Data breach
Sedgwick Government Solutions
- Records
- 34,398
- Breach date
- 30 December 2025Estimated
- Added
- 17 February 2026
What was exposed
2 types of data · 5 more reported
- Phone numbers34,398
- Email addresses2,654
- Social security numbersReported, not counted
- NamesReported, not counted
- Home addressesReported, not counted
- Dates of birthReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Managed Care Advisors/Sedgwick Government Solutions, a federal government contractor that handles workers' compensation and managed care services for U.S. agencies, is notifying people after a ransomware attack on one of its file transfer servers. According to our investigation team, the breach involves approximately 34,398 records, including 34,398 phone numbers and 2,654 email addresses. The company discovered on December 4, 2025 that files on a corporate Secure File Transfer Protocol (SFTP) server had been encrypted by an unauthorized party. That server held sensitive files tied to the Nationwide Provider Network for the World Trade Center (WTC) Health Program, which the company manages under federal contract. A ransomware group calling itself TridentLocker claimed responsibility for the theft and leaked roughly 3.4 gigabytes of the organization's data online, according to reporting by ClassAction.org.
Breach Timeline
November 16, 2025: A third party gained access to the corporate SFTP server and encrypted files, according to ClaimDepot's summary of the company's disclosures.
December 4, 2025: The company discovered the unauthorized access and activated its incident response plan.
December 5, 2025: All connections to the server were disabled and encrypted data was restored from a secure backup.
January 2, 2026: The TridentLocker ransomware group claimed responsibility and leaked about 3.4 gigabytes of stolen data, per ClassAction.org.
February 11, 2026: Notification letters began going out to affected individuals.
What Information Was Compromised?
Our analysis found the following data types in this breach: phone numbers and email addresses.
The company's notice, as summarized by ClaimDepot and Cafferty Clobes, lists additional exposed fields: first and last names, addresses, full or partial Social Security numbers, dates of birth, medical record images, completed WTC Health Program forms, certified health conditions, and other protected health information.
Not every individual is affected by every type of data listed here.
Because the exposed server supported the WTC Health Program's provider network, much of the material relates to health program claimants and their records. The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation and the New Hampshire Attorney General, which reported 16 affected Massachusetts residents and three New Hampshire residents so far, though the full scope remains unclear. Our investigation team's index of the leaked data shows phone numbers for all 34,398 records, with email addresses present in 2,654 of them.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, dates of birth, and medical records carries serious risk. With those details, criminals can attempt identity theft, open fraudulent accounts, or file fake tax returns in someone's name. Medical identity theft is a distinct concern: exposed health records and program forms could be used to fraudulently obtain care or submit bogus claims, which can be difficult and slow to undo. The public leak of the data on a dark web site means the information is available to anyone willing to look, not just the initial attackers. Phishing messages that reference health program claims or benefits are also a realistic follow-on threat, since scammers can use accurate personal details to appear legitimate.
What Is Sedgwick Government Solutions Doing in Response?
According to the company's disclosures, MCA/SGS quarantined the affected SFTP server, disabled all connections to it, and restored data from a secure backup on December 5, 2025. The company engaged Mandiant, a cybersecurity incident response firm, to conduct a forensic analysis and notified the FBI. Notification letters to affected individuals began on February 11, 2026, and the company is offering 12 months of complimentary credit monitoring and identity theft protection services through Kroll, along with a dedicated call center. Sedgwick has said the affected file transfer platform was segmented from its broader operations and that there is no evidence of access to its claims management servers.
What Should You Do If You Were Affected?
If you received a notification letter, enroll in the complimentary credit monitoring and identity protection services offered through Kroll. Review your credit reports for accounts or inquiries you do not recognize, and consider placing a fraud alert or security freeze with the three major credit bureaus. Watch your Explanation of Benefits statements and health program correspondence for services you did not receive, and report anything suspicious to the provider. Be cautious with unsolicited calls or emails referencing your claims or health program enrollment, since attackers with leaked data often use it to lend credibility to scams.
In the news
- ClaimDepot: Managed Care Advisors/Sedgwick Breach Exposes PHIclaimdepot.com (opens in a new tab)
- ClassAction.org: Managed Care Advisors/Sedgwick Data Breach Reportedclassaction.org (opens in a new tab)
- Cafferty Clobes: Sedgwick Government Solutions Data Breach Investigationcaffertyclobes.com (opens in a new tab)
