The Containment Era is here. →Explore

Executive Summary

In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network.

This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.

Why This Matters Now

Ransomware groups like TridentLocker are intensifying attacks on critical government suppliers, jeopardizing sensitive public-sector data. This growing trend poses urgent risks for national security and public trust, emphasizing the need for immediate improvements in segmentation, visibility, and compliance for all government contractors.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach highlighted the need for robust segmentation, encrypted data transfer, and real-time anomaly detection to align with NIST, HIPAA, PCI, and ZTMM requirements.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Network segmentation, east-west security, real-time anomaly detection, and egress enforcement offered by CNSF controls would have significantly limited attacker movement, isolated workloads, and blocked data exfiltration, while improving visibility and real-time policy response throughout the attack lifecycle.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Prevents unauthorized inbound access to workloads.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Minimizes privilege abuse by enforcing identity-aware least privilege access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detects and blocks unauthorized intra-cloud lateral movement.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Detects and alerts on abnormal outbound command-and-control patterns.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocks unsanctioned data exfiltration to attacker-controlled destinations.

Impact (Mitigations)

Accelerates incident response and limits blast radius of disruptive events.

Impact at a Glance

Affected Business Functions

  • Claims Management
  • Risk Assessment
  • Government Contracting Services
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Approximately 3.4 GB of data was exfiltrated by the TridentLocker ransomware group. The specific contents of the stolen data have not been disclosed, but given Sedgwick Government Solutions' role, it may include sensitive information related to federal agencies and their operations.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate critical workloads and restrict lateral movement pathways.
  • Deploy centralized Cloud Firewalls with URL filtering to reduce attack surface and monitor exposure of file transfer or remote access services.
  • Enforce rigorous egress security policies to block unauthorized outbound data transfers and identify exfiltration attempts in real time.
  • Utilize continuous anomaly detection and threat response mechanisms to rapidly surface and contain covert attacker behaviors.
  • Establish comprehensive east-west traffic visibility across all cloud and hybrid environments to audit, detect, and block suspicious movements.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image