U.S. agencies warn hackers are targeting fuel storage systems – Expert Comments

U.S. cybersecurity agencies, including CISA, the FBI, NSA, and Department of Energy, warned that threat actors are actively targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks.

According to the joint advisory, attackers are exploiting weak cybersecurity practices such as default credentials, unsecured remote access, and internet-exposed systems to gain access to fuel monitoring infrastructure across multiple critical infrastructure sectors.

The advisory follows reports (see below) that attackers have successfully accessed and tampered with fuel storage monitoring systems in the United States. Federal agencies said many of the affected systems are connected directly to the internet and often lack basic security controls.

While ATG systems typically do not directly control fuel flow, officials warned that unauthorized access could disrupt operations, manipulate monitoring data, and create safety concerns for facility operators.
Experts with Suzu Labs and Xcape, Inc. offer perspectives on the matter.

Denis Calderone, CTO, Suzu Labs:

“The ATG story just got significantly worse, and eight federal agencies agree. CISA, FBI, NSA, DOE, EPA, TSA, DOT, and USDA co-signed a joint advisory this week confirming that the threat to automatic tank gauge systems extends well beyond gas stations into energy, chemical, food and agriculture, and transportation infrastructure. When the Department of Agriculture and the EPA are co-authoring a cybersecurity advisory, the blast radius is a lot bigger than fuel pumps. The prescription, however, hasn’t changed at all.

“That expanded scope changes the risk profile considerably. A compromised tank gauge at a gas station can mask a fuel leak or an overfill condition. A compromised ATG at a chemical storage facility or food production environment introduces environmental hazards, food safety concerns, and physical damage potential that are in a different category entirely. The Ag-ISAC is already warning about impacts to harvest operations and food-grade storage. And the government still hasn’t formally attributed this activity, but honestly, attribution doesn’t change the defensive playbook here. The exposure is the problem regardless of who’s walking through the door.

“What’s genuinely frustrating is that the prescriptive advice is functionally identical to what Rapid7 published in 2015 when they found over 5,800 exposed tank gauges with no passwords. Take the systems off the internet. Change default credentials. If you need remote access, put a VPN or firewall in front of it. That guidance hasn’t changed in a decade because it doesn’t need to. These systems should never have been directly reachable from the public internet in the first place, and the fact that it takes eight federal agencies issuing a joint advisory to say that in 2026 tells you everything about the state of critical infrastructure security."

Damon Small, Board of Directors, Xcape, Inc.:

“A joint cybersecurity advisory issued by CISA, the FBI, the NSA, and the Department of Energy warns that malicious cyber actors are actively targeting Internet-exposed automatic tank gauge (ATG) systems. This threat converts basic operational technology configuration oversights into severe, systemic product shortages across critical infrastructure.

“By leveraging unauthenticated remote access and factory-default credentials, threat actors can induce a total denial of view or inject fraudulent telemetry across utilities distributing gasoline, diesel, aviation fuel, liquefied petroleum gas, and industrial chemicals. While ATGs do not directly manipulate physical flow valves, the business impact is immediate. Falsified safety thresholds or masked water contamination anomalies will force operators to halt regional distribution out of sheer caution, leading to cascading health and safety hazards.

“To defend against this active threat, security leaders must immediately pull all ATG monitoring interfaces off the public Internet, place them behind securely configured virtual private networks, and enforce multi-factor authentication along with unique administrative credentials.

Critical Takeaways:

• “Enforce immediate isolation: Disconnect all automatic tank gauge monitoring interfaces from the public Internet and place them behind a stateful firewall or virtual private network.
• “Eliminate factory defaults: Audit all internal and external operational technology endpoints to rotate factory-default administrative credentials and enforce unique, complex passwords.
• “Plan for denial of view: Update incident response playbooks to establish manual verification procedures for liquid levels when telemetry data becomes untrusted or unavailable.

“Attackers do not need to rewrite physical valve logic when they can convince your operators to shut down the pumps themselves using falsified telemetry.”

Articles similaires

Opinion

21 August 2026

Expert Commentary: NCSC urges stronger security controls for agentic AI

UK’s National Cyber Security Centre (NCSC) urging organizations deploying agentic AI systems to (…)

Opinion

18 August 2026

Hacker claims 3.6 million records stolen from major companies’ Azure environments – Expert Comments

A threat actor known as TheHatman is selling databases allegedly stolen from the Microsoft Azure (…)

Opinion

17 August 2026

ETSI advances cybersecurity standards supporting Cyber Resilience Act – Expert Comments

ETSI (European Telecommunications Standards Institute) has moved 17 cybersecurity standards into (…)