Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
Sage Water Resources Utah saltwater disposal facility PLC (TL-2026-1882) is a high-severity ICS/SCADA threat, first published 2026-08-04. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Rockwell Automation CompactLogix PLC, maps to 4 MITRE ATT&CK techniques (T0869, T1491, T1531), and is covered by 9 detection rules and 37 indicators of compromise.
Key facts for TL-2026-1882
- Threat ID
- TL-2026-1882
- Severity
- HIGH
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-08-04
- Last reviewed
- 2026-08-04
- Attribution
- Cyber Av3ngers
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- HACKTIVISM
- Target sectors
- energy, oil-and-gas, water, wastewater, critical-infrastructure, municipal-government
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 37
Malware and tooling in Sage Water Resources Utah saltwater disposal facility PLC
Malware and tooling: Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, Siemens TIA Portal
On 2026-03-15, Sage Water Resources (SWR), a Ute Tribe-owned subsidiary of Sage Energy Partners, detected unauthorized activity on a Programmable Logic Controller (PLC) at its saltwater disposal facility in Duchesne, Utah (Uinta Basin). An advanced nation-state threat actor — consistent with the Iranian IRGC-CEC-affiliated CyberAv3ngers/Shahid Kaveh cluster documented in CISA AA26-097A — manipulated the PLC's control logic, disabling critical shutdown and alarm safeguards that protected the injection pumps. The unauthorized logic changes were detected and mitigated before any physical or environmental damage occurred; no data breach resulted. SWR subsequently hardened the facility from a legacy network to an advanced PLC/VPN configuration.
How Sage Water Resources Utah saltwater disposal facility PLC works
Sage Water Resources (SWR), a wholly-owned subsidiary of Sage Energy Partners and a Native American-owned (Ute Tribe) water and oilfield infrastructure operator, disclosed a targeted cyber incident affecting the Programmable Logic Controller (PLC) automation system at its saltwater disposal (SWD) facility in Duchesne, Utah, within the Uinta Basin. The facility has the capacity to inject up to 22,000 barrels per day of produced/saltwater. On March 15, 2026, during early-morning operations, a vigilant truck driver noticed anomalous PLC behavior and alerted SWR's operations team, which rapidly responded.
Forensic analysis, conducted in coordination with federal law enforcement and cybersecurity experts (including automation firm Sasquatch Automation), determined that an advanced nation-state threat actor had performed malicious logic manipulation of the PLC. The activity was attributed to a broader, sophisticated campaign targeting critical infrastructure operators across the U.S. energy and water sectors. This matches the joint FBI/CISA/NSA/EPA/DOE/CNMF/Treasury advisory AA26-097A (published April 7, 2026; updated July 22, 2026), which documents Iranian-affiliated APT actors (linked to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command, the CyberAv3ngers/Shahid Kaveh cluster) exploiting internet-facing PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens across U.S. Water and Wastewater Systems (WWS), Government Services, and Energy sectors since at least March 2026. In that campaign, actors used vendor PLC programming software (Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal) hosted on leased third-party infrastructure to connect to misconfigured victim PLCs, exfiltrate device project files, modify or delete project logic including Add-On Instructions (AOIs), manipulate HMI/SCADA displays, and disable critical shutdown and alarm logic. The SWR incident's bypass of pump safeguards is consistent with this pattern of disabling shutdown and alarm logic, which allows industrial systems to enter unsafe conditions without notifying operators. Here, the malicious logic changes were caught and neutralized before any physical or environmental damage occurred; SWR reported that core saltwater disposal operations remained functional, no sensitive data was accessed, and no disruption or data breach resulted.
In response, SWR restored the PLC operational logic and hardened the facility's network, transitioning from a legacy configuration (described by the company as its 'Chevy') to one of the most advanced PLC/VPN configurations in the oilfield (its 'Cadillac'), with the PLC now shielded by an extensive Virtual Private Network (VPN). The company announced the completion of comprehensive security hardening on June 10, 2026, with CEO Cleve Pike stating, 'We didn't just patch a hole; we built a fortress.' The incident was reported to the Utah Cyber Center and investigated with federal law enforcement. Attribution to Iran is established at the federal level via the AA26-097A campaign advisory; SWR's own disclosure named an 'advanced nation-state threat actor' but did not specifically name Iran. This intrusion demonstrates the real-world risk to small, independent OT/ICS operators from state-affiliated actors targeting industrial control logic, and the critical importance of removing PLCs from direct internet exposure.
MITRE ATT&CK techniques used in TL-2026-1882
command-and-control
T0869 Standard Application Layer Protocol
Impact
T1491 Defacement; T1531 Account Access Removal; T1565 Data Manipulation
Affected products and versions in Sage Water Resources Utah saltwater disposal facility PLC
- Rockwell Automation — CompactLogix PLC
Vulnerable versions: Internet-facing CompactLogix controllers (CIP/EtherNet-IP port 44818)
Fixed in: Remove from direct internet exposure; place mode switch in Run position - Rockwell Automation — Micro800/Micro850 PLC
Vulnerable versions: Internet-facing Micro850 controllers
Fixed in: Remove from direct internet exposure - Schneider Electric — Modicon M340 (BMX P34) PLC
Vulnerable versions: Internet-facing Modicon M340 controllers (Modbus port 502)
Fixed in: Remove from direct internet exposure - Siemens — SIMATIC S7-1200 PLC
Vulnerable versions: Internet-facing S7-1200 controllers (S7 protocol port 102)
Fixed in: Remove from direct internet exposure
Remediation for Sage Water Resources Utah saltwater disposal facility PLC
Patches
- No CVE or vendor patch applies to this intrusion; apply relevant manufacturer security advisories and firmware updates for Rockwell, Schneider Electric, and Siemens PLC platforms
- For legacy Unitronics devices, update to VisiLogic 9.9.00 and latest firmware as recommended in CISA AA23-335A
Immediate actions
- Remove PLCs, HMIs, and other OT devices from direct internet exposure; place behind secure gateways/firewalls or VPN-protected jump hosts
- Query network and device logs for the AA26-097A IP IOCs and for suspicious traffic on OT ports 44818, 2222, 102, 502, and 22
- Replace all default and weak passwords on PLCs, HMIs, and modems; change default ports and device names
- For Rockwell Automation controllers, place the physical mode switch in the Run position to block remote program downloads
- Engage the Utah Cyber Center, CISA, FBI, and the PLC manufacturer if compromise is suspected
- Restore verified-good PLC program logic from a trusted backup and validate program integrity
Workarounds
- Disable remote access to PLCs except through authenticated VPN with multifactor authentication
- Disable default FTP, Telnet, and unneeded services on PLCs and OT gateways
- Apply security-related ladder-logic elements (TCP/IP passwords, upload passwords, INFO-mode passwords, SD-card passwords) to project files
Longer-term hardening
- Implement OT network segmentation and a dedicated DMZ between IT and OT/ICS networks
- Deploy OT-aware monitoring and alerting for engineering-workstation connections and vendor programming software traffic
- Implement integrity monitoring of PLC project files, Add-On Instructions (AOIs), and task/program parameters to detect unauthorized logic changes
- Establish a configuration-change-management and program-versioning process with cryptographically verifiable program integrity (SHA-2/SHA-3)
- Maintain air-gapped or secured vendor programming workstations and restrict access to authorized operators
- Conduct regular OT security assessments, tabletop exercises, and incident-response planning for ICS environments
Timeline of Sage Water Resources Utah saltwater disposal facility PLC
- IRGC-affiliated CyberAv3ngers/Shahid Kaveh actors begin targeting U.S. Water and Wastewater Systems operating internet-facing HMI-capable Unitronics Vision Series PLCs, exploiting default or no passwords on TCP port 20256.
- CISA, FBI, NSA, EPA, and Israel's National Cyber Directorate publish joint advisory AA23-335A documenting IRGC-affiliated targeting of Unitronics PLCs; at least 75 devices compromised, including 34+ in the U.S. WWS sector.
- U.S. Department of the Treasury sanctions six IRGC-CEC officials for their roles in the CyberAv3ngers operations against U.S. critical infrastructure.
- Iranian-affiliated actors begin an expanded, multi-vendor campaign against internet-facing PLCs; earliest associated IP IOCs (185.82.73.x) are active from January 2025.
- CISA observes Iranian-affiliated PLC exploitation activity across U.S. Government Services/Facilities, Water and Wastewater Systems, and Energy sectors 'since at least March 2026,' using Rockwell Studio 5000, Schneider EcoStruxure, and Siemens TIA Portal on leased infrastructure.
- Sage Water Resources detects unauthorized activity on the PLC at its saltwater disposal facility in Duchesne, Utah (Uinta Basin); an early-morning truck driver spots the anomaly and SWR's operations team responds, detecting malicious logic manipulation that bypassed pump safeguards before physical or environmental damage occurred.
- FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command (CNMF), and Treasury publish joint advisory AA26-097A warning of Iranian-affiliated cyber actors exploiting PLCs across U.S. critical infrastructure; campaign linked to the CyberAv3ngers/Shahid Kaveh cluster.
- Sage Water Resources announces successful recovery and completion of enhanced cybersecurity hardening, migrating the facility from a legacy ('Chevy') network to an advanced PLC/VPN ('Cadillac') configuration with extensive VPN shielding, assisted by Sasquatch Automation and federal partners.
- CISA updates AA26-097A, expanding scope to Schneider Electric (BMX P34/Modicon M340) and Siemens (S7-1200) PLCs, documenting modification/deletion of project logic including Add-On Instructions (AOIs), disabled shutdown and alarm logic, and publishing new IP IOCs.
- DataBreaches.net publishes detailed coverage of the Sage Water Resources incident, characterizing the malicious logic manipulation as an advanced nation-state intrusion consistent with a broader campaign against U.S. energy and water critical infrastructure.
Sources cited for Sage Water Resources Utah saltwater disposal facility PLC
- CISA AA26-097A — Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
- CISA AA23-335A — IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities
- Sage Energy Partners press release — Sage Water Resources announces successful recovery and enhanced cybersecurity hardening of Uinta Basin infrastructure
- PRNewswire — Sage Water Resources announces successful recovery and enhanced cybersecurity hardening
- Water Tech Online — Sage detects SWD cybersecurity attack
- Smart Water Magazine — Cyberattack hits Utah water facility
- DataBreaches.net — Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards
- MITRE ATT&CK (ICS) — CyberAv3ngers group (G1027)
- CrowdStrike — Hydro Kitten adversary profile (CyberAv3ngers / Shahid Kaveh)
- Trend Micro — Federal agencies warn of ongoing PLC exploitation
- Orion Policy Institute — APT Profile: CyberAv3ngers
- The Hill — FBI attributes Iran-linked hackers to U.S. oil, gas, and water infrastructure disruptions
Threats related to Sage Water Resources Utah saltwater disposal facility PLC
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-1882
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1882 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1882
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.