MalwareRansomwareVulnerability ExploitTridentLockerData ExfiltratedData EncryptedData PublishedRansom DemandedCustomer Data InvolvedDelayed DiscoveryTargetedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Managed Care Advisors-Sedgwick Government Solutions
bd_5a43cecf8a757680 · schema v1 · pii pii-v1
Full breach record for Managed Care Advisors-Sedgwick Government Solutions →Managed Care Advisors/Sedgwick Government Solutions (MCA/SGS) reported a ransomware incident involving its corporate SFTP server. The server was compromised on November 16, 2025, and discovered on December 4, 2025. The ransomware group TridentLocker encrypted files and exfiltrated approximately 3.4 GB of data, including PHI, names, SSNs, and addresses. Three New Hampshire residents were affected. MCA/SGS quarantined the server, restored backups, engaged Mandiant for forensics, notified the FBI, and is offering credit monitoring via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_25a0b3004d0f67acIndiana State AGfiled 2026-02-11(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/managed-care-advisors-sedgwick-government-solutions-20260210.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 10, 2026
- Raw hash
- b3564c0cea93f001ada8a20781880b532b48d674a94e18d9e6387fe9c69a93e6
Reporting entity
- Name
- Managed Care Advisors-Sedgwick Government Solutionsnorm: managed care advisors sedgwick government
Victim entity
- Name
- Managed Care Advisors-Sedgwick Government Solutionsnorm: managed care advisors sedgwick government
Incident
- Discovered
- Dec 4, 2025
- Materiality determined
- —
- Notification sent
- Feb 11, 2026
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Ransomware· TridentLocker
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1566.002 Spearphishing Link
- Threat actor
- TridentLockerExternalFinancial
- Regulator citations
- Notified New Hampshire Consumer Protection and Antitrust BureauNotified the Federal Bureau of Investigation (FBI)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.