After recent reports of Iran-linked operators targeting automatic tank gauge (ATG) systems at US gas stations, new analysis shows thousands of unprotected devices still exposed to the public internet. These devices, which monitor fuel inventory, are designed to be accessible without authentication, making them easily accessible by threat actors.

As of May 2026, over 6,502 ATG services running on 6,057 unique hosts were found to be reachable on the public internet across more than 65 countries, excluding honeypots, according to new data from Censys. The Censys report follows revelations last week that attackers suspected to be aligned with Iran have accessed ATGs at stations across the U.S.

The exposure is heavily concentrated in the United States, which accounts for approximately 70 percent of the total, or 4,224 hosts. The second-most affected region is Puerto Rico, with 350 hosts, 347 of which are concentrated on a single ISP (COQUI-NET / DATACOM CARIBE).

The primary ASNs exposing these devices are residential and small-business broadband and cellular ISPs:

  • Verizon Wireless / CELLCO-PART (667)
  • Comcast / CMCS (373)
  • CYBERA Inc. (281)
  • Charter / CHARTER-20115 (241)
  • AT&T (208)
  • UUNET / Verizon Business (171)

Critical Data Leakage and Reconnaissance

The vulnerability of these devices is not just a matter of unauthorized access; it facilitates broad reconnaissance for adversaries. A total of 3,907 services (60.1 percent of the total exposed) openly broadcast a full I20100 in-tank inventory. Iranian threat actors have proved themselves to be quite capable, and the ongoing conflict between the U.S. and Iran has certainly raised the stakes for cyber operations.

This leakage includes detailed identifying and operational information:

  • Station brand, name, and street address
  • Sometimes a phone number
  • Live volume / ullage / water-bottom readings

And, 3,907 of these exposed services openly broadcast the station’s brand, street address, and on-site phone number, meaning the necessary reconnaissance is already done for any attacker looking to take advantage of these devices.

US officials suspect Iran-linked operators were behind recent intrusions against unprotected, internet-facing ATGs at US gas stations, according to a report from CNN. Attackers reached devices “sitting online and unprotected by passwords” and successfully altered on-display fuel readings.

Investigators emphasized that physical fuel levels were not changed. However, by protocol design, the same access channel that permitted altering on-display readings could also be used to permit a real leak to go undetected.

The exposed infrastructure includes major fuel retailers:

  • Shell (602)
  • Mobil (184)
  • BP (78)
  • Texaco (68)
  • Puma (52, LatAm)
  • Marathon (47)
  • Exxon (41)
  • Sunoco (37)
  • Gulf (32)
  • Citgo (31)
  • Chevron (23)
  • Valero (23)

The continued exposure of thousands of Automatic Tank Gauges, often connected via residential-grade ISPs and completely lacking authentication, represents a severe and unaddressed risk in critical infrastructure. Given that nation-state actors have already demonstrated the capability to exploit these systems to alter readings, organizations must treat this as an active threat.