THREAT ACTOR
TRIDENTLOCKER_
ActiveTRIDENTLOCKER is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of TRIDENTLOCKER, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 5
- 2025 12
Leak site mirrors
2 mirrors tracked, 2 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onionTridentLocker snapshot · 2026-09-23 05:02 -
tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onionTridentLocker snapshot · 2026-09-23 05:26
Recent victims
The 50 most recent victims claimed by TRIDENTLOCKER. Total in the index: 17.
| Date listed | Victim | Description |
|---|---|---|
| 2026-09-04 | SouthernCarlson | |
| 2026-04-26 | RT Software | |
| 2026-03-05 | Jameson Pepple Cantu PLLC | |
| 2026-02-06 | TMPartner | |
| 2026-01-12 | Eco Green Group | |
| 2025-12-31 | Sedgwick Government Solutions | |
| 2025-12-19 | allenprinting | |
| 2025-12-02 | noment | |
| 2025-12-01 | bpost | |
| 2025-11-29 | GuestTek | |
| 2025-11-29 | Advantage 360 | |
| 2025-11-29 | iqs | |
| 2025-11-29 | LMG Holdings | |
| 2025-11-29 | EnQuest | |
| 2025-11-29 | Calmec | |
| 2025-11-29 | typecaseinc | |
| 2025-11-29 | asiawba |
CONFIRMED ATTACKS
Tridentlocker confirmed attacks: 2 verified incidents
Ransomnews has verified 2 Tridentlocker incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. All of them fall in December 2025. United States accounts for 1 of them (50%), with victims recorded in 2 countries in total. The most affected sector is service, at 1 confirmed victim. Where a figure was disclosed (1 case), these incidents account for 290 exposed records.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Tridentlocker incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| December 2025 | Sedgwick Government Solutions | Service | Maryland, United States | 290 | Unknown | Source |
| December 2025 | Belgian Post Group (Bpost) | Government | Brussels, Belgium | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Tridentlocker's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.