Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ransomware-group-operationthird-party-vendor-breachbuild-pipeline-compromisebreach-disclosure-notification

Trellix Confirms Source Code Repository Breach as RansomHouse Claims Responsibility

Updated 20d agoFirst seen May 2, 202610 sources

Trellix disclosed that attackers gained unauthorized access to part of its internal source code repository, prompting the cybersecurity vendor to engage external forensic experts and notify law enforcement. The company said its investigation has so far found no evidence that its source code release or distribution process was affected, that customer-facing products were tampered with, or that the accessed code has been exploited in the wild. Trellix has not publicly identified the intrusion method, the exact data accessed, the threat actor behind the breach, or how long the attackers maintained access, and said additional details will be shared after the investigation is complete.

The incident drew heightened attention because Trellix is a major security supplier formed from the merger of McAfee Enterprise and FireEye, and compromise of a security vendor's code repository raises concerns about downstream supply-chain risk, exposed secrets, and insight into defensive logic. Days after the disclosure, the RansomHouse extortion group claimed responsibility and posted screenshots allegedly showing access to Trellix internal systems and dashboards, though it did not specify what data was stolen. Trellix has continued to state that there is no indication its build or software distribution pipeline was compromised, even as the breach is being compared with other recent source code and software supply-chain incidents affecting security vendors and platforms.

Share:
Trellix Confirms Source Code Repository Breach as RansomHouse Claims Responsibility
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 8, 20262mo ago

RansomHouse publicly claims responsibility for Trellix breach

RansomHouse publicly claimed responsibility for the Trellix intrusion and posted Trellix on its Tor leak site. The group shared screenshots allegedly showing access to Trellix internal systems, adding a new attribution claim to the incident.

Trellix Breach - RansomHouse Claims Access to Parts of Source Code
May 4, 20262mo ago

Infosecurity reports Trellix disclosed the breach on May 4

One report stated that Trellix disclosed on May 4 that threat actors had gained unauthorized access to part of its source code repository. The company was said to have notified law enforcement, engaged forensic experts, and found no evidence of source code exploitation or release-process impact.

Trellix Reveals Unauthorized Access to Source Code - Infosecurity Magazine
May 2, 20262mo ago

Trellix discloses unauthorized access to part of source code repository

Trellix disclosed that attackers gained unauthorized access to a portion of its internal source code repository. The company said it engaged forensic experts, notified law enforcement, and found no evidence that its source code release or distribution process was affected or that the accessed code had been exploited.

Trellix discloses the breach of a code repository
Apr 17, 20262mo ago

RansomHouse says it breached Trellix on April 17

RansomHouse claimed the compromise of Trellix occurred on April 17, 2026. The group later alleged it had accessed internal services and management dashboards, though the exact data exfiltrated was not specified.

Trellix Breach - RansomHouse Claims Access to Parts of Source Code
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Threat actors
4 linked
Malware
3 linked
Affected products
2 linked
TrivyBig-Ip
Organizations
22 linked
TrellixSecurity AffairsAdvanced Micro DevicesShopriteOktaLastPassCheckmarxAqua SecurityGoogleSemgrepMicrosoft CorporationSymphony Technology GroupMcAfee EnterpriseAikido SecurityHackerOneDark ReadingF5GitHubWizThe Hacker NewsNavia Benefit SolutionsDelta Dental
Breaches
3 linked
TRELLIX-2026-05AQUASECURITY-2026-05TRELLIX-2026-04
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.