Skip to content

Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards

A truck driver spotted pumps running dry while the control system showed normal operation, prompting workers to switch the facility to manual operation before damage occurred.

Large cylindrical storage tanks and connecting pipes at the Blue Bench 13-1 oilfield wastewater disposal facility near Duchesne, Utah.
Storage tanks and related infrastructure at Sage Water Resources’ Blue Bench 13-1 saltwater disposal facility near Duchesne, Utah. (Sage Energy Partners)

Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, before the March 15 intrusion caused equipment failure or environmental damage.

In an Aug. 3 email to DysruptionHub, Sage Energy Partners Chief Financial Officer Steve Crower said the attacker altered the programmable logic controller’s safety logic and bypassed shutdown protections. Crower, who said he led the company’s cybersecurity response, said the changes caused pumps to continue running dry while the control system showed them as operating “green,” or normally.

Crower said a truck driver noticed during a routine unloading operation that the pumps’ physical behavior did not match the control system and alerted the facility manager early that morning. Workers shut down the automated system and switched the facility to manual operation.

“Facility operations transitioned smoothly to manual override,” Crower said. He said the facility continued receiving wastewater without interruption and maintained its environmental safety controls.

Running the pumps dry could have caused cavitation and pump failure, Crower said. Sage reported no physical or environmental damage.

Sage’s automation contractor reconstructed and verified the controller’s safety logic, and the facility returned to continuous operation within days, Crower said. The company later installed an on-site security server and moved the controller system to a network accessible only through a virtual private network, or VPN, to eliminate direct internet exposure.

Sage publicly disclosed the incident June 10 and initially attributed it to an “advanced nation-state threat actor,” citing forensic work coordinated with federal law enforcement and cybersecurity experts.

Crower’s response provided a more limited explanation of that attribution. He said Sage’s systems were not configured to collect enough forensic data to independently determine who conducted the intrusion. He linked the incident to a broader Iranian-affiliated campaign after federal agencies issued an April 7 advisory describing similar attacks.

“The tactics described in that advisory are consistent with what we experienced,” Crower said.

No federal agency has publicly attributed the Sage incident itself to Iran or another nation-state actor. Sage declined to say whether an agency had separately confirmed to the company that the incident was part of the Iranian-affiliated campaign.

Crower said Sage has since worked with the Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency, the Energy Department and Rockwell Automation. He said the company provided requested forensic telemetry and that federal agencies were leading efforts to trace the source of the intrusion.

CISA personnel also visited the facility in late July for a network assessment, Crower said. He initially described it as a “38-point inspection,” but Sage declined to clarify whether that was the formal name of a CISA assessment or the company’s description of the review. Sage said additional security hardening remained underway.

The affected site is a commercial facility where wastewater from oil and gas production is injected underground for disposal. It does not provide drinking water to the public.

About two weeks after the intrusion, Blue Bench 13-1 failed a state-required mechanical integrity test, forcing Sage Water Resources to suspend disposal operations. In an April 17 statement, the company said crews removed a compromised packer, cleared an obstruction and installed a replacement before the well passed a subsequent test and returned to service.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Sage has not linked the well-integrity failure or shutdown to the cyber incident. The company declined to say whether it had determined that the failure was unrelated to the altered controller logic or any other effect of the intrusion, but has said the cyberattack caused no physical damage.

Federal agencies warned April 7 that Iranian-affiliated actors had targeted internet-facing programmable logic controllers since at least March at government agencies and water, wastewater and energy organizations. The agencies updated the advisory July 22 with information about malicious interactions with controller project files, manipulation of data displayed to operators, operational disruptions and financial losses.

The advisory did not identify individual victims, including Sage. It urged infrastructure operators to remove programmable logic controllers from direct internet access and secure remote connections with gateways, firewalls or virtual private networks.

The Sage incident occurred months before a late July wave of attacks on internet-connected programmable logic controllers at water and wastewater utilities in at least seven states. Federal officials said some of those attacks caused operational disruptions.

Sage declined to identify the controller manufacturer or model or say how long the unauthorized access lasted. The company has not provided technical indicators, disclosed its response costs or publicly released evidence directly linking the incident to a specific threat actor. Crower said the federal investigation and the company’s security work remained active as of Aug. 3.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
Joseph Topping

Joseph Topping

A writer, intelligence analyst, and technology enthusiast passionate about the connection between the digital and physical worlds. His views expressed here do not necessarily reflect those of his employer, and he writes here as an individual.

All articles

More in Critical Infrastructure

See all

More from Joseph Topping

See all