Ransomware
Sedgwick Government Solutions TridentLocker Ransomware Attack
Primary Source βIncident Details
On New Year’s Eve 2025/2026, the TridentLocker ransomware-as-a-service (RaaS) group claimed an attack on Sedgwick Government Solutions, a subsidiary of Sedgwick that provides claims and risk management services to federal agencies including DHS, ICE, CBP, USCIS, Department of Labor, and CISA. The group claimed to have stolen 3.4 GB of data. Sedgwick confirmed the incident involved an isolated file transfer system and stated no broader Sedgwick operations or data were impacted due to network segmentation. TridentLocker emerged in late November 2025 and uses standard double-extortion tactics.
Technical Details
- Initial Attack Vector
- TridentLocker ransomware group breached Sedgwick Government Solutions via an isolated file transfer system; initial access vector not publicly disclosed
- Malware Family
- TridentLocker
Timeline
- 2025-12-31 Breach occurred
- 2026-01-02 Publicly disclosed