Iran-Linked Hackers Breach U.S. Gas Station Tank Readers, Fuel Data Manipulated

U.S. officials said suspected Iran-linked hackers breached remote “tank reader” systems at gas stations in multiple states, manipulating fuel-level displays but causing no known physical damage or shortages as of Friday. The intrusions targeted automatic tank gauges (ATGs) that were exposed to the open internet, in some cases with no passwords, in an incident that sharpened concerns over the security of U.S. critical infrastructure during wartime with Iran idahopress.
The breaches were under active investigation, with agencies including the Cybersecurity and Infrastructure Security Agency (CISA) notified; the FBI declined public comment. Officials said the activity fit a pattern of increasingly aggressive Iranian cyber operations that have recently disrupted U.S. oil, gas, water and private-sector networks idahopress +1.
How Hackers Reached the Gas Station Tank Readers
Investigators said the hackers scanned the internet for ATG devices reachable over common ports and found many “sitting online and unprotected by passwords,” allowing them to log in and alter displayed tank readings remotely idahopress. ATGs, widely deployed at gas stations and depots, monitor fuel volume, temperature and possible leaks and can trigger alarms or shutoffs if something goes wrong rd +1.
Security research over the past decade showed thousands of these devices worldwide remain directly exposed online, often using legacy protocols that were never designed for modern cybersecurity threats. Early work in 2015 found about 5,800 exposed ATGs, including roughly 5,300 in the U.S., while a 2022 scan identified more than 11,000 such systems globally rd. More recently, BitSight researchers documented 11 critical vulnerabilities across six ATG models, including command-injection flaws with maximum-severity CVSS scores of 10.0 that could give attackers full control of affected devices darkreading.
In the latest incident, officials said attackers only manipulated what operators could see on their screens, not the actual fuel in the tanks idahopress. But experts warned that the same level of access could, in other circumstances, be used to disable alarms, mask leaks or tamper with safety thresholds, creating the potential for environmental damage or explosions rd +1.
A Warning Shot for Critical Infrastructure Defenses
The suspected Iranian operation came against a backdrop of escalating cyber activity tied to the conflict, including incidents that disrupted internet access for U.S. oil, gas and water companies between January 2025 and March 2026, according to an FBI report consumer. “We have seen both state and non-state actors in Iran pose real risk and show willingness to hurt people through compromising these systems,” said Rob Lee, CEO of industrial cybersecurity firm Dragos consumer.
Federal agencies and security firms have repeatedly urged fuel retailers to remove ATGs from the public internet, segment operational networks, apply vendor patches and implement stronger authentication rd +2. Yet the persistence of vulnerable, decades-old hardware in the field, combined with the cost and logistical burden of replacing it, has slowed progress. Researchers warned that even modest manipulations of fuel data could prompt operators to shut down sites out of caution, risking localized disruptions similar in effect—if not in scale—to the 2021 Colonial Pipeline shutdown rd +1.
The Bigger Picture
The gas-station breaches underscored how relatively simple techniques—scanning for exposed devices and exploiting weak or missing passwords—could still reach sensitive industrial systems in 2026. While the immediate impact appeared limited, the incident added urgency to calls for stronger baseline protections and possible new regulatory requirements for internet-exposed control systems. As investigations continue, the episode highlighted a central dilemma of modern infrastructure: long-lived, indispensable equipment built for reliability, now operating in a threat environment it was never designed to withstand.
Sources
cnn
EXCLUSIVE: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible
US officials suspect Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas...
idahopress
Code violations and ‘negligence’ likely factors in North Idaho gas station explosion that killed 2, report says
Originally published on March 23 at Spokesman.com.
rd
How to Spot a Gas Pump Skimmer and Avoid Getting Scammed
Gas-station fraud commonly occurs with small devices thieves place on, in or above the card readers at gas pumps (and ATMs) to copy and steal your credit card...
darkreading
Many Fuel Tank Monitoring Systems Vulnerable to Disruption
Thousands of automatic tank gauge (ATG) devices are accessible over the Internet and are just a packet away from compromise, security researcher warns at 2025...
svvoice
Kinder Morgan Fined Nearly $227K for Air Quality Violations at Bay Area Fuel Terminals
The Bay Area Air District says Kinder Morgan, Inc. has paid nearly $227000 in fines for issues at its fuel terminals in San Jose and...
taosnews
Spokesperson denies hacking breach at Taos County Speedway stations
At least four Taos County residents said they have incurred fraudulent charges on bank accounts used to make purchases at local Speedway gas...
consumer
Watch out for card skimming at the gas pump
The FTC is warning drivers about skimming scams at the pump. Skimmers are illegal card readers attached to payment terminals.
darkreading
Critical Automated Tank Gauge Bugs Threaten Gas Infrastructure
The security vulnerabilities could lead to everything from gas spills to operations data disclosure, affecting gas stations, airports,...
thedailyrecord
Gas station contractor sues Royal Farms for alleged contract breaches
A service station contractor is suing Royal Farms for allegedly breaching a contract to construct two new car washes and failing to pay for...
nbcnews
Watered Down Gas Is Way More Common Than You May Think
Faulty gas pumps mean you could be buying watered down gas, gas with sediment in it, or getting less gas than you pay for. A motorist pumps...
pbs
Iran-linked hackers take aim at U.S. and other targets, raising risk of cyberattacks during war
Hackers supporting Iran claimed responsibility for a significant cyberattack Wednesday against U.S. medical device company Stryker.
thebulletin
When the war in Iran comes home: Why the US isn’t ready for increasing hybrid threats
Hours before President Trump announced a two-week ceasefire with Iran last Tuesday, the Cybersecurity and Infrastructure Security Agency...
cloudsek
Situation Report: Middle East Escalation (February 27–1st March, 2026)
The report examines the sharp escalation following the 28 February 2026 joint Israel–U.S. strikes on Iran, triggering a hybrid conflict...
industrialcyber
Iranian petrol stations hit by cyber attack allegedly linked to Israeli hacker group
Iran has accused a hacking group with alleged ties to Israel of carrying out a cyber attack that resulted in service disruptions at petrol stations throughout...
timesofisrael
Israel-linked group claims cyberattack that shut down 70% of Iran’s gas stations
Tehran cites 'software problem' as cause for shutdown; group known as Gonjeshke Darande takes responsibility, says attack is response to Iranian...
cnbc
Israel-linked hackers claim cyberattack that hit 70% of Iran's gas stations
Israel-linked hackers claim cyberattack that hit 70% of Iran's gas stations · The cyberattack knocked out a majority of gas stations across Iran...
aljazeera
Iran points at Israeli-linked group as cyberattack disrupts fuel network
A cyberattack has disrupted services at around 70 percent of Iran's fuel stations, according to reports. The Israel-linked group Predatory...
thehill
FBI: Iran-linked hackers disrupted US oil, gas, water sites
Iran-linked hackers disrupt internet access for US oil, gas, and water companies, targeting PLC systems. FBI warns of increased...
therecord
Pro-Israel hackers claim breach of Iranian bank amid military escalation
A hacking group known as Predatory Sparrow, believed to be linked to Israel, has claimed responsibility for a cyberattack on an Iranian bank.
time
What to Know About the Cyber Attack on Iran’s Gas Stations
Around 70% of Iran's petrol stations have seen their services disrupted Monday after a massive cyber attack was carried out by the hacker group Gonjeshke...
stacker
HIPAA violations in 2025: Staff mistakes and vendor blind spots
HIPAA violations don't always come from malicious attacks or headline-making data breaches. More often, they stem from everyday mistakes,...
therecord
Pro-Russian hackers caught bragging about attack on fake water utility
A pro-Russian hacker group has been caught boasting about a cyberattack that unfolded entirely inside a decoy system set up by researchers.
digitalcommerce360
Canadian Tire reports data breach affecting ecommerce customers
The data breach involved a database containing names, addresses, email addresses and years of birth for online account holders of Canadian...
bitsight
Critical Vulnerabilities Discovered in Automated Tank Gauge Systems
Recent investigation by Bitsight TRACE has discovered multiple critical 0-day vulnerabilities across six ATG systems from five different vendors.
industrialcyber
Cyble details Russian hacktivist group Sector 16 targeting US oil infrastructure in alarming data breaches
New research from Cyble has revealed the emergence of a new Russian hacktivist group on the dark web in January, alongside a surge in data...
resecurity
Cyber Threats Against Energy Sector Surge as Global Tensions Mount
Cyberattacks targeting the energy sector are increasing, driven by a host of geopolitical and technological factors. A report published by...
cpomagazine
Canadian Cyber Centre Warns of Hacktivists Breaching Critical Infrastructure via Internet-Exposed ICS Devices
The Canadian Centre for Cyber Security (CCCS) is warning of increased malicious activity from hacktivists targeting critical infrastructure,...
wttw
Breach Exposed Data of Half-Million Chicago Students, Staff
The data breach occurred Dec. 1 and technology vendor Battelle for Kids notified CPS on April 26, the district said Friday.
cnn
Stryker: Pro-Iran hackers claim cyberattack on major US medical device maker
A cyberattack claimed by pro-Iran hackers has caused a “global network disruption” to a major US medical device maker, according to a...
cnn
Iran-linked hackers have breached FBI Director Kash Patel’s personal emails
Hackers connected to the Iranian government accessed FBI Director Kash Patel's personal email and posted materials — including photos and...
cybersecuritynews
CISA Warns Of Critical Veeder-Root Vulnerabilities Let Attackers Execute System-level Commands
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark advisory highlighting two severe vulnerabilities in.
industrialcyber
BitSight discloses zero-day vulnerabilities in ATG systems, posing major threat to critical infrastructure
An investigation by BitSight Technologies' TRACE researchers has discovered multiple critical zero-day vulnerabilities across six Automatic...
csoonline
Thousands of internet-exposed fuel gauges could be hacked and dangerously exploited
Despite a decade of warnings, devices used to monitor fuel tanks have critical vulnerabilities and poor code quality that could allow...
cyberpress
CISA Warns of Critical Veeder-Root Flaws Enabling System Command Execution
Security researchers at Bitsight identified two dangerous vulnerabilities that pose an immediate threat to critical infrastructure...
thehackernews
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & More
Explore major cyber shifts this week—from stealthy nation-state ops to new data exposure risks.
arstechnica
Internet attack could shut down US gas stations
A device used to monitor the gasoline levels at refueling stations across the United States—known as an automated tank gauge or ATG—could be...
securityaffairs
Unknown hackers hit Gas Pump Monitoring Systems in the US
Researchers from Trend Micro discovered that unknown hackers have compromised Gas Pump Monitoring Systems in the US ... it's security...
Iran-linked hackers have successfully targeted and caused ...
The U.S. Justice Department's September 2024 indictment accused the group of orchestrating the hacking operation, a claim the hackers have ...
wistv
Deal reached with hackers to delete data stolen from the Canvas ...
A hacking group named ShinyHunters claimed responsibility for last week's breach, threatening to leak data involving nearly 9,000 schools ...
ctvnews
Cyberattack by Pro-Iran hackers targets U.S. medical device maker
Pro-Iran hackers claim cyberattack on major U.S. medical device maker. By. CNN ... hack a U.S. think tank employee — since the war began.
cnn
What we know about the Canvas hack that has impacted ... - CNN
A University of Washington student who tried to log into Canvas around noon Thursday was greeted by a message from the hacking group ...
nbcnews
NBC News - Breaking Headlines and Video Reports on World, U.S. ...
Go to NBCNews.com for breaking news, videos, and the latest top stories in world news, business, politics, health and pop culture.
washingtonpost
The Washington Post - Breaking news and latest headlines, U.S. ...
Breaking news, live coverage, investigations, analysis, video, photos and opinions from The Washington Post. Subscribe for the latest on U.S. and ...
usmcu
[PDF] Published by Marine Corps University Press
Abstract: In 2015, Chinese hackers breached the Office of Personnel Manage- ... such as the OPM hack and 2016 election; those may be the last warnings it.
state
International Religious Freedom Reports: Custom Report Excerpts
The military stated it was concerned the gas tanks might be used to make bombs for insurgent attacks. ... On May 15, following an investigation of the ...
wisn
Hackers have breached tank readers at US gas stations
U.S. officials suspect Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving ...
Iran-linked hackers have successfully targeted and caused ...
Iran-linked hackers have successfully targeted and caused disruptions at multiple US oil and gas and water sites in recent weeks, according to a ...
pbs
U.S. pipelines ordered to increase cyber defenses after hack - PBS
The hack that targeted Colonial Pipeline prompted the company to shut down a system that delivers about 45% of the gasoline consumed on the East ...
Today the FBI and DOJ announced Operation Masquerade, a court ...
Today the FBI and DOJ announced Operation Masquerade, a court-authorized technical disruption of Russian GRU infrastructure used to steal ...
darkreading
Gas Stations Urged To Secure Internet-Exposed Fuel Tank Devices
Researchers find more than 5000 US gas stations' automated tank gauges unprotected on the public Internet and open to hackers.
papetroleum
Beware of Nationwide Cyberattacks Targeting Automatic Tank ...
The attacks have allowed unauthorized access to fuel tank and fuel sensor information, and, in some cases, such information has been deleted ...
kmbc
America's pipelines ordered to step up cyber defenses after attack
Pipeline operators will now be required to conduct a cybersecurity assessment under a new directive from the Biden administration.
securityweek
US Gas Stations Exposed to Cyberattacks: Researchers
Researchers have discovered that the automatic tank gauges (ATGs) at 5300 gas stations in the United States are vulnerable to hacker ...
Kuwait has accused Iran of sending an IRGC team to launch an ...
Kuwait has accused Iran of sending an IRGC team to launch an attack in the Middle East nation. Kuwait said a team of six-armed members of ...
security
Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software ...
Activity associated with Iranian APT group Seedworm has been spotted on the networks of multiple U.S. companies. The activity began in February 2026 and has ...
pbs
Suspected cyberattack renders most gas stations in Iran out of service
Nearly 70% of Iran's gas stations went out of service on Monday following possible sabotage — a reference to cyberattacks, Iranian state TV ...
timesofisrael
Iran official blames Israel, US for cyberattack that crippled gas stations
Iran's head of civil defense on Saturday blamed Israel and the United States for a cyberattack this week that crippled gas stations across the country.
youtube
Iran says cyberattack caused gas station chaos - YouTube
A cyberattack disrupted the sale of heavily subsidized gasoline in Iran on Tuesday, state media reported, causing long queues at gas ...
securityweek
Suspected Cyberattack Paralyzes the Majority of Gas Stations ...
Nearly 70% of Iran's nearly 33,000 gas stations went out of service on Monday following possible cyberattacks, Iranian state TV reported.
npr
A cyberattack paralyzed every gas station in Iran - NPR
Iran's president said Wednesday that a cyberattack which paralyzed every gas station in the Islamic Republic was designed to get people angry by creating ...
abc17news
EXCLUSIVE: Hackers have breached tank readers at US gas stations
Published May 15, 2026 1:41 PM. By Sean Lyngaas, CNN. (CNN) — US officials suspect Iranian hackers are behind a series of breaches of systems ...
edition
CNN: Breaking News, Latest News and Videos
View the latest news and breaking news today for U.S., world, weather, entertainment, politics and health at CNN.com.
CNN is on the ground in Iran getting a look at how bridges and ...
CNN is on the ground in Iran getting a look at how bridges and roads damaged by U.S. strikes are impacting travel. This CNN assessment of the ...
transcripts
CNN.com - Transcripts
Aired May 01, 2026 - 02:00 ET. THIS IS A RUSH TRANSCRIPT. THIS COPY MAY NOT BE IN ITS FINAL FORM AND MAY BE UPDATED. [02:00:00]
congress
H. Rept. 116-346 - IMPEACHMENT OF DONALD J. TRUMP ...
House report on IMPEACHMENT OF DONALD J. TRUMP PRESIDENT OF THE UNITED STATES. This report is by the Judiciary.
Gas prices are skyrocketing because of President Trump's war with ...
... May 2026 $3.196, $3.278, $3.179, $3.039, $3.771, $4.236, $4.420 ... Americans feeling the cost of the war with Russia with rising prices at the ...
A growing number of gas stations along the East Coast are without ...
A growing number of gas stations along the East Coast are without fuel as nervous drivers aggressively fill up their tanks following a ...
wikipedia
Cyberwarfare by Russia - Wikipedia
Cyberwarfare by Russia comprises denial-of-service campaigns, hacking operations, disinformation programs, and state-directed online repression, ...
cnn
Iran hackers: Hackers have breached tank readers at gas stations; officials suspect Iran is responsible US officials suspectIranian hackers are behind a series of breachesof systems that monitor the amount of fuel in storage tanks serving gas stations in multiple states, according to multiple sources briefed on the activity. The hackers responsible have exploited automatic tank gauge (ATG) systems that were sitting online and unprotected by passwords, allowing them in some cases to tinker with...
abc17news
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible By Sean Lyngaas, CNN (CNN) — US officials suspectIranian hackers are behind a series of breachesof systems that monitor the amount of fuel in storage tanks serving gas stations in multiple states, according to multiple sources briefed on the activity. The hackers responsible have exploited automatic tank gauge (ATG) systems that were sitting online and unprotected by passwords, allowing t...
darkreading
Many Fuel Tank Monitoring Systems Vulnerable to Disruption Source: jittawit21 via Shutterstock RSAC CONFERENCE 2025 – San Francisco – Internet-connected automatic tank gauges (ATGs) pose a serious but often overlooked cyber-risk to the thousands of gas stations, fuel depots, and facilities that rely on these devices to monitor tank levels, temperatures, leaks, and other critical operational parameters. Pedro Umbelino, principal research scientist at Bitsight, is sounding the alarm on the ...
bitsight
Critical Vulnerabilities Discovered in Automated Tank Gauge Systems Introduction Industrial Control Systems (ICS) have become a ubiquitous part of modern critical infrastructure. Automatic Tank Gauge (ATG) systems play a role in this infrastructure by monitoring and managing fuel storage tanks, such as those found in everyday gas stations. These systems ensure that fuel levels are accurately tracked, leaks are detected early, and inventory is managed efficiently. Although the typical gas stati...
thehill
FBI: Iran-linked hackers disrupted US oil, gas, water sites Iran-linked hackers were responsible for recent disruptions to internet access for companies tied to U.S. oil, gas and water infrastructure, the FBI said in a report published Tuesday. The report warned that similar companies across the country should be aware of an increased push by hackers to take over programmable logic controller (PLC) systems, which can be used to digitally control physical machinery from remote locations. Secur...