Managed Care Advisors/Sedgwick Government Solutions (MCA/SGS) reported a ransomware incident involving its corporate SFTP server. The server was compromised on November 16, 2025, and discovered on December 4, 2025. The ransomware group TridentLocker encrypted files and exfiltrated approximately 3.4 GB of data, including PHI, names, SSNs, and addresses. Three New Hampshire residents were affected. MCA/SGS quarantined the server, restored backups, engaged Mandiant for forensics, notified the FBI, and is offering credit monitoring via Kroll.
Affected (this filing): 3