TL;DR · 30-second read
The Short Version
Eight US government agencies, including the National Security Agency, warned on June 3 that hackers are breaking into the electronic gauges that measure what is inside fuel storage tanks, and tampering with them.
These gauges sit on tanks across energy, chemical, farming and transport sites. The same kind of gauge often watches the diesel that keeps a data center’s emergency generators running during a power cut.
If a gauge reports the wrong amount of fuel, a backup plan can fail exactly when it is needed. The agencies are urging every operator to lock these devices down.
On June 3, 2026, the National Security Agency said in a press release that it had joined the Cybersecurity and Infrastructure Security Agency (CISA) and six other federal agencies in publishing a fact sheet titled CISA and Partners Urge Hardening Automatic Tank Gauge Systems. Automatic tank gauges (ATGs) are networked devices that remotely monitor fuel and liquid levels, temperature and potential leaks in storage tanks.
The agencies said unattributed threat actors have been compromising internet-exposed ATGs and then modifying them through command execution. The co-authors are CISA, the NSA, the FBI, the Department of Energy, the Environmental Protection Agency, the TSA, the Department of Transportation and the Department of Agriculture. The NSA recommended that all operational technology owners in national security systems, the Department of War, the defense industrial base, the federal government and US critical infrastructure sectors review and implement the fact sheet’s mitigations.
Executive Summary
Eight federal agencies have jointly flagged ongoing malicious activity against a device most people have never heard of: the automatic tank gauge, the electronic sensor-and-console unit that reports how much liquid is in a tank, how warm it is and whether it is leaking. The warning names energy, chemical, food and agriculture, and transportation as affected sectors, and describes attackers not just reading these devices but changing them.
For data center operators, the relevance is direct even though the sector is not singled out. Every facility with diesel backup generators stores fuel on site, and the number that tells an operator how many hours of emergency runtime remain is typically produced by tank-monitoring equipment of exactly this kind. A warning that such equipment is being actively modified by outsiders turns generator fuel data from a facilities housekeeping item into something that belongs inside the security program.
The broader lesson is about scope. As AI campuses scale up their on-site generation and fuel storage, the attack surface grows with it, and much of that surface is operational technology (OT), the industrial control equipment that runs physical plant rather than business IT.
The Gauge Behind the Runtime Promise
A data center’s resilience story usually runs in layers: utility power, then batteries in the uninterruptible power supply (UPS) to bridge the first seconds of an outage, then diesel generators to carry the load for hours or days. That last layer is only as good as the fuel behind it, and operators state their emergency runtime in hours of on-site fuel. The figure they rely on comes from tank monitoring, the level, temperature and leak readings the agencies say ATGs are built to provide.
The agencies describe attackers compromising internet-exposed ATGs and then modifying them through command execution, meaning they issued commands that changed how the device behaves. Applied to a generator fuel system, the operational risks are straightforward to reason about: a gauge that overstates fuel can leave an operator believing it has a day of runtime when it has far less; one with suppressed leak alarms can let a spill go unnoticed; one that throws false alarms can trigger unnecessary emergency deliveries or shutdown procedures. None of those outcomes needs an attacker to touch the generator itself. The fuel reading is part of the power chain, and that is why it now has to be defended like one.
That argument scales with AI. Large AI training and inference campuses draw far more power than traditional enterprise halls, and operators that back that load with diesel need correspondingly more generators and more stored fuel. More tanks mean more gauges, and every networked gauge is a device that has to be inventoried, patched or isolated.
A Broad Coalition, a Broader Recommendation
The makeup of the coalition says something about how the agencies view the problem. The EPA regulates fuel storage and leak detection, the Department of Energy covers the energy sector, the TSA and Department of Transportation cover pipelines and transport, and the Department of Agriculture covers farm fuel storage. Pairing them with the NSA, CISA and the FBI signals that the concern spans environmental, safety and national security lines at once.
Data centers are not among the sectors the fact sheet names. But the NSA’s recommendation is deliberately wide: all OT owners and operators in national security systems, the Department of War, the defense industrial base, the federal government and US critical infrastructure. Facilities that host government workloads, defense contractors or critical services fall squarely inside that language, and colocation providers serving those customers will likely be asked about it.
Where Security Programs Tend to Thin Out
Tank gauges often sit in an organizational gap. They are frequently specified by the fuel system or generator contractor, maintained by facilities staff, and sometimes connected so that a fuel supplier or monitoring service can read them remotely. The network team may not know they exist, and the security team may never have scanned them. That is the pattern that leaves OT devices reachable from the internet, and it is the exposure the agencies describe.
The practical response is unglamorous: find every gauge, confirm none is reachable from the public internet, place them behind segmented networks, review remote-access arrangements with vendors, and apply the fact sheet’s mitigations. Just as important, operators should keep an independent way to verify fuel levels, such as periodic manual measurement, so that a single compromised device cannot quietly rewrite the runtime assumption an entire backup plan depends on.
The agencies have not attributed the activity, and the warning should be read for what it is: evidence of ongoing compromise and modification of exposed devices, not a claim that any data center has lost backup power. That measured reading is still enough to justify action, because the fix is cheap relative to the consequence.
Background
Automatic tank gauges have been standard equipment on fuel storage tanks for decades, in large part because they automate the leak detection that environmental rules require for stored fuel. Over time many gained network interfaces so that owners, fuel suppliers and service contractors could read them remotely, and security researchers have documented internet-reachable units for roughly a decade.
CISA leads federal efforts to protect US critical infrastructure and frequently co-publishes guidance with the NSA, the FBI and sector-specific agencies. Data centers depend on the same class of equipment: diesel generators backed by on-site fuel tanks remain the dominant form of emergency power, and fuel monitoring is part of how operators plan how long they can run without the grid. Source: NSA Joins CISA and Partners to Release Guidance on Hardening Automatic Tank Gauge Systems, the NSA’s June 3, 2026 announcement of a joint eight-agency fact sheet on malicious activity targeting internet-exposed ATG systems.Sources

