news.mlab.sh
Back to the feed
threat-intel

CISA and Partners Urge Hardening Automatic Tank Gauge Systems

High
Summary

CISA, alongside several US government agencies, has issued an alert regarding malicious cyber activity targeting Automatic Tank Gauge (ATG) systems used across sectors like energy, chemicals, and transportation. Cyber actors are exploiting vulnerabilities such as weak passwords and internet exposure to compromise ATG systems, potentially manipulating tank levels and causing operational disruptions. The agencies are urging ATG owners and operators to immediately harden their systems by removing internet access and implementing stronger security measures.

The Cybersecurity and Infrastructure Security Agency (CISA) and a coalition of US government agencies, including the FBI, NSA, DOE, EPA, TSA, DOT, and USDA, are responding to a growing threat targeting Automatic Tank Gauge (ATG) systems. These systems, vital for monitoring fuel and liquid levels in storage tanks, are increasingly exposed to the internet, creating an entry point for cyberattacks. The threat actors are exploiting vulnerabilities like weak passwords and open internet access to gain unauthorized control over the systems.

The observed malicious activity involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution. Specifically, they can alter system attributes, compound operational malfunctions, and disable system alerts, increasing the risk of environmental or physical hazards. The agencies are highlighting the potential for disruption to critical infrastructure and the need for immediate action. They are providing guidance on mitigating these risks, including restricting internet access and implementing strong authentication protocols.

The authoring organizations recommend ATG owners immediately implement the following recommendations: Eliminate public internet exposure, restrict access using firewalls or VPNs, enforce credential security with strong passwords and MFA, apply patches, and monitor networks for unauthorized access. These measures aim to reduce the attack surface and limit the potential damage from a successful compromise.

Read the full article at CISA Advisories