US Fuel Tank Gauge Exposure Plummets Amidst Security Advisories
Internet-connected fuel tank gauges in the US have seen their exposure drop by over 50% in three months, following urgent advisories and suspected nation-state activity.

Internet-connected automatic tank gauges (ATGs) used to monitor fuel levels at critical infrastructure sites across the United States have experienced a dramatic reduction in their online exposure. Data from BitSight indicates that the number of internet addresses responding to the ATG protocol has fallen by more than half, from approximately 4,800 monthly addresses to just 2,354 by June. This significant decline, observed consistently across April, May, and June, also surpasses previous year's figures, suggesting a proactive response to security concerns.
The reduction is not attributed to transient factors like address churn or port hopping, which could artificially inflate or deflate exposure numbers. BitSight's analysis, which examined exposure on both the primary port 10001 and a secondary port 8001, revealed that the steep decline was primarily concentrated on the default port 10001. While port 8001 saw a minor decrease, the significant drop on port 10001 points to genuine remediation efforts rather than network fluctuations.
These ATGs, found not only at gas stations but also under airports, hospitals, power plants, and military bases, track vital metrics such as fuel level, temperature, moisture, and leaks. They also control alarms and fume extractors. The potential for attackers to alter readings, disable alarms, or damage hardware makes their exposure a significant security risk. BitSight had previously identified numerous zero-day vulnerabilities in gauges from multiple vendors, underscoring the inherent risks associated with these devices.
The sharp decrease in exposure appears to coincide with urgent advisories issued by industry bodies and government agencies. The Energy Marketers of America (EMA) released an advisory on April 14, warning of attackers targeting unprotected tank gauges, with suspicions pointing towards Iran. This warning was amplified by industry channels and later reported by CNN on May 15, weeks after the initial alert.
Prior to this decline, US exposure figures had remained relatively stable for nearly a year, hovering between 4,300 and 5,300 addresses per month. The drop began in April, with a 27.6% decrease, followed by a further 31.8% fall in May, and culminating in the 56% reduction from the March peak by June. The decline outside the US was less pronounced, approximately 26% over the same period, further highlighting the targeted nature of the remediation efforts within the United States.
While BitSight stops short of definitively attributing the reduction to specific actors, the pattern is consistent with operators acting on the advisories. The company credits a collective effort involving CISA, US law enforcement, industry associations, integrators, and operators. However, the analysis also points out that simply stopping external scans does not equate to complete security. Gauges behind firewalls or NAT gateways may still be vulnerable if accessed laterally within a network, and newer web-based consoles with default credentials remain a target.
The report emphasizes the need for ongoing measurement of risk reduction and remediation rates. The success seen in reducing ATG exposure offers a model for how coordinated advisories and industry-wide action can lead to tangible security improvements. However, it also serves as a reminder that securing industrial control systems requires a multi-layered approach, addressing both external exposure and internal network security.
The data also highlights a potential blind spot: systems operating on less common ports, such as port 8001, may not have seen the same level of attention. This suggests that organizations relying on these systems should ensure their security posture is comprehensively reviewed, not just for the most commonly exposed configurations.