Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards

Sage Water Resources Utah saltwater disposal facility PLC (TL-2026-1882) is a high-severity ICS/SCADA threat, first published 2026-08-04. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Rockwell Automation CompactLogix PLC, maps to 4 MITRE ATT&CK techniques (T0869, T1491, T1531), and is covered by 9 detection rules and 37 indicators of compromise.

Key facts for TL-2026-1882

Threat ID
TL-2026-1882
Severity
HIGH
Status
ACTIVE
Category
ICS_SCADA
First published
2026-08-04
Last reviewed
2026-08-04
Attribution
Cyber Av3ngers
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
HACKTIVISM
Target sectors
energy, oil-and-gas, water, wastewater, critical-infrastructure, municipal-government
Target regions
united states of america
Detection rules
9
Indicators of compromise
37

Malware and tooling in Sage Water Resources Utah saltwater disposal facility PLC

Malware and tooling: Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, Siemens TIA Portal

On 2026-03-15, Sage Water Resources (SWR), a Ute Tribe-owned subsidiary of Sage Energy Partners, detected unauthorized activity on a Programmable Logic Controller (PLC) at its saltwater disposal facility in Duchesne, Utah (Uinta Basin). An advanced nation-state threat actor — consistent with the Iranian IRGC-CEC-affiliated CyberAv3ngers/Shahid Kaveh cluster documented in CISA AA26-097A — manipulated the PLC's control logic, disabling critical shutdown and alarm safeguards that protected the injection pumps. The unauthorized logic changes were detected and mitigated before any physical or environmental damage occurred; no data breach resulted. SWR subsequently hardened the facility from a legacy network to an advanced PLC/VPN configuration.

How Sage Water Resources Utah saltwater disposal facility PLC works

Sage Water Resources (SWR), a wholly-owned subsidiary of Sage Energy Partners and a Native American-owned (Ute Tribe) water and oilfield infrastructure operator, disclosed a targeted cyber incident affecting the Programmable Logic Controller (PLC) automation system at its saltwater disposal (SWD) facility in Duchesne, Utah, within the Uinta Basin. The facility has the capacity to inject up to 22,000 barrels per day of produced/saltwater. On March 15, 2026, during early-morning operations, a vigilant truck driver noticed anomalous PLC behavior and alerted SWR's operations team, which rapidly responded.

Forensic analysis, conducted in coordination with federal law enforcement and cybersecurity experts (including automation firm Sasquatch Automation), determined that an advanced nation-state threat actor had performed malicious logic manipulation of the PLC. The activity was attributed to a broader, sophisticated campaign targeting critical infrastructure operators across the U.S. energy and water sectors. This matches the joint FBI/CISA/NSA/EPA/DOE/CNMF/Treasury advisory AA26-097A (published April 7, 2026; updated July 22, 2026), which documents Iranian-affiliated APT actors (linked to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command, the CyberAv3ngers/Shahid Kaveh cluster) exploiting internet-facing PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens across U.S. Water and Wastewater Systems (WWS), Government Services, and Energy sectors since at least March 2026. In that campaign, actors used vendor PLC programming software (Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal) hosted on leased third-party infrastructure to connect to misconfigured victim PLCs, exfiltrate device project files, modify or delete project logic including Add-On Instructions (AOIs), manipulate HMI/SCADA displays, and disable critical shutdown and alarm logic. The SWR incident's bypass of pump safeguards is consistent with this pattern of disabling shutdown and alarm logic, which allows industrial systems to enter unsafe conditions without notifying operators. Here, the malicious logic changes were caught and neutralized before any physical or environmental damage occurred; SWR reported that core saltwater disposal operations remained functional, no sensitive data was accessed, and no disruption or data breach resulted.

In response, SWR restored the PLC operational logic and hardened the facility's network, transitioning from a legacy configuration (described by the company as its 'Chevy') to one of the most advanced PLC/VPN configurations in the oilfield (its 'Cadillac'), with the PLC now shielded by an extensive Virtual Private Network (VPN). The company announced the completion of comprehensive security hardening on June 10, 2026, with CEO Cleve Pike stating, 'We didn't just patch a hole; we built a fortress.' The incident was reported to the Utah Cyber Center and investigated with federal law enforcement. Attribution to Iran is established at the federal level via the AA26-097A campaign advisory; SWR's own disclosure named an 'advanced nation-state threat actor' but did not specifically name Iran. This intrusion demonstrates the real-world risk to small, independent OT/ICS operators from state-affiliated actors targeting industrial control logic, and the critical importance of removing PLCs from direct internet exposure.

MITRE ATT&CK techniques used in TL-2026-1882

command-and-control

T0869 Standard Application Layer Protocol

Impact

T1491 Defacement; T1531 Account Access Removal; T1565 Data Manipulation

Affected products and versions in Sage Water Resources Utah saltwater disposal facility PLC

  • Rockwell Automation — CompactLogix PLC
    Vulnerable versions: Internet-facing CompactLogix controllers (CIP/EtherNet-IP port 44818)
    Fixed in: Remove from direct internet exposure; place mode switch in Run position
  • Rockwell Automation — Micro800/Micro850 PLC
    Vulnerable versions: Internet-facing Micro850 controllers
    Fixed in: Remove from direct internet exposure
  • Schneider Electric — Modicon M340 (BMX P34) PLC
    Vulnerable versions: Internet-facing Modicon M340 controllers (Modbus port 502)
    Fixed in: Remove from direct internet exposure
  • Siemens — SIMATIC S7-1200 PLC
    Vulnerable versions: Internet-facing S7-1200 controllers (S7 protocol port 102)
    Fixed in: Remove from direct internet exposure

Remediation for Sage Water Resources Utah saltwater disposal facility PLC

Patches

  • No CVE or vendor patch applies to this intrusion; apply relevant manufacturer security advisories and firmware updates for Rockwell, Schneider Electric, and Siemens PLC platforms
  • For legacy Unitronics devices, update to VisiLogic 9.9.00 and latest firmware as recommended in CISA AA23-335A

Immediate actions

  • Remove PLCs, HMIs, and other OT devices from direct internet exposure; place behind secure gateways/firewalls or VPN-protected jump hosts
  • Query network and device logs for the AA26-097A IP IOCs and for suspicious traffic on OT ports 44818, 2222, 102, 502, and 22
  • Replace all default and weak passwords on PLCs, HMIs, and modems; change default ports and device names
  • For Rockwell Automation controllers, place the physical mode switch in the Run position to block remote program downloads
  • Engage the Utah Cyber Center, CISA, FBI, and the PLC manufacturer if compromise is suspected
  • Restore verified-good PLC program logic from a trusted backup and validate program integrity

Workarounds

  • Disable remote access to PLCs except through authenticated VPN with multifactor authentication
  • Disable default FTP, Telnet, and unneeded services on PLCs and OT gateways
  • Apply security-related ladder-logic elements (TCP/IP passwords, upload passwords, INFO-mode passwords, SD-card passwords) to project files

Longer-term hardening

  • Implement OT network segmentation and a dedicated DMZ between IT and OT/ICS networks
  • Deploy OT-aware monitoring and alerting for engineering-workstation connections and vendor programming software traffic
  • Implement integrity monitoring of PLC project files, Add-On Instructions (AOIs), and task/program parameters to detect unauthorized logic changes
  • Establish a configuration-change-management and program-versioning process with cryptographically verifiable program integrity (SHA-2/SHA-3)
  • Maintain air-gapped or secured vendor programming workstations and restrict access to authorized operators
  • Conduct regular OT security assessments, tabletop exercises, and incident-response planning for ICS environments

Timeline of Sage Water Resources Utah saltwater disposal facility PLC

  • IRGC-affiliated CyberAv3ngers/Shahid Kaveh actors begin targeting U.S. Water and Wastewater Systems operating internet-facing HMI-capable Unitronics Vision Series PLCs, exploiting default or no passwords on TCP port 20256.
  • CISA, FBI, NSA, EPA, and Israel's National Cyber Directorate publish joint advisory AA23-335A documenting IRGC-affiliated targeting of Unitronics PLCs; at least 75 devices compromised, including 34+ in the U.S. WWS sector.
  • U.S. Department of the Treasury sanctions six IRGC-CEC officials for their roles in the CyberAv3ngers operations against U.S. critical infrastructure.
  • Iranian-affiliated actors begin an expanded, multi-vendor campaign against internet-facing PLCs; earliest associated IP IOCs (185.82.73.x) are active from January 2025.
  • CISA observes Iranian-affiliated PLC exploitation activity across U.S. Government Services/Facilities, Water and Wastewater Systems, and Energy sectors 'since at least March 2026,' using Rockwell Studio 5000, Schneider EcoStruxure, and Siemens TIA Portal on leased infrastructure.
  • Sage Water Resources detects unauthorized activity on the PLC at its saltwater disposal facility in Duchesne, Utah (Uinta Basin); an early-morning truck driver spots the anomaly and SWR's operations team responds, detecting malicious logic manipulation that bypassed pump safeguards before physical or environmental damage occurred.
  • FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command (CNMF), and Treasury publish joint advisory AA26-097A warning of Iranian-affiliated cyber actors exploiting PLCs across U.S. critical infrastructure; campaign linked to the CyberAv3ngers/Shahid Kaveh cluster.
  • Sage Water Resources announces successful recovery and completion of enhanced cybersecurity hardening, migrating the facility from a legacy ('Chevy') network to an advanced PLC/VPN ('Cadillac') configuration with extensive VPN shielding, assisted by Sasquatch Automation and federal partners.
  • CISA updates AA26-097A, expanding scope to Schneider Electric (BMX P34/Modicon M340) and Siemens (S7-1200) PLCs, documenting modification/deletion of project logic including Add-On Instructions (AOIs), disabled shutdown and alarm logic, and publishing new IP IOCs.
  • DataBreaches.net publishes detailed coverage of the Sage Water Resources incident, characterizing the malicious logic manipulation as an advanced nation-state intrusion consistent with a broader campaign against U.S. energy and water critical infrastructure.

Sources cited for Sage Water Resources Utah saltwater disposal facility PLC

Threats related to Sage Water Resources Utah saltwater disposal facility PLC

Detection coverage for TL-2026-1882

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1882 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1882

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats