U.S. officials are concerned that Iranian hackers have targeted systems monitoring fuel storage at gas stations in several states. Reports suggest these hackers accessed automatic tank gauge (ATG) systems that were online without proper security measures. Although no physical harm has been reported, the potential for creating unsafe situations, like unnoticed gas leaks, raises alarms among experts.
Why the focus on Iran? This country has a history of targeting fuel systems, making it a prime suspect in these breaches. However, U.S. officials warn that without clear evidence, pinpointing exact culprits can be tricky.
If confirmed, this incident highlights an ongoing threat from Iran to U.S. infrastructure. During the recent conflict, Iranian hackers have shown adaptability and resourcefulness. They previously targeted U.S. water utilities following the October 7, 2023, Hamas attacks on Israel, displaying messages against Israel on water management equipment.
Despite warnings from cybersecurity experts about vulnerable ATGs, many critical U.S. systems remain unprotected. In a demonstration back in 2015, Trend Micro set up mock ATGs online, quickly attracting hackers, including those affiliated with Iran. A 2021 report noted that internal Iran documents identified ATGs as key targets for cyberattacks aimed at disrupting gas stations.
While some view Iran’s capabilities as inferior to China and Russia, recent opportunistic hacks suggest otherwise. Since the start of hostilities in February, Iranian-linked hackers have caused disturbances in U.S. oil, gas, and water sectors, disrupting operations and even leaking sensitive information from an FBI official.
Yossi Karadi, head of Israel’s National Cyber Directorate, emphasized that Iran’s cyber activities have become faster and more integrated with psychological warfare tactics. The Israeli military has even targeted Iranian cyber operations, indicating the seriousness of the threat.
Allison Wikoff from PwC has observed that Iran recently engaged in creating faster, simpler malware, marking a shift in its cyber strategy. Their operations now include aggressive campaigns against media and civilian infrastructure.
Interestingly, the public reaction to these hacks has often been one of alarm, especially when hackers boast of breaching federal systems. Alex Orleans, a cybersecurity expert, notes that while the Iranian threats have been significant, there are reasons why more extensive attacks haven’t occurred. These include limited access to targets and a strategic choice to avoid reckless cyber operations.
As the U.S. approaches the midterm elections, the looming threat of Iranian cyber operations is a concern. After incidents in the 2020 elections where Iran allegedly tried to intimidate voters, officials worry that similar tactics might resurface. Some experts believe Iranian actors will likely focus on disinformation campaigns rather than direct attacks on election systems, as these methods are cheaper and easier to implement.
This situation calls for proactive measures. The continued vulnerabilities in critical infrastructure, coupled with Iran’s evolving tactics, showcase a pressing need for improved cybersecurity defenses. As cities and states work to protect essential services, staying ahead in this digital battlefield is more important than ever.

