
Sedgwick, which provides claims administration services, said it is probing a data security incident involving a subsidiary that works with multiple U.S. government agencies.
Headquartered in Memphis, Tennessee, Sedgwick is a global third-party administrator providing claims administration, loss adjusting, and technology-enabled services. It employs more than 33,000 people worldwide, serves major retailers such as Amazon, Target, and Home Depot, and works extensively with U.S. federal, state, and local government agencies.
Recently, a group of threat actors going by the name TridentLocker hacking group said it infiltrated the internal network of Sedgwick Government Solutions and stole confidential data. The group said it obtained 2,947 files totaling 3.4 GB and threatened to release the data unless its ransom demands are met.
🚨Cyberattack Alert ‼️
— Hackmanac (@H4ckmanac) December 31, 2025
🇺🇸United States - Sedgwick Government Solutions
TridentLocker hacking group claims to have breached Sedgwick Government Solutions.
Allegedly, the attackers exfiltrated 3.4 GB of data.
Sector: Professional / Scientific / Technical
Threat class:… pic.twitter.com/uBe3jCR4Ow
Acknowledging the hackers’ claims, a Sedgwick spokesperson said the company immediately activated its incident response protocols and engaged external cyber security experts to assess the nature and scope of the incident.
In a statement shared withThe Record Media, the spokesperson said, “Following the detection of the incident, we initiated our incident response protocols and engaged external cybersecurity experts through outside counsel to assist with our investigation of the affected isolated file transfer system.
“Importantly, Sedgwick Government Solutions is segmented from the rest of our business, and no wider Sedgwick systems or data were affected. Further, there is no evidence of access to claims management servers nor any impact on Sedgwick Government Solutions ability to continue serving its clients,” the spokesperson added.
The company added that it has notified the appropriate law enforcement authorities and is working with them to resolve the incident as quickly as possible.
Emerging in late November 2025, TridentLocker is a ransomware-as-a-service (RaaS) operation that employs double-extortion tactics, encrypting systems while threatening to leak stolen data if ransoms are not paid. Its Tor leak site lists 12 confirmed victims, including Belgian postal and parcel delivery service bpost.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543