US Automatic Fuel‑Tank Gauges Exposure Halved as Threat Actors Target Critical Infrastructure
What Happened — Over the past three months the number of publicly reachable U.S. automatic fuel‑tank gauge (ATG) IP addresses dropped from ~4,800 to 2,354, a 56 % decline. The gauges, which monitor fuel levels, temperature, moisture and alarms for gas stations, airports, hospitals, data‑centers and military sites, have been the focus of suspected Iran‑linked intrusions; ten zero‑day flaws were disclosed in six models across five vendors in 2024‑2025.
Why It Matters for Compliance & Audit Readiness
- The episode underscores the need for continuous asset‑inventory and network‑segmentation controls that SOC 2 CC 1.1 (Security) and CC 5.1 (System Operations) require.
- Demonstrating that exposed OT assets are identified, monitored, and evidence of remediation is collected satisfies the “continuous monitoring” evidence auditors look for.
- Mapping the ATG exposure to a control‑gap in your Trust Center provides defensible proof of due‑diligence for regulators and customers.
Who Is Affected – Energy & utilities, transportation, healthcare, data‑center operators, and any organization that runs on‑site generators protected by ATG devices.
Recommended Actions
- Add ATG endpoints to your asset inventory and tag them as critical OT assets.
- Enforce network segmentation and restrict inbound traffic to the ATG protocol ports (10001, 8001).
- Deploy continuous scanning and log collection to capture any exposure changes; map findings to SOC 2 controls and retain evidence in your Trust Center.
Source: Help Net Security
Technical Notes – The ATG protocol runs on TCP ports 10001 (≈84 % of sightings) and 8001. Zero‑day vulnerabilities discovered in 2024‑2025 allow remote code execution and alarm manipulation. No CVE IDs were publicly disclosed, but the flaws affect at least five vendors. The exposure metric counts unique IPv4 addresses that respond to ATG queries, not distinct devices.