Executive Summary
In May 2026, Iranian hackers reportedly breached automatic tank gauge (ATG) systems monitoring fuel levels at gas stations across multiple U.S. states. These systems, exposed online without password protection, allowed attackers to alter display readings without affecting actual fuel levels. While no physical damage occurred, the incident underscores vulnerabilities in critical infrastructure. (abc17news.com)
This breach highlights the evolving nature of cyber warfare, where nation-state actors target essential services. The incident serves as a stark reminder for organizations to secure internet-facing operational technology systems to prevent potential disruptions and safety hazards.
Why This Matters Now
The incident underscores the urgent need for securing critical infrastructure against cyber threats, especially as nation-state actors increasingly target essential services. Organizations must prioritize the protection of internet-facing operational technology systems to prevent potential disruptions and safety hazards.
Attack Path Analysis
Attackers exploited internet-exposed Automatic Tank Gauge (ATG) systems lacking password protection to gain initial access. They then manipulated display readings to mislead operators about fuel levels. No further escalation or movement was detected. The attackers established control over the ATG systems to alter data. No data exfiltration was reported. The impact was limited to potential safety risks due to false readings.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited internet-exposed Automatic Tank Gauge (ATG) systems lacking password protection to gain initial access.
Related CVEs
CVE-2024-2442
CVSS 7.5A path traversal vulnerability in Franklin Fueling System EVO 550 and EVO 5000 allows remote attackers to read arbitrary files on the system.
Affected Products:
Franklin Fueling System EVO 550 – < 2.26.3.8963
Franklin Fueling System EVO 5000 – < 2.26.3.8963
Exploit Status:
no public exploitCVE-2025-2567
CVSS 9.8An authentication bypass vulnerability in certain Automatic Tank Gauge (ATG) systems allows attackers to modify settings and disable fuel monitoring, leading to potential safety hazards.
Affected Products:
Veeder-Root TLS4B Automatic Tank Gauge System – All versions
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Internet Accessible Device
Exploit Public-Facing Application
Brute Force I/O
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Public-Facing Applications
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Access Controls
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Primary target of Iran's fuel tank gauge attacks, facing critical infrastructure vulnerabilities in ATG systems requiring immediate segmentation and encrypted traffic protection.
Utilities
High exposure to Internet-facing operational technology systems exploited by Iranian actors, necessitating zero trust segmentation and enhanced east-west traffic monitoring capabilities.
Transportation
Vulnerable through fuel supply chain dependencies and exposed ATG systems at distribution points, requiring egress security and multicloud visibility for resilience.
Government Administration
Critical infrastructure protection mandate amid geopolitical cyber warfare, demanding comprehensive threat detection and anomaly response capabilities across all operational technology assets.
Sources
- Fuel Tank Breaches Expand Scope of Iran's Cyber Offensivehttps://www.darkreading.com/cyberattacks-data-breaches/fuel-tank-breaches-expand-scope-irans-cyber-offensiveVerified
- Franklin Fueling System EVO 550/5000 | CISAhttps://www.cisa.gov/news-events/ics-advisories/icsa-24-079-01Verified
- CVE-2025-2567: ATG System Auth Bypass Vulnerabilityhttps://www.sentinelone.com/vulnerability-database/cve-2025-2567/Verified
- Suspected Iranian Hackers Breach US Gas Station Fuel Systemshttps://www.jpost.com/international/article-896341Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit internet-exposed ATG systems and manipulate fuel level readings, thereby reducing the potential safety risks associated with false data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix Zero Trust CNSF would likely have constrained unauthorized access to ATG systems by enforcing strict access controls and segmenting network traffic.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely have restricted attackers' ability to alter display readings by enforcing least-privilege access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely have constrained any potential lateral movement by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely have detected and constrained unauthorized control over ATG systems by providing real-time monitoring and policy enforcement.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely have limited potential data exfiltration by controlling outbound traffic.
Aviatrix Zero Trust CNSF would likely have reduced the scope of impact by limiting attackers' ability to manipulate critical system data, thereby mitigating potential safety risks.
Impact at a Glance
Affected Business Functions
- Fuel Monitoring
- Inventory Management
- Environmental Safety
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement strong password policies and ensure all internet-facing systems are secured.
- • Regularly audit and monitor ATG systems for unauthorized access or anomalies.
- • Apply network segmentation to isolate critical infrastructure from external networks.
- • Deploy intrusion detection systems to identify and respond to unauthorized activities.
- • Educate staff on cybersecurity best practices and the importance of securing operational technology.



