CSIDB logo
Incident

Sage Water Resources

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-17 04:05

Linked entities

Victim
Sage Water Resources
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Mar 2026
Disclosed
Jun 2026
Resolved
Jun 2026

Summary

Sage Water Resources detected unauthorized activity on the programmable logic control system at its salt water disposal facility, and forensic analysis with federal law enforcement confirmed the activity was a malicious logic manipulation by an advanced nation‑state threat actor linked to a broader campaign targeting U.S. energy and water critical infrastructure. The anomaly was spotted by an early‑morning truck driver and quickly contained by the operations team, preventing any physical or environmental harm. After restoring the PLC operational logic, the company hardened its network with an extensive virtual private network and moved from a legacy configuration to an advanced PLC/VPN setup, resuming full operations while continuing to pursue growth opportunities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 15, 2026, Sage Water Resources detected unauthorized activity on its programmable logic controller at the salt water disposal facility in Duchesne, Utah. Forensic analysis conducted in coordination with federal law enforcement and cybersecurity experts determined that the activity consisted of malicious logic manipulation carried out by an advanced nation-state threat actor. The incident was identified as part of a broader, sophisticated campaign targeting critical infrastructure operators across the United States energy and water sectors. No physical or environmental damage was reported at the time of detection.

The unauthorized logic changes were first noticed by an early morning truck driver who reported the anomaly to the facility’s operations team. SWR’s operations team responded rapidly, isolating the affected PLC and reversing the unauthorized modifications before they could affect process controls. After the malicious logic was removed, the operational logic of the programmable logic controller was restored to its pre‑incident state. To prevent further intrusion, the company implemented an extensive virtual private network around the PLC environment.

Following a rigorous forensic investigation, Sage Water Resources transitioned its network architecture from a legacy configuration referred to internally as “Chevy” to an advanced programmable logic controller and virtual private network configuration referred to as “Cadillac”. The company announced the completion of the security hardening and recovery efforts on June 10, 2026. Sage Energy Partners expressed gratitude to the federal agencies whose coordination and forensic cybersecurity support contributed to the swift response and recovery. At the time of the announcement, Sage Water Resources was fully operational and continued to pursue new growth opportunities in the Uinta Basin.

Sources

Sources available to members: 1 source.

CSIDB