Sage Water Resources said a cyber intrusion at its oilfield wastewater disposal site near Duchesne, Utah, altered an automated controller and bypassed pump shutdown safeguards, creating conditions that could have caused equipment failure or environmental damage. The company said the attack occurred on March 15 and targeted a programmable logic controller, with the manipulated safety logic allowing pumps to continue running dry while the control system falsely indicated normal operation.
According to Sage Energy Partners CFO Steve Crower, workers detected and stopped the malicious changes before the intrusion caused physical consequences. Sage had previously disclosed the incident in June and later provided additional details in an Aug. 3 email cited by DysruptionHub, framing the event as a serious attempted manipulation of industrial control systems at a critical wastewater disposal operation.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
In an Aug. 3 email cited by later reporting, Sage Energy Partners CFO Steve Crower provided additional details about the incident and said he led the company's cybersecurity response. He stated that the attacker altered PLC safety logic and bypassed shutdown protections during the attack.
Sage Water Resources disclosed in June that a cyberattack had targeted its oilfield wastewater disposal site near Duchesne, Utah. Later reporting identified the incident as involving an automated controller at the saltwater disposal facility.
During the March 15 intrusion, workers intervened and stopped the malicious controller changes before they caused equipment failure or environmental damage. Sage said the attack had bypassed pump safeguards, making the incident a potentially serious critical infrastructure event.
On March 15, an attacker made malicious changes to an automated controller at Sage Water Resources' oilfield wastewater disposal site near Duchesne, Utah. According to the company, the intrusion altered programmable logic controller safety logic, bypassed shutdown protections, and caused pumps to continue running dry while the control system falsely showed normal operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcedysruptionhub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.