More than 900 automatic tank gauge systems in the United States were reportedly found exposed online, leaving fuel and chemical storage monitoring systems vulnerable to attack. These systems are used to measure tank levels, temperature, leaks, alarms, and other operational conditions across gas stations and other critical infrastructure environments. Putting them directly on the internet is less “remote monitoring” and more “please inspect our industrial equipment, dear strangers.” 

What makes this serious 

Automatic tank gauge systems may not look as dramatic as ransomware targets or cloud platforms, but they are tied to real-world operations. If attackers gain access, they may be able to manipulate readings, disable alarms, change configuration values, or disrupt visibility into fuel and liquid storage conditions.

Government agencies including CISA, NSA, FBI, EPA, and the Department of Energy have warned that threat actors are actively targeting internet-exposed ATG systems. The concern is not theoretical. These systems are already being probed and compromised, mainly because many are exposed with weak passwords, default credentials, poor segmentation, or no meaningful access controls. A truly dazzling achievement in making industrial monitoring systems behave like abandoned webcams.

Why this is an OT problem, not just an IT issue 

In traditional IT, a compromised system may mean stolen data, malware, or service disruption. In OT environments, the impact may involve physical processes, safety systems, inventory accuracy, environmental controls, and operational continuity.

A wrong tank reading can affect dispatch, refilling, billing, safety decisions, and leak detection. If alerts are disabled or values are changed, operators may lose trust in the very systems meant to warn them of abnormal conditions. That is why even “read-only” or “monitoring” systems must not be casually exposed.

OT devices often run for years with minimal updates, limited logging, weak authentication, and vendor-dependent support. Attackers know this. They also know many organizations do not maintain a clear inventory of these devices, which is basically asking defenders to protect ghosts.

What operators should do 

Operators should immediately check whether any automatic tank gauge systems are reachable from the public internet. If remote access is required, it should be placed behind a secure VPN or dedicated remote access gateway with MFA, logging, and strict access rules.

Default passwords must be changed, weak credentials removed, and device access limited to trusted networks only. Unused services should be disabled, firmware should be updated where available, and vendor guidance should be followed. Firewalls should block direct internet access to ATG interfaces, and network segmentation should separate these systems from corporate IT and payment systems.

Organizations should also monitor for unexpected configuration changes, unusual login attempts, alarm changes, unexplained tank reading variations, and suspicious outbound connections. For critical sites, manual verification procedures should remain available, because blindly trusting a compromised sensor is not automation. It is just confidence with poor evidence.

What security teams should learn 

This incident is a reminder that exposure management must include OT and industrial devices, not only laptops, servers, and cloud assets. Internet-facing inventories should be reviewed regularly using internal scans, external attack surface monitoring, firewall reviews, and vendor asset lists.

Security teams should work with operations teams to identify ATG systems, document ownership, define remote access rules, and create incident response procedures. OT security is not solved by sending one email to the plant team and hoping everyone becomes enlightened. It requires asset visibility, segmentation, access control, patch planning, monitoring, and practical coordination.

Security takeaway 

The exposure of more than 900 tank gauge systems shows how ordinary operational devices can become critical security risks when connected without proper controls.

The practical message is clear: remove ATG systems from direct internet access, enforce strong authentication, segment OT networks, monitor configuration changes, and maintain a full inventory of exposed industrial assets. Attackers do not need advanced malware when critical systems are already reachable online with weak protection. That is not sophistication. That is defenders doing the reconnaissance for them.


Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks. [...]

Source: Over 900 US gas station tank gauge systems exposed to attacks via Bleeping Computer — published 05 Jun 2026.