Over 900 US gas station tank gauge systems exposed to attacks
More than 900 U.S. tank gauge systems are exposed online, and federal agencies say attackers are already exploiting them to change settings.
Intelligence analysis by GPT-5.4 Mini

CISA, the FBI, the NSA, the DOE, and partners warned that internet-exposed automatic tank gauge systems face active attacks. Shadowserver found 1,061 exposed systems, 909 of them in the U.S., and said attackers can target weak credentials and software flaws to alter behavior.
These tank monitors are like a fuel tank’s dashboard. If strangers get in, they can make the numbers lie and silence the alarms, which could hide leaks or break equipment.
Analysis
What happened
U.S. federal agencies issued a joint advisory warning that internet-facing automatic tank gauge (ATG) systems are being targeted in ongoing attacks. These devices are used to remotely monitor fuel, chemicals, and other liquids in storage tanks, including at gas stations and industrial sites.
The advisory says threat actors have been exploiting weaknesses such as hardcoded credentials, authentication bypasses, SQL injection, command execution flaws, and privilege escalation bugs. According to the agencies, recent malicious activity involved attackers compromising exposed ATG systems and then modifying them through command execution.
Why the exposure is serious
CISA warned that after a successful compromise, attackers could disable alerts and interfere with safety-related monitoring. That raises the risk of leaks, equipment failures, and potentially permanent damage to the tank systems themselves.
Shadowserver added urgency to the warning by saying it found 1,061 IPs associated with ATG systems online on June 5, 2026. It said 909 of those were in the United States, after removing devices that appeared to be honeypots. The group said it was scanning ATG systems on port 10001/tcp.
What defenders are being told to do
The advisory recommends keeping ATG systems off the public internet where possible and placing remote access behind firewalls, VPNs, or access control lists. It also calls for replacing default passwords, applying security updates, monitoring for unauthorized changes, and using multi-factor authentication where supported.
The article notes that this warning follows earlier reporting about suspected Iranian hackers breaching internet-connected ATG systems at U.S. gas stations. Those incidents reportedly changed display readings rather than actual fuel levels, but they still showed how exposed these systems can be when weak passwords or other flaws are left in place.
Key points
- Federal agencies warned that internet-exposed ATG systems are being actively targeted.
- Shadowserver said it found 1,061 exposed ATG IPs, including 909 in the United States.
- Attackers are said to abuse weak credentials and software flaws to modify system behavior.
- CISA warned that compromised systems could have alerts disabled, raising leak and damage risks.
- Defenders are urged to remove public exposure, patch devices, and use stronger access controls.
If operators follow the advisory, exposed systems can be pulled behind firewalls, VPNs, or access controls and made much harder to reach from the internet. Stronger passwords, updates, and monitoring could reduce the chance that attackers can tamper with tank readings or safety alerts.
If exposed systems stay online with weak controls, attackers may continue to change settings and disable alerts. That could hide leaks, disrupt operations, and in the worst case damage equipment that operators rely on for safety and compliance.



