Menu
Browse

Cyber Incident Victim: Trellix

Date

May 2026

Location

United States of America

Status

Unknown

Updated

2026-08-16 01:26

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending
Summary

Trellix disclosed that threat actors gained unauthorized access to a portion of its source code repository and notified law enforcement while working with forensic experts to determine the scope. The company stated that, based on its investigation to date, there is no evidence that its source code release or distribution process was affected or that the code has been exploited. RansomHouse ransomware group claimed responsibility for the breach, publishing screenshots that show access to internal services and management dashboards but not specifying the type or amount of data taken. Security observers noted a possible link to a recent supply chain campaign involving TeamPCP and Lapsus$, although the company has not confirmed any connection.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On May 4 2026 Trellix issued a public statement indicating that it had identified unauthorized access to a portion of its source code repository. The company said it had notified law enforcement and was collaborating with leading forensic experts to determine the exact nature and scope of the incident. Trellix emphasized that, based on its investigation to date, there was no evidence that its source code release or distribution process had been affected, nor that the accessed source code had been exploited in any way. The statement was posted on the company’s website and was accompanied by a promise to release additional details once the investigation was complete. Trellix described itself as a privately held firm that resulted from the 2021 merger of McAfee Enterprise and FireEye after their acquisition by the private equity firm Symphony Technology Group. The firm provides threat intelligence, AI‑powered detection and response services including network detection and response (NDR) and endpoint detection and response (EDR), as well as data security and email security solutions to its customers.

Cyber Incident Image

The following day, May 5 2026, an article in Infosecurity Magazine elaborated on the disclosure, quoting Isaac Evans, the founder of the software security firm Semgrep, who warned that access to a security vendor’s source code could give attackers a roadmap to defensive controls, detection logic, and trusted update or build paths. Evans noted that attackers were not only after customer data but also sought leverage that could turn the software ecosystem itself into a delivery mechanism for further compromise. The article reiterated that Trellix had not identified any impact on its release or distribution pipelines and that the company remained tight‑lipped about the specifics while awaiting the outcome of its forensic investigation. It also mentioned that several other vendors—Aqua Security and Checkmarx—had recently been compromised in a software supply chain attack that targeted the security scanner Trivy, which had exposed numerous enterprise secrets. The report noted signs that the threat actor group TeamPCP was collaborating with the Vect ransomware group to target victims of that Trivy‑focused campaign. Evans further explained that stolen tokens, CI/CD pipeline gaps, and overtrusted build workflows could allow attackers to move laterally between projects, harvest secrets, and implant persistence.

On May 8 2026 SecurityWeek published a story in which the ransomware group RansomHouse claimed responsibility for the Trellix incident. According to the article, RansomHouse posted a notice on its leak website naming Trellix and released several screenshots that appeared to show access to internal services and management dashboards. The group did not specify the volume or type of data it had exfiltrated from Trellix, nor did it make any explicit claims about the nature of the stolen information. Trellix’s earlier statement that it had found no evidence of exploitation or impact on its source code release or distribution process was reiterated in the SecurityWeek piece. The article also observed that the timing of the Trellix breach coincided with a recent supply chain attack linked to the hacker groups TeamPCP and Lapsus$, which had affected other cybersecurity firms such as Checkmarx, Aqua Security, and Bitwarden. While a direct connection had not been confirmed, the report noted that TeamPCP had reportedly partnered with ransomware groups in the past.

The SecurityWeek article provided background on RansomHouse, describing it as an extortion operation that emerged in 2022 and primarily functions as a ransomware‑as‑a‑service (RaaS) provider targeting large enterprises. The group’s typical tactics involve encrypting victims’ files and exfiltrating valuable data to increase pressure for ransom payments. At the time of the report, RansomHouse’s Tor‑based leak website listed more than 170 victims. The article was authored by Eduard Kovacs, senior managing editor at SecurityWeek, who holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Throughout the coverage, Trellix consistently maintained that its investigation was ongoing and that it would share further details once completed. The company’s communications stressed that it had engaged law enforcement and forensic experts, that it had not observed any alteration to its source code release or distribution mechanisms, and that it had not detected exploitation of the accessed code. The statements from Trellix, the commentary from Isaac Evans, and the claims made by RansomHouse together form the factual record of the incident as presented in the supplied sources. No additional conclusions, recommendations, or speculative assertions are included beyond what is explicitly documented in the articles. The narrative ends here.

Sources
Sources available to members
2 sources