Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    SSA-116924 V1.2 (Last Update: 2024-08-13): Path Traversal Vulnerability in TIA Portal

    June 6, 2026

    Attacks Are Living in the Browser

    June 6, 2026

    SSA-417159 V1.0: Multiple Vulnerabilities in SINEMA Remote Connect Client Before V3.2 SP2

    June 6, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Over 900 US gas station tank gauge systems exposed to attacks
    News

    Over 900 US gas station tank gauge systems exposed to attacks

    adminBy adminJune 5, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Gas station

    Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks.

    ATG systems are electronic monitoring devices used to remotely track fuel, chemicals, or other liquids in storage tanks, automating inventory control, environmental leak detection, and regulatory compliance. While they’re commonly used at gas stations to monitor fuel tank levels, they can also be found in industrial settings to track chemical storage tanks.

    On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, the Department of Energy, and other U.S. government partners issued a joint advisory warning critical infrastructure organizations to secure internet-exposed ATG systems against ongoing attacks.

    image

    The federal agencies warned that threat actors target such devices to alter system settings in command execution attacks after exploiting various security flaws, including hardcoded credentials, authentication bypasses, SQL injection vulnerabilities, OS command execution flaws, and privilege escalation weaknesses.

    “The recent malicious cyber activity observed by the authoring organizations—which the U.S. government has not yet attributed to a nation-state or threat actor group—involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution,” the joint advisory warned.

    As CISA cautioned, following successful compromises, the attackers could disable system alerts, increasing the risk of leaks or equipment failures and even causing permanent damage to the targeted tank systems.

    In light of CISA’s advisory, Internet security watchdog Shadowserver warned today that over 1,000 ATG systems were exposed online, with the vast majority (909 devices) in the United States.

    Map of ATG systems exposed online
    Map of ATG systems exposed online (Shadowserver)

    ​”We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp),” Shadowserver said. “This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001).”

    Critical infrastructure organizations are advised to restrict remote access to ATG systems from the Internet as soon as possible and implement controlled access through firewalls, VPNs, or access control lists.

    They should also replace default passwords on vulnerable devices with strong credentials, apply security updates, monitor systems for unauthorized changes, and implement multi-factor authentication where possible.

    CISA’s warning comes after a May CNN report that Iranian hackers had breached ATG systems connected to the Internet at multiple gas stations across the United States. Iranian hacking groups were linked to these incidents based on their previous history of targeting fuel management systems and other industrial control technologies.

    After hacking the devices with weak or nonexistent passwords, the attackers reportedly manipulated the display readings but did not alter the actual fuel levels. Although these incidents didn’t cause any physical damage, they raise concerns that such attacks could hinder automated fuel leak detection and similar safety-related functions.

    In April, another joint advisory issued by U.S. federal agencies linked Iranian state-backed hackers to attacks targeting Rockwell Automation/Allen-Bradley PLC devices since March 2026, causing financial losses and operational disruptions.

    Cybersecurity firm Censys reported one day later that 74.6% (3,891 hosts) of such industrial control systems found exposed online globally were from the United States.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-9829 | THREATINT
    Next Article SSA-088132 V1.1 (Last Update: 2024-09-10): Denial of Service Vulnerability in the OPC UA Server Implementations of Several Industrial Products
    admin
    • Website

    Related Posts

    News

    Attacks Are Living in the Browser

    June 6, 2026
    News

    Dark web Nemesis Market vendor gets 26 years for selling drugs

    June 5, 2026
    News

    Cybersecurity Hygiene Reinforced by the 2026 Verizon DBIR

    June 5, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    SSA-116924 V1.2 (Last Update: 2024-08-13): Path Traversal Vulnerability in TIA Portal

    June 6, 2026

    Attacks Are Living in the Browser

    June 6, 2026

    SSA-417159 V1.0: Multiple Vulnerabilities in SINEMA Remote Connect Client Before V3.2 SP2

    June 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.