US government agencies including CISA, FBI, and NSA are alerting critical infrastructure operators to cyberattacks targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks.
The joint warning from CISA, the FBI, NSA, and Department of Energy flags a significant threat to fuel distribution networks and related infrastructure. Attackers are actively exploiting vulnerabilities in ATG systems—devices that automatically measure and report fuel levels in storage tanks across the energy sector and other critical industries.
Automatic tank gauges are integral to fuel management operations, providing real-time monitoring of inventory levels. When connected to the internet without adequate security measures, these systems become accessible entry points for malicious actors.
The agencies did not specify which threat groups are behind the attacks or provide details on successful breaches. However, the coordinated warning indicates the threat level warrants urgent attention from operators managing these systems.
ATG systems are widely deployed across gas stations, fuel distribution centers, and industrial facilities that store and manage petroleum products and other liquids. Compromised systems could enable attackers to manipulate fuel inventory data, disrupt supply chains, or pivot to larger infrastructure networks.
Recommended Actions:
CISA advises organizations operating ATG systems to:
- Segment networks to isolate tank monitoring systems from internet access where possible
- Implement strong authentication protocols and change default credentials
- Apply available security patches and updates promptly
- Monitor for suspicious access attempts and unusual data changes
- Conduct vulnerability assessments of exposed systems
The warning underscores the broader vulnerability of operational technology systems that were often designed without internet connectivity in mind but are increasingly connected for remote monitoring and efficiency gains.
Organizations managing critical fuel infrastructure are urged to review their ATG deployments immediately and consult CISA resources for additional mitigation guidance.
A U.S. citizen is asking a court to dismiss government accusations that he used a 'duress' password to erase his phone during a border search, raising fresh constitutional questions about digital privacy rights.
A threat actor deployed the open-source Hermes AI agent in unattended mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance.
OnTrac, a major parcel delivery company, has notified customers of a network breach that may have exposed personal information. The hack compromised the company's corporate systems.
Slopsquatting, phantom domains, and HalluSquatting exploit identical vulnerabilities in AI coding agents. Security researchers warn that these attacks leverage late-binding patterns where AI systems trust non-existent packages and repositories.