Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards — Threadlinqs Intelligence
As of 2026-08-05, Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards is a high-severity ics scada threat attributed to Cyber Av3ngers (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1882 · Severity: HIGH · Status: ACTIVE · Category: ICS_SCADA
Attribution: Cyber Av3ngers · Iran · HACKTIVISM
On 2026-03-15, Sage Water Resources (SWR), a Ute Tribe-owned subsidiary of Sage Energy Partners, detected unauthorized activity on a Programmable Logic Controller (PLC) at its saltwater disposal
Sage Water Resources (SWR), a wholly-owned subsidiary of Sage Energy Partners and a Native American-owned (Ute Tribe) water and oilfield infrastructure operator, disclosed a targeted cyber incident affecting the Programmable Logic Controller (PLC) automation system at its saltwater disposal (SWD) facility in Duchesne, Utah, within the Uinta Basin. The facility has the capacity to inject up to 22,000 barrels per day of produced/saltwater. On March 15, 2026, during early-morning operations, a vigilant truck driver noticed anomalous PLC behavior and alerted SWR's operations team, which rapidly responded.
Forensic analysis, conducted in coordination with federal law enforcement and cybersecurity experts (including automation firm Sasquatch Automation), determined that an advanced nation-state threat actor had performed malicious logic manipulation of the PLC. The activity was attributed to a broader, sophisticated campaign targeting critical infrastructure operators across the U.S. energy and water sectors. This matches the joint FBI/CISA/NSA/EPA/DOE/CNMF/Treasury advisory AA26-097A (published April 7, 2026; updated July 22, 2026), which documents Iranian-affiliated APT actors (linked to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command, the CyberAv3ngers/Shahid Kaveh cluster) exploiting internet-facing PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens across U.S. Water and Wastewater Systems (WWS), Government Services, and Energy sectors since at least March 2026. In that campaign, actors used vendor PLC programming software (Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal) hosted on leased third-party infrastructure to connect to misconfigured victim PLCs, exfiltrate device project files, modify or delete project logic including Add-On Instructions (AOIs), manipulate HMI/SCADA displays, and disable critical shutdown and alarm logic. The SWR incident's bypass of pump safeguards is consistent with this pattern of disabling shutdown and alarm logic, which allows industrial systems to enter unsafe conditions without notifying operators. Here, the malicious logic changes were caught and neutralized before any physical or environmental damage occurred; SWR reported that core saltwater disposal operations remained functional, no sensitive data was accessed, and no disruption or data breach resulted.
In response, SWR restored the PLC operational logic and hardened the facility's network, transitioning from a legacy configuration (described by the company as its 'Chevy') to one of the most advanced PLC/VPN configurations in the oilfield (its 'Cadillac'), with the PLC now shielded by an extensive Virtual Private Network (VPN). The company announced the completion of comprehensive security hardening on June 10, 2026, with CEO Cleve Pike stating, 'We didn't just patch a hole; we built a fortress.' The incident was reported to the Utah Cyber Center and investigated with federal law enforcement. Attribution to Iran is established at the federal level via the AA26-097A campaign advisory; SWR's own disclosure named an 'advanced nation-state threat actor' but did not specifically name Iran. This intrusion demonstrates the real-world risk to small, independent OT/ICS operators from state-affiliated actors targeting industrial control logic, and the critical importance of removing PLCs from direct internet exposure.
Target sectors: energy, oil-and-gas, water, wastewater, critical-infrastructure, municipal-government
Target regions: united states of america
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
ICS_SCADA, HIGH, threat intelligence, cybersecurity, T0869, T1491, T1565, T1531