATG systems should become much harder to reach and manipulate from the internet. Better passwords, tighter access, and logging could help teams catch problems earlier and reduce the chance of leaks or outages.
If exposed systems are left online with weak or default credentials, attackers may continue to find them and alter device settings. That could hide real tank conditions, disable alerts, or create safety and environmental risks before anyone notices.



