CISA warns of cyberattacks targeting fuel tank monitoring systems
US agencies warn that internet-exposed fuel tank monitoring systems are being compromised and changed remotely. CISA says operators should pull them off the internet and harden access.
Intelligence analysis by GPT-5.4 Mini

CISA, the FBI, the NSA, the Department of Energy, and other US partners say attackers are targeting exposed automatic tank gauge systems used across critical infrastructure. The agencies say the intrusions can change settings, hide alerts, and raise the risk of leaks or equipment failures.
Officials say some fuel-monitoring machines on the internet are being broken into. It is like someone sneaking into a building’s control room and changing the fuel gauge or turning off the alarm, which could hide a leak or other danger.
Analysis
What the agencies are warning about
CISA and several US government partners say hackers are targeting internet-exposed automatic tank gauge (ATG) systems. These systems are used in sectors including Energy, Chemical, Food and Agriculture, and Transportation to remotely track tank levels, temperatures, and leaks.
What attackers can do
According to the advisory, malicious actors have been able to compromise exposed ATG devices and change them through command execution. The entry paths named by the agencies include authentication bypass flaws, hardcoded credentials, command-execution bugs, SQL injection, and privilege-escalation weaknesses. Once inside, attackers may be able to alter network settings, product identifiers, tank volumes, and pump controls. They can also disable alerts, which could keep operators from seeing unsafe fill levels.
Why the risk is serious
The article says the immediate concern is not just false readings but operational safety. If alerts are turned off or values are manipulated, operators may miss leaks or other failures until damage is already done. The agencies are urging organizations to remove ATG systems from direct internet exposure, restrict remote access through firewalls, VPNs, or access control lists, replace default passwords, use strong credentials and multifactor authentication, apply updates, and watch for unauthorized changes.
Context from prior reporting
The piece notes that CNN reported in May that Iranian hackers were suspected in similar intrusions at gas stations in multiple states. But the government advisory itself does not assign blame, and the article says forensic evidence may be too limited to pin the activity on a specific group.
Key points
- CISA and several US agencies say attackers are targeting internet-exposed automatic tank gauge systems.
- The systems are used to monitor fuel and liquid storage in multiple critical infrastructure sectors.
- Attackers may be able to change settings, alter readings, and disable alerts after compromising a device.
- The agencies recommend removing these systems from the internet and hardening remote access immediately.
- The article cites earlier reporting that Iranian hackers may have been behind similar incidents, but the government has not attributed the current activity.
If operators follow the guidance quickly, they can reduce exposure by taking ATG systems off the internet and tightening access. That would make it much harder for attackers to change readings or disable alerts.
If exposed systems stay online with weak passwords or known flaws, attackers could keep finding them and tamper with tank data. False readings and missing alerts could increase the chance of leaks, unsafe fills, or equipment failures.



