Eight federal agencies urge immediate security hardening of automatic tank gauge systems after observing malicious cyber activity targeting internet-exposed devices across critical infrastructure sectors.
Summary
- CISA and seven partner agencies report active cyber threats targeting automatic tank gauge (ATG) systems used across energy, chemical, food and transportation sectors
- Attackers exploit authentication bypass, command injection and privilege escalation flaws to gain full control of tank monitoring systems
- Successful compromises could disrupt tank operations, disable safety alerts and cause environmental hazards through manipulated monitoring data
- Federal agencies recommend immediately removing ATG systems from public internet exposure and implementing strong authentication controls
The Threat
CISA, FBI, NSA and five other federal agencies report ongoing malicious cyber activity targeting automatic tank gauge systems across the United States. These systems provide automated monitoring of storage tank parameters including fuel levels, temperature and leak detection across energy, chemical, food and agriculture, and transportation sectors. The threat activity has not yet been attributed to any specific nation-state or threat group.
Attack Methods
Threat actors are exploiting multiple vulnerabilities in internet-exposed ATG systems. The primary attack vectors include authentication bypass through hardcoded credentials, operating system command execution, SQL injection attacks, and privilege escalation to gain full administrator access. Once compromised, attackers can interface directly with tank management systems as if they had legitimate physical console access.
Potential Impact
Successful ATG compromises pose significant operational and safety risks. Attackers could alter critical system attributes including network settings, product identifiers, tank volumes and pump controls. They could compound operational malfunctions that create denial of view conditions for tank fill levels, potentially causing permanent damage to critical tank functions. Most concerning, attackers could disable system alerts, reducing operators’ ability to detect system issues and increasing risks of environmental or physical hazards from incidents such as leaks or relay failures.
Recommended Actions
The federal agencies recommend ATG owners immediately eliminate public internet exposure by removing serial ports and web interfaces from direct internet access. If remote access is necessary, organisations should restrict access through firewalls, access control lists or VPNs. Other critical steps include changing all default passwords immediately, implementing strong authentication credentials, and deploying phishing-resistant multifactor authentication where feasible. Organisations should work with certified ATG service providers to apply security patches and ensure compliance with manufacturer recommendations.
Monitoring Requirements
The advisory emphasises active network monitoring for unauthorised access attempts. Organisations should enable comprehensive logging and audit systems to identify exposures of ATG device interfaces, unauthorised connections, suspicious alarms, alarm threshold modifications, tank label changes and other system modifications. Any suspected incidents should be reported promptly through CISA’s incident reporting portal.
Why it matters
ATG systems represent critical operational technology infrastructure that, when compromised, could cause environmental damage, safety incidents, and significant business disruption. The active threat campaign targeting these widely deployed systems across multiple critical infrastructure sectors represents both immediate operational risk and potential regulatory compliance exposure for affected organisations.
What to do now
- Immediately audit all ATG systems for internet exposure and remove them from public access
- Change all default passwords and implement strong, unique credentials for all ATG interfaces
- Deploy phishing-resistant multifactor authentication where technically feasible
- Implement network segmentation using firewalls, ACLs or VPNs if remote access is required
- Enable comprehensive logging and monitoring for ATG device interfaces and system modifications
- Work with certified ATG service providers to apply latest security patches
- Report any suspected compromise incidents to CISA through their incident reporting portal
