• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

FBI: CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Commonground

Senior Moderator
FBI – Federal Bureau of Investigation

21h ·
Malicious cyber actors are targeting U.S.-based automatic tank gauge (ATG) systems, widely used throughout the Energy, Chemical, Food and Agriculture, and Transportation Systems Sectors. The threat actors exploit flaws in ATG systems through multiple attack vectors, compromising internet-exposed ATG systems and subsequently modify them through command execution.

The #FBI, CISA, NSA, DOE, EPA, TSA, DOT, and USDA urge ATG owners and operators to defend against this malicious activity by securing their ATG systems with with strong authentication and segmentation practices. Learn more: https://www.ic3.gov/CSA/2026/260602.pdf

https://www.facebook.com/FBI/posts/...ic-tank-gauge-atg-systems-w/1412545320919030/


From PDF:

Overview

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the

National Security Agency (NSA), the Department of Energy (DOE), the Environmental Protection Agency

(EPA), the Transportation Security Administration (TSA), the Department of Transportation (DOT), and the

U.S. Department of Agriculture (USDA)—hereafter referred to as “the authoring organizations”

—are aware of

malicious cyber activity targeting U.S.-based automatic tank gauge (ATG) systems. ATG systems are widely

used throughout the Energy, Chemical, Food and Agriculture, and Transportation Systems Sectors for

automated and remote monitoring of storage tank parameters, including fuel and liquid levels,

temperature, and possible leak detection. The authoring organizations urge ATG owners and operators to

defend against this malicious activity by securing their ATG systems with strong passwords and by

removing them from the internet to reduce public exposure.

Threat

The recent malicious cyber activity observed by the authoring organizations—which the U.S. government

has not yet attributed to a nation-state or threat actor group—involves cyber threat actors compromising

internet-exposed ATG systems and subsequently modifying them through command execution. This fact

sheet provides insight into probable tactics, techniques, and procedures (TTPs) leveraged by these cyber

actors, highlights risk factors associated with such compromises, and provides mitigation guidance and

resources to reduce the likelihood of continued malicious activity targeting U.S.-based ATG systems.

Cyber threat actors may exploit flaws in ATG systems through multiple attack vectors:

▪ Authentication Bypass and Hardcoded Credentials: Threat actors gain unauthorized access to

device management interfaces.

▪ OS Command Execution and Structured Query Language (SQL) Injection: Threat actors execute

arbitrary code and manipulate underlying databases.

▪ Privilege Escalation: Threat actors achieve full administrator privileges over the device application

and operating system.

Should a cyber threat actor exploit these vulnerabilities and compromise an ATG system, they could disrupt

or manipulate the below critical functions by interfacing directly with the tank management as though they

possessed legitimate physical access to the system console. The cyber threat actors could:


▪ Alter system(s) attributes, such as network settings, product identifiers, tank volumes, and pump

controls;

▪ Compound operational malfunctions; components operating incorrectly could create a denial of

view condition of tank fill levels, which could cause permanent damage to the tank system’s critical

function;

▪ Disable system alerts, reducing an operator’s ability to detect and mitigate system issues increases

the risk of environmental or physical hazards from incidents such as leaks or relay failures.

Continued: https://www.ic3.gov/CSA/2026/260602.pdf
 
Back
Top