Connect with us

Hi, what are you looking for?

HEADLINES

Gas stations also vulnerable to hackers, according to study

Kaspersky Lab researchers helped uncover a number of unknown vulnerabilities that have left gas stations around the world exposed to remote takeover, often for years.  The vulnerabilities were found in an embedded gas station controller of which there are currently over 1,000 installed and online. The manufacturer was notified when the threat was confirmed.

IMAGE SOURCE

Kaspersky Lab researchers helped uncover a number of unknown vulnerabilities that have left gas stations around the world exposed to remote takeover, often for years.  The vulnerabilities were found in an embedded gas station controller of which there are currently over 1,000 installed and online. The manufacturer was notified when the threat was confirmed.

Ido Naor, senior security researcher at Kaspersky Lab, together with another researcher found the controller during unrelated research into devices with open connections to the internet. In many cases the controller had been placed in the fuel station over a decade ago and had been connected to the internet ever since.

The controller, which runs a Linux machine, operates with high privileges and the researchers discovered a number of vulnerabilities that leave the device and the systems it is connected to open to cyberattack.  For example, the researchers were able to monitor and configure many of the gas station settings.  An intruder able to bypass the login screen and gain access to the main interfaces would be able to do any of the following:

  • Shut down all fueling systems
  • Change the fuel prices
  • Cause fuel leakages
  • Circumvent payment terminals to steal money (the controller connects directly to the payment terminal, so payment transactions could be hijacked)
  • Scrape vehicle license plates and driver identities
  • Execute code on the controller unit
  • Move freely within the gas station network

“When it comes to connected devices it is easy to focus on the new and to forget about products installed many years ago that might be leaving the business wide open to attack.  The damage that could be done by sabotaging a gas station doesn’t bear thinking about. We have shared our findings with the manufacturer,” said Naor.

The  vulnerabilities have been reported to MITRE and the research is ongoing.

Kaspersky Lab advises manufacturers of connected internet-of-thing devices to consider the security of their products from the very first moment of development and design, and to review legacy devices for possible security vulnerabilities. Users of connected devices are urged to review regularly the security of these devices and not to rely on factory settings.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

HEADLINES

Password guessing and valid account misuse rank among the most effective tactics used by cyber criminals in 2025. This trend reflects a strategic shift,...

Advertisement