Suspected Iranian hackers breached internet-exposed automatic tank gauge (ATG) systems at gas stations in several U.S. states, reportedly targeting Veeder-Root TLS-350 and TLS-450 Plus consoles that lacked password protection rather than exploiting a newly disclosed flaw. Advisories said incidents affected sites in Tennessee, including one convenience store chain with 15 tanks impacted, and in some cases attackers deleted fuel tank and sensor data or altered system settings. Officials said no physical damage was reported, but security experts warned that compromised ATGs could enable fuel overfills, disable safety alarms, and cause environmental or equipment damage.
The intrusions come amid a broader surge in attacks on operational technology across industrial sectors. NCC Group said industrial organizations suffered 2,073 ransomware attacks in the 12 months to March 2026, accounting for 30% of all ransomware activity, with manufacturers of capital goods, machinery, construction, and engineering among the hardest hit. The report said many organizations still prioritize IT defenses over OT security even as governments and regulators expand resilience requirements, while international authorities have issued procurement guidance to push stronger security controls into OT products and supply chains.

Map this exposure pattern across your cloud, code, and identities.
8 events from the most recent confirmed update back to the earliest known activity.
Shadowserver reported seeing 1,061 internet-exposed automatic tank gauge IPs on 2026-06-05 after filtering out many apparent honeypots, including 909 in the United States. The figures provided an updated snapshot of the attack surface amid ongoing federal warnings about ATG targeting.
CISA and multiple U.S. government partners published a joint fact sheet urging stronger security for automatic tank gauge systems targeted by cyber threat actors in the United States. The guidance recommended measures including removing ATG systems from the internet, using strong passwords, and auditing and monitoring logs.
Following the gas station tank gauge compromises, response efforts involved the Department of Energy's CESER team and CISA. Officials and industry groups warned that compromised ATGs could create overfill, alarm failure, environmental, and equipment damage risks even though no physical damage was reported.
Suspected Iranian hackers breached automatic tank gauge systems at gas stations in several U.S. states by accessing internet-exposed Veeder-Root consoles that lacked password protection. In Tennessee, attacks affected at least one convenience store chain with 15 tanks impacted, and some systems had fuel tank and sensor data deleted or settings changed.
Censys reported that 6,502 Automatic Tank Gauge services on 6,057 hosts across more than 65 countries were publicly reachable in May 2026, with all indexed services accessible without authentication because the protocol lacked login controls. The firm said 3,907 services exposed full unauthenticated inventory responses containing station identity and live tank data, with the United States accounting for about 70% of exposed hosts.
NCC Group reported that industrial organizations experienced 2,073 ransomware attacks in the 12 months ending in March 2026, accounting for 30% of all ransomware activity. Manufacturers of capital goods, especially machinery, construction, and engineering firms, were identified as the hardest-hit segments.
International authorities including the UK NCSC and partners from the US, Australia, Canada, and Europe issued procurement guidance to help operational technology owners embed security requirements into products and systems. The guidance reflected growing regulatory focus on OT resilience and supply-chain security.
CISA and the FBI warned that Iran-linked cyber actors were targeting critical infrastructure organizations, highlighting ongoing risks to internet-exposed operational technology and other poorly secured systems. The alert provided an earlier official warning context for later concerns about Iranian activity affecting exposed industrial environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
19 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourcescworld.com
Open sourceenergymarketersofamerica.org
Open sourceattack.mitre.org
Open sourcenextgov.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.