CISA warns of fuel tank monitoring system cyberattacks

▼ Summary
– U.S. government agencies warn that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage in critical infrastructure sectors.
– ATG systems are used in Energy, Chemical, Food and Agriculture, and Transportation Systems to remotely monitor tank levels, temperatures, and leaks.
– Attackers compromise ATG systems through vulnerabilities like authentication bypass, hardcoded credentials, and SQL injection, then modify system settings via command execution.
– Successful compromise allows attackers to alter network settings, tank volumes, pump controls, and disable alerts, risking leaks or equipment failures.
– The advisory follows CNN reporting that Iranian hackers previously breached ATG systems at U.S. gas stations, but the current activity has not been attributed to any specific threat actor.
A coalition of U.S. federal agencies,including CISA, the FBI, the NSA, and the Department of Energy,has issued a joint warning about hackers actively targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across critical infrastructure.
These ATG systems are widely deployed in the Energy, Chemical, Food and Agriculture, and Transportation Systems sectors. They allow operators to remotely track storage tank levels, temperatures, and potential leaks. Now, the government warns that threat actors are compromising these exposed devices and executing commands to alter system settings.
“The recent malicious cyber activity observed by the authoring organizations,which the U. S. government has not yet attributed to a nation-state or threat actor group,involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution,” the advisory states.
Attackers are reportedly gaining entry through a range of vulnerabilities: authentication bypass flaws, hardcoded credentials, operating system command-execution weaknesses, SQL injection vulnerabilities, and privilege-escalation issues. Once inside, they can modify network settings, product identifiers, tank volumes, and pump controls. They can also disable alerts, preventing operators from properly monitoring fill levels and increasing the risk of leaks or equipment failures.
To defend against these threats, the agencies urge organizations to block ATG systems from direct internet access, restrict remote connections using firewalls, VPNs, or access control lists, replace default passwords with strong credentials and multifactor authentication, apply security updates promptly, and actively monitor systems for unauthorized changes.
Iranian hackers previously linked to similar activity
While this advisory does not officially attribute the attacks to any specific actor, it follows a CNN report from May that Iranian hackers were behind a series of breaches involving ATG systems at gas stations across several U. S. states. According to CNN, the attackers exploited systems connected to the internet and protected only by weak or nonexistent passwords. They were able to manipulate display readings, though they did not alter actual fuel levels.
The incidents reportedly caused no physical damage, but they raised alarms about the potential for attackers to interfere with leak detection and other safety-critical functions. CNN reported that Iran was the primary suspect due to its history of targeting fuel management systems and other industrial control technologies. However, sources briefed on the investigation noted that limited forensic evidence may make it impossible to definitively attribute the activity to a specific attacker.
CISA and its partners stress that organizations operating ATG systems should immediately review their exposure and implement the recommended mitigations to reduce the risk of compromise.
(Source: BleepingComputer)
