Iran-Linked Hackers Suspected in US Gas Station Fuel-Monitoring Cyber Breach
US officials suspect Iranian-linked hackers accessed unprotected fuel-level monitoring systems at gas stations across multiple states. No physical damage reported, but the intrusions expose dangerous gaps in critical infrastructure security.

Gas station fuel pump with a digital display showing unusual readings, representing a cyberattack on automatic tank gauge systems
US federal officials are investigating a series of cyber intrusions targeting automatic tank gauge (ATG) systems at petrol stations across multiple states, with Iran emerging as the leading suspect. The investigation was first reported by CNN, citing sources briefed on the probe. The compromised systems monitor fuel levels at underground storage tanks and had been left exposed on the public internet without password protection. In some cases, attackers were able to manipulate the fuel level readings displayed on monitors. Investigators confirmed that actual fuel volumes in the physical storage tanks were not affected. No physical damage or injuries have been reported.
Why OT security failures made this possible
US federal officials are investigating a series of cyber intrusions targeting automatic tank gauge (ATG) systems at petrol stations across multiple states, with Iran emerging as the leading suspect. The investigation was first reported by CNN, citing sources briefed on the probe. The compromised systems monitor fuel levels at underground storage tanks and had been left exposed on the public internet without password protection. In some cases, attackers were able to manipulate the fuel level readings displayed on digital monitors. Investigators confirmed that actual fuel volumes in the physical storage tanks were not affected, and no physical damage or injuries have been reported. Federal investigators are conducting forensic analysis of the affected monitoring systems while coordinating with fuel distributors, station operators and infrastructure security teams to determine whether the activity was reconnaissance for future attacks, an attempted disruptive campaign, or both.
What ATG systems are and why they are targeted
Automatic tank gauge systems are used by petrol stations and fuel distributors to manage underground storage, detect leaks, monitor pressure and track inventory. Many of these systems were engineered decades ago, long before internet connectivity was part of the design consideration, and have since been connected to public-facing networks as part of broader remote monitoring programmes. The result is a class of operational technology that sits on the open internet, often with factory-default or no credentials, and with little to no visibility from enterprise security teams. Research from Bitsight has shown that thousands of ATG systems remain directly accessible on the public internet, with new vulnerable systems appearing online every day. The risks extend well beyond manipulated readings. Threat actors with access to an ATG system could theoretically overfill fuel tanks, disable critical safety alarms, trigger undetected leaks, or manipulate physical relays to cause lasting damage to equipment. As one security researcher summarised the exposure bluntly:
"Internet-facing ATG systems have long been vulnerable due to weak security configurations, with mock systems previously attracting Iranian-linked groups in testing environments."
A 2021 document cited by Sky News, attributed to the Islamic Revolutionary Guard Corps, explicitly identified ATG systems as a potential target for a disruptive cyberattack on petrol stations. That warning has now moved from intelligence reporting to active exploitation.
Iran as the leading suspect and the broader campaign context
Iran is the leading suspect in this investigation based on its documented history of targeting fuel and energy infrastructure. The group most closely associated with this category of targeting is CyberAv3ngers, which presents itself as a hacktivist collective but is assessed by US intelligence agencies to be an advanced persistent threat operated by the Islamic Revolutionary Guard Corps Cyber Electronic Command. This incident sits within a wider pattern of Iranian-affiliated cyber activity against US critical infrastructure that has escalated significantly in 2026. In April, CISA and federal partners issued a joint advisory warning of ongoing Iranian-affiliated APT activity targeting programmable logic controllers (PLCs) across the energy, water, healthcare and government sectors. That advisory confirmed that since at least March 2026, Iranian-affiliated actors have disrupted PLC operations at multiple US critical infrastructure organisations, with some incidents resulting in operational disruption and financial loss. Since the conflict between the US, Israel and Iran began in late February 2026, Tehran-linked actors have caused disruptions at multiple oil, gas and water sites, introduced shipping delays at medical device firm Stryker, and leaked private communications belonging to senior US government officials. This gas station intrusion fits that pattern of opportunistic, psychologically targeted operations designed to create uncertainty about the security of everyday infrastructure. Investigators have cautioned that definitive attribution in this specific case may not be possible, given the limited forensic evidence left behind. Neither CISA nor the FBI has publicly commented at the time of writing.
What security teams across the GCC should take from this
The structural vulnerability exposed by this incident is directly relevant for security teams managing fuel, energy and utilities infrastructure across the Gulf. Petrol distribution networks, terminal management systems and remote industrial monitoring platforms across Saudi Arabia, the UAE and the wider GCC share the same exposure profile as the systems targeted in the US: internet-facing, weakly authenticated and rarely subject to the same security rigour applied to IT environments. The UAE Cyber Security Council has documented over 800,000 daily cyberattacks targeting the country, and Genetec has warned that AI is accelerating credential attacks against physical security systems across the Middle East. Adding unprotected OT assets and fuel monitoring infrastructure to that threat picture compounds the exposure considerably. CISA and its federal partners have published clear guidance on securing ATG systems specifically. The recommended actions are as follows. Disconnect ATG systems from the public internet entirely, and if remote access or polling is operationally required, place the device behind a secured VPN gateway with enforced authentication. Replace any factory-default passwords with long, unique credentials. Deploy industrial firewalls in front of ATG systems to filter unauthorised access. Ensure that back-office and point-of-sale networks are properly segmented from OT assets so that a compromise in one environment cannot propagate to fuel management systems. Finally, prepare manual gauging and control procedures that can be activated in the event of a network outage or cyber incident. For GCC security leaders, the broader lesson is that OT security can no longer be treated as a deferred IT project. State-linked actors have demonstrated both the capability and the intent to target physical infrastructure through digital means, and the consequences of a successful attack on a fuel system extend from operational disruption into public safety.
Iran as the leading suspect
Iran is cited as the leading suspect based on its documented history of targeting fuel and infrastructure systems, including prior incidents affecting US water, energy and critical national infrastructure. However, investigators have cautioned that definitive attribution may not be possible in this case, given the limited forensic evidence left by the attackers. This is characteristic of operationally mature intrusion campaigns designed to preserve plausible deniability. Experts cited in the CNN report noted that Iran's cyber operations have grown more frequent, more opportunistic, and increasingly integrated with broader psychological influence campaigns in recent years. Neither CISA nor the FBI has publicly commented on the incidents at the time of writing. One security researcher familiar with ATG exposure summarised the structural problem clearly:
"Internet-facing ATG systems have long been vulnerable due to weak security configurations, with mock systems previously attracting Iranian-linked groups in testing environments."
What this means for GCC energy and utilities teams
The pattern is directly relevant for security teams managing fuel and energy infrastructure across the Gulf. Petrol distribution networks, terminal management systems and industrial monitoring platforms across the region share the same exposure profile as the systems targeted in this incident: internet-facing, weakly authenticated, and rarely subject to the same security rigour applied to IT environments. AI is already accelerating credential attacks on physical security systems in the Middle East, as Genetec recently warned. Adding unprotected OT assets to that risk picture compounds the exposure significantly. Organisations managing fuel infrastructure, port logistics and utilities across Saudi Arabia and the wider Gulf should treat this development as a direct prompt to take the following actions. First, audit all internet-facing OT assets, including ATG systems, SCADA interfaces and remote monitoring panels, and confirm none are accessible without authenticated access controls. Second, enforce network segmentation between IT and OT environments so that a compromise in one domain cannot propagate to the other. Third, ensure that all OT monitoring systems are placed behind authenticated access controls and removed from public-facing network ranges entirely.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.