Sage Water Resources
Incident posture
Linked entities
- Victim
- Sage Water Resources
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Sage Water Resources detected unauthorized activity on the programmable logic control system at its salt water disposal facility, and forensic analysis with federal law enforcement confirmed the activity was a malicious logic manipulation by an advanced nation‑state threat actor linked to a broader campaign targeting U.S. energy and water critical infrastructure. The anomaly was spotted by an early‑morning truck driver and quickly contained by the operations team, preventing any physical or environmental harm. After restoring the PLC operational logic, the company hardened its network with an extensive virtual private network and moved from a legacy configuration to an advanced PLC/VPN setup, resuming full operations while continuing to pursue growth opportunities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 15, 2026, Sage Water Resources detected unauthorized activity on its programmable logic controller at the salt water disposal facility in Duchesne, Utah. Forensic analysis conducted in coordination with federal law enforcement and cybersecurity experts determined that the activity consisted of malicious logic manipulation carried out by an advanced nation-state threat actor. The incident was identified as part of a broader, sophisticated campaign targeting critical infrastructure operators across the United States energy and water sectors. No physical or environmental damage was reported at the time of detection.
The unauthorized logic changes were first noticed by an early morning truck driver who reported the anomaly to the facility’s operations team. SWR’s operations team responded rapidly, isolating the affected PLC and reversing the unauthorized modifications before they could affect process controls. After the malicious logic was removed, the operational logic of the programmable logic controller was restored to its pre‑incident state. To prevent further intrusion, the company implemented an extensive virtual private network around the PLC environment.
Following a rigorous forensic investigation, Sage Water Resources transitioned its network architecture from a legacy configuration referred to internally as “Chevy” to an advanced programmable logic controller and virtual private network configuration referred to as “Cadillac”. The company announced the completion of the security hardening and recovery efforts on June 10, 2026. Sage Energy Partners expressed gratitude to the federal agencies whose coordination and forensic cybersecurity support contributed to the swift response and recovery. At the time of the announcement, Sage Water Resources was fully operational and continued to pursue new growth opportunities in the Uinta Basin.
Sources
Sources available to members: 1 source.