Trellix disclosed that attackers gained unauthorized access to part of its internal source code repository, prompting the cybersecurity vendor to engage external forensic experts and notify law enforcement. The company said its investigation has so far found no evidence that its source code release or distribution process was affected, that customer-facing products were tampered with, or that the accessed code has been exploited in the wild. Trellix has not publicly identified the intrusion method, the exact data accessed, the threat actor behind the breach, or how long the attackers maintained access, and said additional details will be shared after the investigation is complete.
The incident drew heightened attention because Trellix is a major security supplier formed from the merger of McAfee Enterprise and FireEye, and compromise of a security vendor's code repository raises concerns about downstream supply-chain risk, exposed secrets, and insight into defensive logic. Days after the disclosure, the RansomHouse extortion group claimed responsibility and posted screenshots allegedly showing access to Trellix internal systems and dashboards, though it did not specify what data was stolen. Trellix has continued to state that there is no indication its build or software distribution pipeline was compromised, even as the breach is being compared with other recent source code and software supply-chain incidents affecting security vendors and platforms.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
RansomHouse publicly claimed responsibility for the Trellix intrusion and posted Trellix on its Tor leak site. The group shared screenshots allegedly showing access to Trellix internal systems, adding a new attribution claim to the incident.
One report stated that Trellix disclosed on May 4 that threat actors had gained unauthorized access to part of its source code repository. The company was said to have notified law enforcement, engaged forensic experts, and found no evidence of source code exploitation or release-process impact.
Trellix disclosed that attackers gained unauthorized access to a portion of its internal source code repository. The company said it engaged forensic experts, notified law enforcement, and found no evidence that its source code release or distribution process was affected or that the accessed code had been exploited.
RansomHouse claimed the compromise of Trellix occurred on April 17, 2026. The group later alleged it had accessed internal services and management dashboards, though the exact data exfiltrated was not specified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourcedarkreading.com
Open sourceblog.cybernexora.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.