Sage Water Resources

At Sage Water Resources’ Duchesne, Utah, saltwater-disposal facility, an attacker altered PLC safety logic on March 15, 2026, bypassing shutdown protections and leaving pumps running dry while the control system showed normal operation. A truck driver spotted the mismatch; workers shut down automation, continued receiving wastewater under manual control, and avoided pump failure, service interruption and environmental harm. Sage said a contractor rebuilt and verified the safety logic and restored continuous operation within days.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that an attacker maliciously altered programmable-logic-controller safety logic at Sage Water Resources’ saltwater-disposal facility near Duchesne, Utah, on March 15, 2026. In an August 3 response to DysruptionHub, Sage Energy Partners chief financial officer Steve Crower said the changes bypassed shutdown protections and caused pumps to continue running dry while the control system showed them as operating normally.
The account materially clarifies the incident’s physical-process consequences. During routine truck unloading, a driver noticed that actual pump behavior did not match the control display and alerted the facility manager. Workers shut down the automated system before cavitation caused pump failure and moved the facility to manual operation. Sage reported no physical or environmental damage.
Sage said manual operation allowed the facility to continue receiving oilfield wastewater without interruption while maintaining environmental safety controls. The incident therefore caused a documented operational workaround and an industrial-safety hazard even though it did not interrupt receiving service or produce a spill, release or equipment failure.
Sage’s automation contractor reconstructed and verified the PLC safety logic, and the facility returned to continuous operation within days. That supports a resolved status, but the exact restoration date is not public. The record therefore does not assign March 15 as the confirmed end of incident activity.
Sage’s June 10 disclosure characterized the intrusion as the work of an advanced nation-state threat actor. Its August response provided a narrower evidentiary basis: Sage said its systems were not configured to capture enough forensic data to determine independently who conducted the intrusion. Crower linked the event to a broader Iranian-affiliated campaign because its tactics were consistent with those described in joint federal advisory AA26-097A.
The federal advisory describes Iranian-affiliated targeting of internet-connected PLCs across government, water/wastewater and energy organizations, including malicious project-file interaction and manipulation of HMI or SCADA displays. It does not identify Sage as a victim or attribute this incident. No federal agency has publicly named the Sage attacker, and Sage declined to say whether an agency had privately confirmed the campaign linkage. Threat-actor attribution therefore remains unresolved.
Sage said it worked with CISA, the FBI, NSA, the Energy Department and Rockwell Automation and provided requested forensic telemetry. It reported installing a dedicated on-site security server, restricting network access to VPN connections and continuing additional hardening after a late-July CISA network assessment. These measures document the response but do not establish the original access path or controller vendor.
Sage first publicly referred to the March 15 cyberattack in an April 17 announcement about a separate mechanical-integrity test and well workover. It issued a detailed cyber disclosure June 10 and supplied the controller, detection and manual-operation details to DysruptionHub on August 3. Sage has not linked the later well-integrity failure or workover to the cyber incident.
Confidence is high that malicious PLC logic manipulation, defeated safety shutdowns, dry-running pumps, manual operation and a narrowly avoided equipment failure occurred because Sage provided a first-hand operational account. Confidence is also high that receiving service continued and physical and environmental harm were avoided, based on the same account. Attribution confidence is unresolved because Sage could not identify the actor independently and no federal source publicly attributes this incident.
The public record does not identify the PLC manufacturer or model, exposed service, compromised credential, vulnerability, source infrastructure, duration of access, technical indicators or whether other devices were reached. It also does not establish that data or credentials were copied, that ransomware or extortion occurred, or that any named threat actor conducted the intrusion.

Sage told DysruptionHub that attackers bypassed PLC safety shutdowns and left pumps running dry while the control display showed normal operation. A truck driver spotted the mismatch; workers shut down automation, continued receiving wastewater manually and avoided cavitation, pump failure and environmental harm. Sage said its contractor rebuilt and verified the safety logic and restored continuous operation within days. Sage also said it lacked enough forensic telemetry to identify the attacker independently; AA26-097A does not name Sage.
The joint advisory, first issued April 7 and revised July 22, warns of Iranian-affiliated targeting of internet-connected PLCs across government, water/wastewater and energy organizations. It describes malicious project-file interaction, manipulation of HMI and SCADA displays, and operational disruption at some victims. It does not identify Sage Water Resources or attribute the Sage incident.
In an April 17 announcement, Sage CFO Steve Crower referred to the March 15 cyberattack, said it placed the company in crisis footing, and described the cyber response together with a separate April 1 state-mandated mechanical-integrity test and resulting well workover as operationally and financially demanding. The company said the well passed the test and was fully operational.
Sage Energy Partners’ website lists its June 10 announcement that wholly owned subsidiary Sage Water Resources completed recovery and cybersecurity hardening of Uinta Basin infrastructure following a targeted cyber incident.
Sage Water Resources said it detected unauthorized activity on a PLC at its Duchesne saltwater-disposal facility on March 15. Forensic analysis confirmed malicious logic manipulation; personnel mitigated the changes before physical or environmental damage, restored the PLC logic, upgraded the network configuration and added VPN protection.
Smart Water Magazine reported that forensic investigators confirmed unauthorized manipulation of PLC logic at the Duchesne facility. It said no physical or environmental harm was reported and noted that Sage Water Resources did not name the nation-state it believed was responsible.
Signed-in members can report an error, update, or missing source.