The dispensers have constant real-time communication to the forecourt controller and the attendant inside. What are they showing when this "hack" happens? Are the attackers taking the RS485 line down (which would show the pump offline immediately inside) and forcing the pump to manually dispense?
I'd kill to see some more actual information than this. I am not aware of a single pump on the market with Bluetooth right now but I do remember some IR-based remotes for some old Wayne pumps.