← All ransomware groups
Tridentlocker logo

Ransomware group profile · #173 by claimed victims

Tridentlocker ransomware

TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of regulated or third-party data — including government services, telecom, and engineering firms — across the US, Canada, UK, and Asia using double-extortion tactics.

Active First seen Nov 2025
17Victims claimed on leak sites
1Victims in the last 30 days
1Victims in the last 90 days
7Countries hit
2Leak-site URLs tracked, 0 online
4 Sep 2026Latest claim recorded

Victimology

Who Tridentlocker claims to have breached, from 17 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 8Dec 2025: 4Jan 2026: 1JanFeb 2026: 1Mar 2026: 1Apr 2026: 1AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 1

Top sectors

Technology5
Professional Services3
Energy & Utilities2
Manufacturing2
Other1
Government & Defense1

Top countries

United States7
United Kingdom3
Canada2
South Korea1
Japan1
Belgium1
Iraq1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
SouthernCarlson southerncarlson.com Not Found 4 Sep 2026
RT Software rtsw.co.uk Technology GB 27 Apr 2026
Jameson Pepple Cantu PLLC jpclaw.com Professional Services US 5 Mar 2026
TMPartner tm-partner.ch Other JP 6 Feb 2026
Eco Green Group ecogreengroup.co.uk Energy & Utilities GB 12 Jan 2026
Sedgwick Government Solutions sedgwickgovernment.com Government & Defense US 30 Dec 2025
allenprinting allenprinting.com Professional Services US 19 Dec 2025
noment noment.com Not Found US 2 Dec 2025
bpost bpost.be Technology BE 1 Dec 2025
GuestTek guesttek.com Technology CA 29 Nov 2025
Advantage 360 advantage360.com Technology US 29 Nov 2025
iqs Not Found IQ 29 Nov 2025

All 17 Tridentlocker victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Tridentlocker is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Tridentlocker ransomware still active?
Tridentlocker is tracked as active. The most recent leak-site claim VULONE recorded is dated 4 September 2026. 1 victims were claimed in the last 30 days.
How many victims has Tridentlocker claimed?
VULONE has recorded 17 leak-site victim claims attributed to Tridentlocker since November 2025, across 7 countries and 7 sectors.
Which industries does Tridentlocker target?
The sectors most often named on the Tridentlocker leak site are Technology, Professional Services, Energy & Utilities.
Which countries are most affected by Tridentlocker?
Most Tridentlocker victims recorded by VULONE are located in United States, United Kingdom, Canada.
Where does VULONE get Tridentlocker victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].