Sedgwick, a major claims management and risk solutions provider, confirmed a ransomware attack targeting its U.S. federal contractor subsidiary, Sedgwick Government Solutions. The TridentLocker ransomware group claimed responsibility for the incident, announcing the theft of 3.4GB of data from an isolated file transfer system on New Year's Eve. Sedgwick Government Solutions supports several key U.S. federal agencies, including DHS, ICE, CBP, USCIS, DOL, and CISA. The company emphasized that the affected system was segmented from core operations, with no evidence of access to claims management servers or disruption to client services.
Following detection of the breach, Sedgwick activated its incident response protocols, engaged external cybersecurity experts, and notified law enforcement and impacted customers. TridentLocker, an emerging ransomware-as-a-service group, has targeted multiple sectors since its launch in late 2025, using double-extortion tactics. Security professionals are advised to monitor for indicators of compromise related to TridentLocker and to prioritize network segmentation, especially in federal contractor environments, to mitigate similar risks.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In early January 2026, Sedgwick publicly disclosed a cybersecurity incident affecting Sedgwick Government Solutions. The company confirmed the breach was limited to the subsidiary's isolated file transfer system and said the investigation was ongoing.
Following discovery of the breach, Sedgwick isolated affected systems, engaged external cybersecurity experts, notified law enforcement, and began informing affected customers. The company said client services were not disrupted and broader Sedgwick operations were unaffected.
On or around New Year's Eve 2025, TridentLocker added Sedgwick Government Solutions to its Tor leak site and claimed to have exfiltrated roughly 3.39 to 3.4 GB of data, publishing some of the allegedly stolen material. The public claim linked the incident to the ransomware group, though Sedgwick itself did not publicly attribute the breach to a specific actor.
Around December 30, 2025, Sedgwick Government Solutions suffered unauthorized access to an isolated file transfer system. Sedgwick said the affected environment was segmented and that there was no evidence claims management servers or broader company systems were accessed.
The TridentLocker ransomware-as-a-service group emerged in late November 2025 and began posting victims on its leak site. By early January 2026, reporting said the group had claimed around 12 organizations across multiple sectors and regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethecyberthrone.in
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.