// THREAT ACTOR
TRIDENTLOCKER_
DormantTRIDENTLOCKER is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of TRIDENTLOCKER — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 4
- 2025 12
Leak site mirrors
2 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onionTridentLocker snapshot · 2026-08-02 19:13 -
tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onionTridentLocker snapshot · 2026-08-02 19:34
Recent victims
The 50 most recent victims claimed by TRIDENTLOCKER. Total in the index: 16.
| Date listed | Victim | Description |
|---|---|---|
| 2026-04-26 | RT Software | |
| 2026-03-05 | Jameson Pepple Cantu PLLC | |
| 2026-02-06 | TMPartner | |
| 2026-01-12 | Eco Green Group | |
| 2025-12-31 | Sedgwick Government Solutions | |
| 2025-12-19 | allenprinting | |
| 2025-12-02 | noment | |
| 2025-12-01 | bpost | |
| 2025-11-29 | GuestTek | |
| 2025-11-29 | Advantage 360 | |
| 2025-11-29 | iqs | |
| 2025-11-29 | LMG Holdings | |
| 2025-11-29 | EnQuest | |
| 2025-11-29 | Calmec | |
| 2025-11-29 | typecaseinc | |
| 2025-11-29 | asiawba |