Sedgwick Acknowledges Data Breach Linked to TridentLocker Ransomware Attack - cyberpress.org
cyberpress.orgArchived Mar 18, 2026✓ Full text saved
Sedgwick Acknowledges Data Breach Linked to TridentLocker Ransomware Attack cyberpress.org
Full text archived locally
✦ AI Summary· Claude Sonnet
Sedgwick Acknowledges Data Breach Linked to TridentLocker Ransomware Attack
By AnuPriya
January 7, 2026
Categories:
Cyber Security NewsCybersecurityData Breach
Claims administration giant Sedgwick disclosed a cybersecurity incident at its government-focused subsidiary on January 4, 2026, after the TridentLocker ransomware gang publicly claimed responsibility for stealing 3.4 gigabytes of sensitive data.
The breach underscores persistent vulnerabilities that federal contractors entrusted with critical U.S. government information face.
Sedgwick Government Solutions (SGS), the affected subsidiary, provides risk management and claims processing services to major federal agencies, including the Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE), Customs and Border Protection (CBP), U.S.
Citizenship and Immigration Services (USCIS), the Department of Labor, and the Cybersecurity and Infrastructure Security Agency (CISA).
The subsidiary also serves municipal agencies in all 50 states, as well as prominent institutions such as the Smithsonian Institution and the Port Authority of New York and New Jersey.
Threat Actor Disclosure and Data Exfiltration
TridentLocker, an emerging ransomware-as-a-service group that surfaced in late November 2025, announced SGS as a victim on New Year’s Eve, claiming to have exfiltrated 3.39 GB of documents.
The gang posted data samples on its dark web leak site as proof, employing double-extortion tactics that combine system encryption with threats of public data disclosure.
Since its emergence two months ago, TridentLocker has claimed 12 victims spanning manufacturing, government, information technology, and professional services sectors, primarily targeting organizations in North America and Europe.
The group has previously compromised the Belgian postal service bpost and has demonstrated sophisticated operational security practices aligned with modern ransomware methodologies.
Sedgwick emphasized in a statement to security media that the breach was limited in scope.
“Following detection of the incident, we initiated our incident response protocols and engaged external cybersecurity experts through outside counsel to assist with our investigation of the affected isolated file transfer system,” a company spokesperson explained.
The multinational corporation, which operates in 80 countries, has over 33,000 employees and generates multi-billion-dollar annual revenue, stressed that network segmentation contained the damage.
Ransomware Gang Claim
“Sedgwick Government Solutions is segmented from the rest of our business, and no wider Sedgwick systems or data were affected. Further, there is no evidence of access to claims management servers nor any impact on Sedgwick Government Solutions’ ability to continue serving its clients.”
Sedgwick has notified law enforcement and affected clients. CISA and DHS declined to comment on the breach.
The incident reflects a troubling pattern. Federal contractors have faced repeated ransomware campaigns, including the 2025 attack on Conduent that exposed personal data for more than 10 million individuals, and Chemonics’ breach targeting USAID operations.
Cybersecurity experts recommend that federal contractors implement enhanced network segmentation, mature incident response capabilities, and rigorous supply chain security scrutiny to mitigate rising threats to public sector operations.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyber Press as a Preferred Source in Google.
Share
Facebook
Twitter
Pinterest
WhatsApp
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.
Recent Articles
Apple WebKit Vulnerability Allows Malicious Content Bypass on iOS and macOS
Apple March 18, 2026
Diplomats and Critical Infrastructure Targeted In Boggy Serpens Spy Campaign
APT March 18, 2026
Critical Telnetd Vulnerability Allows Remote Code Execution Attacks
Cyber Security News March 18, 2026
OpenAI Launches GPT-5.4 Mini and Nano, Delivering Answers 2× Faster
Cyber Security News March 18, 2026
Fake Telegram Site Delivers Multi-Stage Malware Using In-Memory Execution
Cyber Security News March 18, 2026
Related Stories
Apple
Apple WebKit Vulnerability Allows Malicious Content Bypass on iOS and macOS
AnuPriya - March 18, 2026
APT
Diplomats and Critical Infrastructure Targeted In Boggy Serpens Spy Campaign
Varshini - March 18, 2026
Cyber Security News
Critical Telnetd Vulnerability Allows Remote Code Execution Attacks
AnuPriya - March 18, 2026
Cyber Security News
OpenAI Launches GPT-5.4 Mini and Nano, Delivering Answers 2× Faster
AnuPriya - March 18, 2026
Cyber Security News
Fake Telegram Site Delivers Multi-Stage Malware Using In-Memory Execution
Varshini - March 18, 2026
Cyber Security News
Ubuntu Desktop Vulnerability Allows Privilege Escalation to Full Root Access
AnuPriya - March 18, 2026
LEAVE A REPLY
Comment:
Name:*
Email:*
Website: