In April, the Energy Marketers of America warned members that attackers were targeting internet-exposed automatic tank gauge (ATG) systems, citing incidents in Tennessee including one convenience-store chain with at least fifteen tanks affecte CNN reported the story nationally in May. On June 2, CISA and seven federal partners—including the FBI, NSA, and Department of Energy—issued a joint advisory urging critical-infrastructure operators to remove their tank gauges from direct internet exposure. Days later, the Shadowserver Foundation reported that more than 1,000 ATG systems remained exposed on the public internet on TCP ports 8001, 9001, and 10001.
If you missed the news cycle, the short version is that attackers found internet-accessible ATGs, modified system information and, in some cases, deleted sensor and tank configuration. No physical impacts were publicly reported. But the potential consequences were serious: a real leak or equipment problem could pass undetected if an attacker altered readings, thresholds, or alarms.
What we saw in the field
Across the sites our team monitors, we watched both waves of this campaign unfold in real time, and the field picture was more textured than the headlines suggested.
Among the incidents PDS observed, the earlier and more destructive cases involved Franklin systems. Some affected sites lost their programming entirely and had to be reconfigured from scratch—tank strappings, alarm thresholds, product assignments, and sensor settings. That is a nontrivial recovery requiring an on-site service visit, careful re-entry of tank data, and independent confirmation that inventory and leak-monitoring functions are reliable before normal operations resume. Public coverage focused largely on Veeder-Root, but Franklin operators should understand that some systems in the field experienced significant configuration loss.
In later incidents PDS observed involving Veeder-Root TLS-350 and TLS-450 Plus consoles, the changes were generally less destructive. In most of those cases, attackers changed tank names and left the remaining configuration intact. That was still enough to make an operator distrust the console until every critical setting had been reviewed, but it was not the same programming-loss event seen in the Franklin cases we encountered.
Geographically, we saw incidents across both coasts of the United States and in Canada. That spread matters. Whatever the attackers’ intent, the operational pattern appeared less like a campaign against particular regions and more like broad scanning for whatever was reachable on the open internet.
What protected the sites that did not get hit
The pattern in what we did not see is at least as instructive as what we did.
Across the same fleet, sites not exposed to the public internet—such as those monitored through private cellular and VPN connections that did not permit unsolicited public-internet access—were not impacted. Sites monitored through IP polling were affected only when the console was directly reachable from the public internet, for example when a router forwarded inbound traffic from anywhere on the internet to the ATG’s serial or web interface.
The meaningful distinction is exposure, not simply whether a connection uses cellular service or the internet. Architectures using a private cellular APN or an outbound-initiated VPN sharply reduce the internet-facing attack surface because the ATG does not accept unsolicited public connections. Where inbound polling is necessary, a firewall or access-control list should restrict it to specifically authorized monitoring addresses. Remote administration should use authenticated VPN access rather than an internet-facing ATG web or serial interface.
Many ATG consoles in service today are decades old and still doing their core job perfectly well, and the installed base is not going to turn over quickly. That is fine. For most operators, the fastest and least expensive path to security is not replacing the ATG but putting a modern communications gateway or firewall between the console and the outside world, so that gateway—not the ATG—is what accepts or initiates every remote connection. Well-built older hardware behind a properly configured perimeter is not the profile that got hit this summer.
The underlying problem is not new
Security researchers have been publishing on this issue since at least 2015. Bitsight later published technical research covering the Franklin TS-550 and systems from several other vendors, and the June 2026 CISA fact sheet cites that work directly. The prescriptive advice has not changed in a decade because the underlying problem has not changed: legacy operational technology was connected to a hostile network without adequate access controls.
What changed this year is that attackers found real operators still leaving the door open, at scale.
Five things to do now
The federal guidance provides a useful starting point. In practical terms:
- Eliminatepublic internet exposure. Do not expose an ATG serial port, including TCP ports 8001, 9001, or 10001, or an ATG web interface directly to the internet. Use a private cellular APN, an outbound-initiated VPN, or a firewall or access-control list that permits only specifically authorized monitoring sources.
- Change default credentials. Set strong, unique security codes and administrative credentials on every console, communications card, router, modem, VPN, and remote-access interface. Use phishing-resistant multifactor authentication on the VPN or remote-access platform wherever feasible.
- Patch what you can. Work with a certified ATG service provider to verify model-specific security guidance, supported firmware, and applicable patches.
- Segment the ATG network. Place the ATG and its communications equipment on a dedicated network segment separated from point-of-sale, payment, office, and guest networks. Permit only the specific traffic required for monitoring and service.
- Monitor and report. Enable ATG audit logging where available, but also retain firewall, VPN, cellular-router, and remote-monitoring logs. Watch for unexpected inbound connections, repeated authentication failures, suspicious alarms, tank-label edits, alarm-threshold changes, and other configuration changes. Report suspected incidents promptly to CISA.
Questions to ask this week
Five concrete questions to your ATG service provider and IT contact will reveal most of what you need to know:
- Are any ATG serial ports, web interfaces, routers, or remote-access services reachable from the public internet?
- Is every remote connection restricted by a private APN, VPN, or source-IP allowlist?
- Are the ATG and its communications equipment using unique, non-default credentials?
- Is the ATG isolated from the POS, payment, office, and guest networks?
- Do we have a current backup or written baseline of each console’s tank, alarm, sensor, relay, user, and network configuration?
A competent provider should be able to answer these questions clearly and in writing. If yours cannot—or will not—that is useful information too.
If you suspect a compromise
Do not simply change a tank name back and assume the problem is resolved. Restrict the ATG’s network access, preserve available logs, contact the certified ATG service provider, and compare every tank, alarm, sensor, relay, user, and network setting against a known-good configuration. Confirm that inventory and leak-monitoring functions are reliable before returning the console to normal remote operation, and report suspected activity to CISA.
The line worth drawing
Many of the first steps—closing exposed ports, changing default credentials, and documenting remote connections—are inexpensive, and rarely require replacing equipment that is otherwise doing its job. Network redesign may require planning, but leaving a safety and compliance system exposed is the more expensive risk.
ATGs have historically been treated as appliances: install them, connect them, and do not think about them again until they alarm. The summer attacks are the moment to change that. The equipment monitoring the tanks beneath your sites is part of your cybersecurity perimeter, whether you designed it that way or not. Treat it accordingly, and this becomes an old story instead of a recurring one.

