Sedgwick confirms Data Breach Following TridentLocker Ransomware Gang Claim
Sedgwick has confirmed a cybersecurity incident involving its subsidiary focused on government operations. This follows claims by the TridentLocker ransomware group that it stole 3.4 gigabytes of data. The breach underscores ongoing risks for federal…
Sedgwick has confirmed a cybersecurity incident involving its subsidiary focused on government operations. This follows claims by the TridentLocker ransomware group that it stole 3.4 gigabytes of data. The breach underscores ongoing risks for federal contractors managing sensitive U.S. agency data.
On January 4, 2026, Sedgwick acknowledged unauthorized access to an isolated file transfer system within Sedgwick Government Solutions (SGS). This subsidiary provides risk management and claims services to federal entities such as the Department of Homeland Security, Immigration and Customs Enforcement, Customs and Border Protection, U.S. Citizenship and Immigration Services, Department of Labor, and the Cybersecurity and Infrastructure Security Agency. SGS also supports municipal agencies nationwide, the Smithsonian Institution, and the Port Authority of New York and New Jersey.
TridentLocker, operational since late November 2025, listed SGS as a victim on December 31, 2025, and claimed to have exfiltrated 3.39 GB of documents. The group employs ransomware-as-a-service (RaaS) models utilizing double-extortion tactics, which include encrypting systems and threatening data leaks.
According to a Sedgwick representative, the company activated its incident response protocols and engaged external cybersecurity experts to investigate the compromised system. Sedgwick emphasized that SGS is isolated from the company's broader operations, ensuring no other systems or data were affected. There is no evidence of access to claims management servers, and SGS's operational capabilities remain intact.
Sedgwick has confirmed a cybersecurity incident involving its subsidiary focused on government operations.
Sedgwick has informed law enforcement and clients while maintaining regular operations. The company employs over 33,000 individuals across 80 countries and generates multi-billion-dollar revenue.
Since November 2025, TridentLocker has targeted 12 organizations across sectors such as manufacturing, government, IT, and professional services in North America and Europe. The group utilizes data exfiltration over web protocols and encryption for impact. Previous notable incidents include a breach at the Belgian postal service bpost.
Federal contractors continue to face high threats from ransomware attacks, as evidenced by past incidents involving Conduent and Chemonics. Experts recommend enhanced segmentation, incident response, and supply chain scrutiny to mitigate rising threats to public sector partners.
Based on reporting by Cyber Security News.
