← Sage Water Resources

2026 Sage Water Resources — Utah disposal-site PLC intrusion bypassed pump shutdown safeguards (Mar 15)

2026 Unknown records affected Share on X

Data compromised

No personal data reported. Impact was operational-technology integrity: falsified control-system status and defeated pump safety interlocks, stopped by staff before equipment failure or environmental damage.

Technical writeup

Company-confirmed OT intrusion — Sage Water Resources says workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah before the March 15, 2026 intrusion caused equipment failure or environmental damage. In an August 3, 2026 email to DysruptionHub, Sage Energy Partners chief financial officer Steve Crower, who said he led the company cybersecurity response, described the attacker altering the programmable logic controller safety logic and bypassing shutdown protections: pumps continued running dry while the control system displayed them as operating "green," or normal. Sage disclosed the attack in June 2026; the August reporting added the technical detail that safety interlocks — not just process setpoints — were manipulated, which is what separates this from nuisance defacement of an internet-exposed HMI. No personal data is reported as involved, so recordsAffected is 0; the catalogued harm is control-system integrity at a produced-water disposal facility, a class of critical-infrastructure target that has drawn repeated intrusions against small US water and energy operators.

Root cause

Intrusion into an automated programmable logic controller at an oilfield saltwater disposal site near Duchesne, Utah. The attacker altered the PLC safety logic and bypassed shutdown protections, causing pumps to keep running dry while the control system reported them as operating normally.

References