Sedgwick Acknowledges Data Breach Linked to TridentLocker Ransomware Attack

Claims administration giant Sedgwick disclosed a cybersecurity incident at its government-focused subsidiary on January 4, 2026, after the TridentLocker ransomware gang publicly claimed responsibility for stealing 3.4 gigabytes of sensitive data.

The breach underscores persistent vulnerabilities that federal contractors entrusted with critical U.S. government information face.

Sedgwick Government Solutions (SGS), the affected subsidiary, provides risk management and claims processing services to major federal agencies, including the Department of Homeland Security (DHS), Immigration and Customs Enforcement (ICE), Customs and Border Protection (CBP), U.S.

Citizenship and Immigration Services (USCIS), the Department of Labor, and the Cybersecurity and Infrastructure Security Agency (CISA).

The subsidiary also serves municipal agencies in all 50 states, as well as prominent institutions such as the Smithsonian Institution and the Port Authority of New York and New Jersey.

Threat Actor Disclosure and Data Exfiltration

TridentLocker, an emerging ransomware-as-a-service group that surfaced in late November 2025, announced SGS as a victim on New Year’s Eve, claiming to have exfiltrated 3.39 GB of documents.

The gang posted data samples on its dark web leak site as proof, employing double-extortion tactics that combine system encryption with threats of public data disclosure.

Since its emergence two months ago, TridentLocker has claimed 12 victims spanning manufacturing, government, information technology, and professional services sectors, primarily targeting organizations in North America and Europe.

The group has previously compromised the Belgian postal service bpost and has demonstrated sophisticated operational security practices aligned with modern ransomware methodologies.

Sedgwick emphasized in a statement to security media that the breach was limited in scope.

“Following detection of the incident, we initiated our incident response protocols and engaged external cybersecurity experts through outside counsel to assist with our investigation of the affected isolated file transfer system,” a company spokesperson explained.

The multinational corporation, which operates in 80 countries, has over 33,000 employees and generates multi-billion-dollar annual revenue, stressed that network segmentation contained the damage.

Ransomware Gang Claim
Ransomware Gang Claim

“Sedgwick Government Solutions is segmented from the rest of our business, and no wider Sedgwick systems or data were affected. Further, there is no evidence of access to claims management servers nor any impact on Sedgwick Government Solutions’ ability to continue serving its clients.”

Sedgwick has notified law enforcement and affected clients. CISA and DHS declined to comment on the breach.

The incident reflects a troubling pattern. Federal contractors have faced repeated ransomware campaigns, including the 2025 attack on Conduent that exposed personal data for more than 10 million individuals, and Chemonics’ breach targeting USAID operations.

Cybersecurity experts recommend that federal contractors implement enhanced network segmentation, mature incident response capabilities, and rigorous supply chain security scrutiny to mitigate rising threats to public sector operations.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyber Press as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories