| SYMBOL | COMMON_NAME | aka. SYNONYMS |
TridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services and telecom providers. They have claimed breaches of multiple victims, such as TMPartner, Sedgwick, and Advantage 360, often exfiltrating sensitive data before deploying ransomware. The group employs techniques such as stolen credentials, phishing, and exploitation of unpatched software to gain initial access and move laterally within networks. Their operations are characterized by high visibility postings on their leak portal, which include detailed victim profiles and countdown timers to create public pressure.
There are currently no families associated with this actor.
| 2026-01-02
⋅
The Record
⋅
Sedgwick confirms cyber incident affecting its major federal contractor subsidiary TridentLocker |