Executive Summary
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network.
This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
Why This Matters Now
Ransomware groups like TridentLocker are intensifying attacks on critical government suppliers, jeopardizing sensitive public-sector data. This growing trend poses urgent risks for national security and public trust, emphasizing the need for immediate improvements in segmentation, visibility, and compliance for all government contractors.
Attack Path Analysis
Attackers gained initial access to Sedgwick Government Solutions via compromise of an externally-facing file transfer system, followed by escalating privileges to move within the isolated environment. They then performed lateral movement across internal workloads to discover and access sensitive information, establishing command and control to maintain persistence and coordinate activity. Sensitive documents were exfiltrated from the environment, culminating in the deployment of ransomware and public disclosure of stolen data.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited an isolated file transfer system with potential vulnerabilities or misconfigurations to establish a foothold within the subsidiary’s network.
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing
Exfiltration Over Alternative Protocol
Valid Accounts
Data Encrypted for Impact
Data Manipulation: Stored Data Manipulation
Automated Exfiltration
Transfer Data to Cloud Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 Rev. 5 – Incident Handling
Control ID: IR-4
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
PCI DSS v4.0 – Security Event Monitoring
Control ID: 10.4.1
CISA Zero Trust Maturity Model 2.0 – Data Segmentation and System Isolation
Control ID: Data: Segmentation & Isolation
NIS2 Directive 2022/2555 – Incident Handling Capabilities
Control ID: Art. 21(2) (b)
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 10
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct ransomware impact on federal contractor serving CISA, DHS, and other agencies highlights critical infrastructure vulnerabilities requiring enhanced segmentation and threat detection capabilities.
Computer/Network Security
TridentLocker ransomware breach of cybersecurity contractor exposes industry credibility risks, demanding stronger zero trust architectures and encrypted traffic protection for client data isolation.
Professional Training
Government contractor breach affects training delivery systems for federal agencies, necessitating secure hybrid connectivity and anomaly detection to protect sensitive educational content and processes.
Insurance
Sedgwick's claims administration breach demonstrates ransomware exposure in insurance operations, requiring egress security controls and multicloud visibility to prevent data exfiltration across client portfolios.
Sources
- Sedgwick confirms breach at government contractor subsidiaryhttps://www.bleepingcomputer.com/news/security/sedgwick-confirms-breach-at-government-contractor-subsidiary/Verified
- Sedgwick discloses data breach after TridentLocker ransomware attackhttps://securityaffairs.com/186525/data-breach/sedgwick-discloses-data-breach-after-tridentlocker-ransomware-attack.htmlVerified
- Cyberattack against Sedgwick’s federal contractor subsidiary confirmedhttps://www.scworld.com/brief/cyberattack-against-sedgwicks-federal-contractor-subsidiary-confirmedVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Network segmentation, east-west security, real-time anomaly detection, and egress enforcement offered by CNSF controls would have significantly limited attacker movement, isolated workloads, and blocked data exfiltration, while improving visibility and real-time policy response throughout the attack lifecycle.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized inbound access to workloads.
Control: Zero Trust Segmentation
Mitigation: Minimizes privilege abuse by enforcing identity-aware least privilege access.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized intra-cloud lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Detects and alerts on abnormal outbound command-and-control patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unsanctioned data exfiltration to attacker-controlled destinations.
Accelerates incident response and limits blast radius of disruptive events.
Impact at a Glance
Affected Business Functions
- Claims Management
- Risk Assessment
- Government Contracting Services
Estimated downtime: N/A
Estimated loss: N/A
Approximately 3.4 GB of data was exfiltrated by the TridentLocker ransomware group. The specific contents of the stolen data have not been disclosed, but given Sedgwick Government Solutions' role, it may include sensitive information related to federal agencies and their operations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate critical workloads and restrict lateral movement pathways.
- • Deploy centralized Cloud Firewalls with URL filtering to reduce attack surface and monitor exposure of file transfer or remote access services.
- • Enforce rigorous egress security policies to block unauthorized outbound data transfers and identify exfiltration attempts in real time.
- • Utilize continuous anomaly detection and threat response mechanisms to rapidly surface and contain covert attacker behaviors.
- • Establish comprehensive east-west traffic visibility across all cloud and hybrid environments to audit, detect, and block suspicious movements.



