Skip to content

PLC safety logic bypassed at Sage Water Resources facility

Summary

Sage Water Resources logo

At Sage Water Resources’ Duchesne, Utah, saltwater-disposal facility, an attacker altered PLC safety logic on March 15, 2026, bypassing shutdown protections and leaving pumps running dry while the control system showed normal operation. A truck driver spotted the mismatch; workers shut down automation, continued receiving wastewater under manual control, and avoided pump failure, service interruption and environmental harm. Sage said a contractor rebuilt and verified the safety logic and restored continuous operation within days.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that an attacker maliciously altered programmable-logic-controller safety logic at Sage Water Resources’ saltwater-disposal facility near Duchesne, Utah, on March 15, 2026. In an August 3 response to DysruptionHub, Sage Energy Partners chief financial officer Steve Crower said the changes bypassed shutdown protections and caused pumps to continue running dry while the control system showed them as operating normally.

The account materially clarifies the incident’s physical-process consequences. During routine truck unloading, a driver noticed that actual pump behavior did not match the control display and alerted the facility manager. Workers shut down the automated system before cavitation caused pump failure and moved the facility to manual operation. Sage reported no physical or environmental damage.

Operational significance

Sage said manual operation allowed the facility to continue receiving oilfield wastewater without interruption while maintaining environmental safety controls. The incident therefore caused a documented operational workaround and an industrial-safety hazard even though it did not interrupt receiving service or produce a spill, release or equipment failure.

Sage’s automation contractor reconstructed and verified the PLC safety logic, and the facility returned to continuous operation within days. That supports a resolved status, but the exact restoration date is not public. The record therefore does not assign March 15 as the confirmed end of incident activity.

Attribution

Sage’s June 10 disclosure characterized the intrusion as the work of an advanced nation-state threat actor. Its August response provided a narrower evidentiary basis: Sage said its systems were not configured to capture enough forensic data to determine independently who conducted the intrusion. Crower linked the event to a broader Iranian-affiliated campaign because its tactics were consistent with those described in joint federal advisory AA26-097A.

The federal advisory describes Iranian-affiliated targeting of internet-connected PLCs across government, water/wastewater and energy organizations, including malicious project-file interaction and manipulation of HMI or SCADA displays. It does not identify Sage as a victim or attribute this incident. No federal agency has publicly named the Sage attacker, and Sage declined to say whether an agency had privately confirmed the campaign linkage. Threat-actor attribution therefore remains unresolved.

Response and hardening

Sage said it worked with CISA, the FBI, NSA, the Energy Department and Rockwell Automation and provided requested forensic telemetry. It reported installing a dedicated on-site security server, restricting network access to VPN connections and continuing additional hardening after a late-July CISA network assessment. These measures document the response but do not establish the original access path or controller vendor.

Disclosure posture

Sage first publicly referred to the March 15 cyberattack in an April 17 announcement about a separate mechanical-integrity test and well workover. It issued a detailed cyber disclosure June 10 and supplied the controller, detection and manual-operation details to DysruptionHub on August 3. Sage has not linked the later well-integrity failure or workover to the cyber incident.

Confidence and uncertainty

Confidence is high that malicious PLC logic manipulation, defeated safety shutdowns, dry-running pumps, manual operation and a narrowly avoided equipment failure occurred because Sage provided a first-hand operational account. Confidence is also high that receiving service continued and physical and environmental harm were avoided, based on the same account. Attribution confidence is unresolved because Sage could not identify the actor independently and no federal source publicly attributes this incident.

Analytic gaps

The public record does not identify the PLC manufacturer or model, exposed service, compromised credential, vulnerability, source infrastructure, duration of access, technical indicators or whether other devices were reached. It also does not establish that data or credentials were copied, that ransomware or extortion occurred, or that any named threat actor conducted the intrusion.

Organizations involved

Impacted location

Sources

Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards

Sage told DysruptionHub that attackers bypassed PLC safety shutdowns and left pumps running dry while the control display showed normal operation. A truck driver spotted the mismatch; workers shut down automation, continued receiving wastewater manually and avoided cavitation, pump failure and environmental harm. Sage said its contractor rebuilt and verified the safety logic and restored continuous operation within days. Sage also said it lacked enough forensic telemetry to identify the attacker independently; AA26-097A does not name Sage.

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

The joint advisory, first issued April 7 and revised July 22, warns of Iranian-affiliated targeting of internet-connected PLCs across government, water/wastewater and energy organizations. It describes malicious project-file interaction, manipulation of HMI and SCADA displays, and operational disruption at some victims. It does not identify Sage Water Resources or attribute the Sage incident.

Sage Water Resources Announces Successful Rework of Saltwater Disposal Well

In an April 17 announcement, Sage CFO Steve Crower referred to the March 15 cyberattack, said it placed the company in crisis footing, and described the cyber response together with a separate April 1 state-mandated mechanical-integrity test and resulting well workover as operationally and financially demanding. The company said the well passed the test and was fully operational.

News and Events

Sage Energy Partners’ website lists its June 10 announcement that wholly owned subsidiary Sage Water Resources completed recovery and cybersecurity hardening of Uinta Basin infrastructure following a targeted cyber incident.

Sage Water Resources Announces Recovery Following Targeted Cyber Incident

Sage Water Resources said it detected unauthorized activity on a PLC at its Duchesne saltwater-disposal facility on March 15. Forensic analysis confirmed malicious logic manipulation; personnel mitigated the changes before physical or environmental damage, restored the PLC logic, upgraded the network configuration and added VPN protection.

Cyberattack hits Utah water facility

Smart Water Magazine reported that forensic investigators confirmed unauthorized manipulation of PLC logic at the Duchesne facility. It said no physical or environmental harm was reported and noted that Sage Water Resources did not name the nation-state it believed was responsible.

See something that needs correction?

Signed-in members can report an error, update, or missing source.