Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    September 24, 2026

    Google’s AI Gemini exhibits self-control, stops unauthorised hack into companies

    September 24, 2026

    Meta Pinky Promises Its Smart Glasses Will Be Private Soon

    September 24, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Hackers Are Targeting Fuel Tank Monitoring Systems
    Cybersecurity

    Hackers Are Targeting Fuel Tank Monitoring Systems

    InfoForTechBy InfoForTechJune 5, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Hackers Are Targeting Fuel Tank Monitoring Systems
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Cybercriminals are probing a quiet layer of fuel infrastructure: the systems that monitor what is inside storage tanks.

    According to a new government advisory, reports have emerged of threat actors targeting Automatic Tank Gauge (ATG) systems used to monitor fuel and liquid storage tanks across the US. Officials say these actors have already compromised internet-facing devices in recent months, raising concerns about the security of these often-overlooked industrial systems.

    The warning points to a growing trend across the threat landscape. Instead of focusing exclusively on digital data theft or enterprise networks, attackers are also probing technologies closer to physical operations, where disruptions can halt real-world operations, affecting millions.

    What does an ATG system do, and why are they being targeted?

    At their core, ATG systems serve as digital monitoring platforms for checking inventory, detecting leaks, and managing tank conditions across sites ranging from gas stations to industrial facilities.

    Because of the role they play in keeping everyday activities that rely on them running smoothly, they’ve recently become active targets for cyberattacks aimed at disrupting these services.

    What makes this even more consequential is where they sit — right in the middle of digital infrastructure and physical activities. To make matters worse, the very conditions that allow these systems to operate smoothly — convenient access — have become the leverage threat actors now use to gain illegal access to them.

    How the attack happens

    According to a June 2 publication from the Cybersecurity & Infrastructure Security Agency (CISA), attacks on ATG systems have been observed exploiting several weaknesses within the system.

    Among the techniques highlighted in the report are authentication bypass vulnerabilities and hardcoded credentials that can grant direct access to device management interfaces. The agency also noted that OS command execution and SQL injection flaws could enable arbitrary code execution, database manipulation, and, in some cases, the escalation of privileges to full administrative control over the system.

    That level of access effectively puts the attackers in the position of a trusted operator, creating entry points to modify configurations, suppress danger alerts, or cause permanent damage to the systems.

    Must-read security coverage

    What CISA and partners are telling operators to fix

    As the agency responsible for infrastructure security, CISA sits at the forefront of this… but it isn’t the only government body involved.

    Affected agencies include the FBI, the NSA, the Department of Energy (DOE), and the Environmental Protection Agency (EPA). Others include the Transportation Security Agency (TSA), the Department of Transportation (DOT), and the US Department of Agriculture (USDA).

    Together, these agencies are recommending that ATG operators do the following, where applicable:

    • Disable direct internet exposure: Remove ATG systems from direct internet access wherever possible and restrict remote connectivity through VPNs, Access Control Lists (ACLs), or similar controls.
    • Strengthen authentication: Replace default credentials with stronger ones and deploy phishing-resistant MFA where possible.
    • Patch and update systems: The attacks exploited vulnerabilities within these systems that could have been avoided with system updates from ATG manufacturers.
    • Increase system visibility: Enable continuous monitoring and logging to detect unauthorized access and unusual changes that could indicate tampering.
    • Enforce vendor security: When working with a vendor, ensure they also follow secure practices, as a supply chain flaw can serve as an entry point into the broader system.

    For operators, the message is straightforward: ATG systems should not be treated as forgotten back-office hardware. Any internet-exposed device should be reviewed, access restricted, credentials changed, and suspicious activity reported to CISA or law enforcement.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    September 24, 2026

    Weekly Update 522: Live From Oslo with Scott Helme

    September 23, 2026

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    September 23, 2026

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    September 23, 2026

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    September 22, 2026

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

    September 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026381 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views

    Creating an AI Girlfriend with OurDream

    February 12, 202623 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026381 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.