Full Breakdown
Suspected Iranian Hackers Breach Fuel Tank Monitors at U.S. Gas Stations
5/16/2026, 4:28:34 AM
Unauthorized ATG Access
U.S. officials detected unauthorized access to automatic tank gauge (ATG) systems at gasoline stations. Hackers changed display readings without altering fuel volumes; no spills or injuries were reported.
Iranian Cyber Pattern
The breaches fit a pattern of Iranian cyber activity that surged after the February 2024 war. A 2021 IRGC document singled out ATGs, and similar attacks have struck U.S. water utilities and medical-device firms.
Actors & Agencies
Suspected actors include the Handala hacktivist persona tied to Iran’s IRGC. U.S. agencies CISA, FBI and DHS are probing, while Israel’s cyber chief Yossi Karadi and researchers at PwC, Sublime Security and Bitsight have examined the incidents.
ATG Exposure
Bitsight’s TRACE platform cataloged thousands of internet-exposed ATGs at gas stations, power plants, airports and military bases. A CNN poll shows 75 % of U.S. adults say the Iran-U.S. war hurts their finances, raising fuel-price concerns.
Risks & Politics
Compromised ATGs could hide gas leaks or falsify inventory, risking environmental harm and artificial fuel shortages. The timing adds political pressure ahead of the 2026 midterm elections.
Official Responses
Karadi warned Iranian actors are under pressure to exploit any opening. Wikoff noted an accelerating, AI-driven playbook. Edwards said the attack surface exceeds most expectations.
Criticism
Security analysts criticize owners for leaving ATGs online despite CISA’s guidance to disconnect or firewall them. Officials note the lack of forensic evidence, urging caution on attributing the breach to Tehran.
Attribution Gaps
Sources suspect Iranian involvement, but investigators lack definitive malware signatures or command-and-control traces. The number of affected stations and any physical damage remain unknown.
Future Guidance
Federal agencies will likely issue advisories to pull ATGs from the public internet, use VPNs, strong passwords, firewalls and manual gauging, and fund attribution research.
Quotes
- “The bottom line is that Iranian actors are under pressure and are trying to strike wherever they find an opening in cyberspace.” — Yossi Karadi, Head, National Cyber Directorate, Israel
- “What’s notably new in their cyber playbook is the swift creation of ‘good-enough’ malware, including the destructive wiping types, complemented by assertive hack-and-leak campaigns against media, dissidents, and key (US) civilian infrastructure.” — Allison Wikoff, Director, Threat Intelligence, PwC
- “The fact that every Handala claim leads to people freaking out demonstrates that the operational reality of the threat Iran poses is something that both government agencies and vendors don’t seem to be able to articulate.” — Alex Orleans, Threat Intelligence Lead, Sublime Security
- “What today’s reported activity makes clear is that these systems are an active target, and the attack surface is larger than most people realize.” — Ben Edwards, Principal Research Scientist, Bitsight
