Internet-exposed Automatic Tank Gauge (ATG) systems in the United States fell sharply after industry and government warnings about active attacks against unprotected fuel monitoring consoles. BitSight reported that U.S. exposure on the ATG protocol dropped about 56% from its March 2026 peak to June, while global exposure declined 49%, with most of the reduction concentrated in the U.S. The decline followed alerts from the Energy Marketers of America, the Tennessee Fuel & Convenience Store Association, DOE CESER, and CISA, which urged operators to harden ATG deployments.
BitSight said the reduction appears to reflect real remediation rather than scanning anomalies, citing churn analysis, port-hopping checks, and comparison against control traffic on port 8001. A second dataset tracking confirmed vulnerable web-facing ATGs showed a smaller but similar decline beginning in April, although some devices resurfaced in June. Officials and researchers warned that significant risk remains because many ATGs are still reachable over 10001, 8001, or web interfaces, and moving systems behind VPNs, NAT, or firewalls may reduce visibility without fixing the underlying vulnerabilities or potential physical-world impact.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
On June 2, 2026, CISA and seven other federal agencies published a joint fact sheet recommending strong passwords and removal of Automatic Tank Gauges from the public internet. The guidance followed the spring 2026 ATG attack activity and provided concrete mitigation steps for operators.
By June 2026, Bitsight observed that U.S. internet-exposed ATG systems had fallen 56% from their March 2026 peak, while global exposure fell 49%. Bitsight linked the sustained three-month decline to remediation following the April attack advisories rather than scan noise.
In May 2026, CNN reported on suspected Iran-linked intrusions targeting internet-connected Automatic Tank Gauges in the United States. The reporting connected the campaign to the attack activity that had prompted April advisories.
On April 14, 2026, the Energy Marketers of America warned of active attacks on Automatic Tank Gauges in Tennessee and nationwide. The advisory said unprotected ATG consoles were the primary targets and noted that many suspected Iran was behind the attacks.
Around April 30, 2026, a follow-up advisory reported by the Tennessee Fuel & Convenience Store Association and republished by the Texas Food & Fuel Association reiterated coordination among industry groups, DOE CESER, and CISA. The notice continued the response to the ATG attack activity disclosed earlier in April.
Bitsight reported that internet-exposed Automatic Tank Gauge systems in the United States peaked in March 2026 before beginning a sharp decline. This peak became the baseline for later measurements showing a 56% drop by June 2026.
In 2025, Bitsight said it identified five additional vulnerabilities affecting Automatic Tank Gauge systems. Across its ATG research, Bitsight said the findings included five high-severity and ten critical vulnerabilities.
In September 2024, Bitsight TRACE reported finding 10 zero-day vulnerabilities across six Automatic Tank Gauge systems from five vendors. The research highlighted serious security weaknesses in internet-connected fuel gauge infrastructure.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcebitsight.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.