google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
USA

Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible

US officials suspect Iranian Hackers are behind a series of system breaches that track the amount of fuel in storage tanks serving gas stations in multiple states, according to multiple sources with knowledge of the activity.

Sources said the hackers responsible used automatic tank gauge (ATG) systems that were online and not protected by passwords, allowing them to correct display readings on tanks in some cases, but not changing the actual fuel levels inside them.

The cyberattacks are not known to cause physical harm or damage, but the breaches have raised security concerns because gaining access to an ATG could theoretically allow a hacker to leak gas undetected, according to private experts and U.S. officials.

Iran’s history of targeting gas tank systems is one reason the country is a prime suspect, sources briefed on the investigation said. But sources warned that the US government cannot definitively determine who is responsible due to a lack of forensic evidence left behind by the hackers.

CNN requested comment from the US Cybersecurity and Infrastructure Security Agency about the ATG attack. The FBI declined to comment.

If Iranian intervention is confirmed, it would be the latest example of Tehran threatening critical infrastructure on US soil, beyond the reach of Iranian drones and missiles, in the midst of the US and Israel’s war with Iran.

This could also raise a politically sensitive issue for the Trump administration by drawing more attention to high gas prices caused by the war. Seventy-five percent of U.S. adults recently surveyed CNN poll He said the Iran war had a negative impact on their finances.

The hacking campaign also serves as a warning to many US critical infrastructure operators who have struggled to secure their systems despite years of federal warnings.

Iranian hacking groups have long been searching for the low-hanging fruit; for example, critical U.S. computer systems online that interact with oil and gas fields and water systems. After Hamas attacked Israel on October 7, 2023, US officials blamed the attack on hackers affiliated with Iran’s Islamic Revolutionary Guard Corps. a series of attacks Water utilities in the US have placed an anti-Israel message on equipment used to manage water pressure.

Cybersecurity researchers have been warning about internet-facing ATGs for more than a decade. Security firm Trend Micro in 2015 put fake ATG systems online to see what kind of hackers would target them. A pro-Iran group quickly surfaced.

A. 2021 report Sky News cited internal documents from the Islamic Revolutionary Guard Corps that highlighted ATGs as a potential target for a devastating cyber attack on petrol stations.

Iran’s cyber operations are accelerating

U.S. intelligence agencies have long considered Iran’s cyber capabilities to be inferior to those of China or Russia. But a series of opportunistic attacks on key US assets during the war show Iran to be a capable and unpredictable adversary.

Tehran-linked hackers since the start of the war in late February caused disruptions In many oil, gas and water fields in the USA, shipping delays Stryker, one of the leading medical device manufacturers in the USA leaked Private emails of FBI Director Kash Patel.

Israeli organizations and citizens were also heavily targeted by hackers in Tehran during the recent war, while the US and Israeli military used cyber operations to carry out their kinetic attacks. more lethal.

Yossi Karadi, head of Israel’s cyber defense agency, the National Cyber ​​Directorate, told CNN that Iran’s cyber activity during the war showed “a significant increase in scale, speed and integration between cyber operations and psychological campaigns.”

The Israel Defense Forces claimed in March that it had struck a compound housing Iran’s “Cyber ​​Warfare headquarters.” It is unclear how many (if any) Iranian cyber agents were killed in this attack.

Karadi did not comment on the issue, citing his agency’s authority limited to cyber defense.

“However, from a defense perspective, we are seeing some deterioration in some of the adversary cyber activity over the past month,” he said. “As a result, Iranian actors are under pressure and are trying to attack wherever they find an opening in cyberspace.

Allison Wikoff, a director on PwC’s threat intelligence team with more than a decade of experience tracking Iran-based threats, found that the past 18 months have shown Iran’s cyber operations generally “accelerating with faster iteration, more layered hacktivist personas, and possibly AI-driven scaling for reconnaissance and phishing.”

“A notable innovation in the cyber playbook is the rapid creation of ‘good enough’ malware, including destructive deletion variants, and complementing them with ambitious hack-and-exfiltration campaigns against media, dissidents, and critical (US) civilian infrastructure,” Wikoff told CNN.

Part of Iran’s playbook draws on the wartime base of the American media, which is quick to pounce on claims from all sides.

Hackers linked to Iran’s intelligence ministry and its paramilitary arm maintain a set of “hacktivist” personas, where they use Telegram to exaggerate their exploits, broadcast stolen material and release promotional videos combined with catchy music.

One of the groups, calling itself Handala after a Palestinian cartoon character, mocked Patel, claiming he had breached the FBI’s “impenetrable” computer systems. In reality, hackers accessed Patel’s Gmail emails from years ago.

“The fact that every Handala claim scares people shows that the operational reality of the threat posed by Iran is something that both government agencies and vendors are failing to articulate,” said Alex Orleans, a cybersecurity researcher who has tracked Iran-linked hackers for years and leads threat intelligence at security firm Sublime Security.

Despite a series of hacks from Iran during the war, Orleans offered two reasons why there wouldn’t be more.

“The first is that Iran lacks the pipelines that would have lasting impacts, or we would probably see more incidents like Stryker,” he told CNN. “Second, the regime has made clear its intention to endure, which further deters unscrupulous cyber influence operations.”

‘Nobody pays for this’

For some current and former U.S. officials, the aggressive and unpredictable nature of Iran’s cyber operations takes on added significance ahead of the midterm elections.

In the 2020 election, federal agencies including the Cybersecurity and Infrastructure Security Agency (CISA) accused Iran of a scheme to impersonate far-right Proud Boys to intimidate voters. During the 2024 US presidential election, Iranian hackers breached Trump’s campaign and sent internal campaign documents to news organizations.

Now, in the first election cycle in years, U.S. military and intelligence officials have yet to mobilize an expert team dedicated to detecting and thwarting foreign threats to elections; This is a move by Jason Kikta, a former Cyber ​​Command official. sort of “strategic malpractice.”

Chris Krebs, who as CISA director in 2020 stood next to then-Director of National Intelligence John Ratcliffe, who warned the American public about Iranian and Russian influence operations, said, “Between what we watched Iran do in this war and what they carried out in 2020, I would be surprised if they canceled the midterms.”

“My bet is on information operations, not attacks on election systems,” Krebs told CNN. “The Russians and Chinese have gone there, and for good reason. It’s cheap, easy to scale with AI, and no one is paying a price for it.”

For more CNN news and newsletters, create an account at: CNN.com

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button