US fuel gauge exposure fell by more than half in three months
Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the decline holds up against checks for address churn and port hopping. Exposure figures rarely move this way, and almost never this fast.

U.S. ATG protocol internet exposure, May 2026 (left) and June 2026 (right) – Source: BitSight
Behind those addresses sit automatic tank gauges, the computers under gas station forecourts that track fuel level, temperature, moisture, and leaks, and that can also control the alarms and fume extractors. The same devices sit under airports, hospitals, power plants, data centers, and military bases, anywhere fuel is kept on site for a backup generator. Someone who reaches one can alter the readings, disable the alarms, or damage the hardware. Bitsight, which found ten zero-day flaws in six gauges from five vendors in 2024 and five more in 2025, ran a connected relay past its duty cycle in a lab until it burned out.
The Energy Marketers of America put out an urgent advisory on April 14. Attackers were hitting tank gauges in Tennessee and around the country, unprotected consoles were the main target, and many suspected Iran. EMA and the Tennessee Fuel & Convenience Store Association were already coordinating with CISA and the Department of Energy’s CESER office. CNN reported the suspected Iran-linked intrusions on May 15, weeks after the warning had gone out through industry channels.
The fall started in April
From June 2025 through March 2026, the US count sat between roughly 4,300 and 5,300 a month, with a 2025 average of 4,815. April dropped 27.6 percent to 3,850. May dropped another 31.8 percent to 2,624. June closed at 2,354, or 56 percent under the March peak.
What gets counted is the unique IPv4 address returning a valid tank gauge protocol response in a month, which is not the same as a device. A gauge on a broadband line takes a new address whenever the provider issues one, so a device that moved looks identical in the data to one that was unplugged.
Outside the US the fall was gentler, about 26 percent over the same window compared with 56 percent inside it. The steepest decline landed in the country the advisories described as under attack.
A second port shows this is not scanner noise
Address churn alone could produce this pattern, and so could a scanner covering less ground in June than in January. The dataset answers both objections with a control.
Port 10001 supplies about 84 percent of what Bitsight sees, and port 8001 covers a smaller population on the same sorts of networks, reached by the same scanner in the same months. US addresses on port 10001 went from 4,214 in January to 1,466 in June, down 65 percent. Port 8001 went from 885 to 849, down 4 percent. Churn and thin scan coverage would show up on both. Only one emptied.
Port 8001 also puts a number on churn. Its total barely moved over those six months, yet about a fifth of its January addresses were gone by June. Carry that rate across and about 870 of port 10001’s departures fall into the same category, leaving roughly 2,260 addresses, close to three quarters, that look like genuine removals. The figure assumes both populations churn at similar rates, which the report calls an approximation. The 3,127 addresses present in January and absent in June outnumber the net fall from 4,214 to 1,466, and thirteen of them turned up on another tank gauge port.
Port 10001 is a factory default. Networking these consoles meant bridging the old Veeder-Root serial line to TCP, very often through a Lantronix adapter that listens on 10001 out of the box. A class of safety-critical equipment is reachable there because one hardware vendor picked the number.
The drop held
A single month proves nothing, because a console or two comes offline when an advisory lands and the count creeps back up once attention moves elsewhere. This decline is in its third month under the whole of the previous year’s floor and still going down. April’s break arrives during the advisory cycle, ahead of the general public reporting, and against ten months of flat baseline it reads as a step change rather than drift.
Bitsight stops short of calling this proof. The pattern is consistent with operators acting on the advisories, and credit gets spread across CISA, US law enforcement, industry associations, integrators, and operators without any one being singled out. The company argues that agencies should measure risk reduction and remediation rates routinely, so the notifications and participants that drove this result can be identified and repeated. Reductions of this size over a span this short are unusual.
What the fix missed
If you take one thing from the numbers, take port 8001. On the protocol surface, the outreach reached one port and left the other where it was, and nothing in the data suggests that port is being addressed. An owner running a console on some other port may assume that puts them in the clear. It does not.
Answering a scan and being vulnerable are two different measurements. A gauge behind a VPN, a network address translation gateway, or a carrier firewall has stopped replying, which is the recommended fix, and it is still powered on and still vulnerable if it is one of the affected models. Attackers reach industrial control systems mainly by moving laterally once inside a network, and that route is untouched.
Newer gauges run their console on a web server, where default credentials are common. Bitsight kept only hosts where a flaw from its earlier research is present, so every address in that set is confirmed vulnerable rather than merely visible, and the set is a subset of the web-facing gauges rather than all of them. The US count sat around 448 a month for ten months, fell to 259 in April and 235 in May, then came back to 320 in June, still under the previous year’s floor. Twelve of those 320 were new, and most of the rest are devices that dropped out of view and returned. The series has no flat comparison group to anchor it, and the addresses churn.
CISA and seven other federal agencies published a joint fact sheet on hardening these systems on June 2, covering the tactics used against the consoles, the risk factors, and the mitigations. Its headline instruction is to set strong passwords and take the devices off the internet, and Bitsight points readers to it. The date matters, because the fact sheet arrived after most of the decline had already happened.
Bitsight believes an ATG has no business answering the open internet, on any port or protocol. Port 8001 held 849 addresses in June, roughly where it stood in January. Set against that, an estimated 2,260 addresses left port 10001 for good between January and June. Those are the ones worth studying, because somebody told the right owners the right thing and a stubborn problem lost most of its mass inside a quarter.

Download: The ultimate guide to network operations management