Skip to content
Data breachContained

Trellix source code repository breach claimed by RansomHouse

Cybersecurity vendor Trellix, formed from McAfee Enterprise and FireEye, disclosed unauthorized access to a portion of its source code repository; the RansomHouse extortion group later listed the company on its leak site.

Victim
Trellix

On 4 May 2026, Trellix, the cybersecurity company created in 2021-2022 from the merger of McAfee Enterprise and FireEye, disclosed that it had "recently identified unauthorized access to a portion of our source code repository." The company said it was working with forensic experts and had notified law enforcement.

Trellix stated that it had found no evidence that its source code release or distribution process was affected, or that its source code had been exploited. It did not say how the intruders got in, how long they had access, or which products' code was involved.

Claim of responsibility

On 7 May, the RansomHouse extortion group listed Trellix on its data-leak site and published screenshots that it said showed access to the company's appliance management systems. A Trellix spokesperson said the company was aware of the claims and looking into them, without confirming a link between the group and the intrusion.

Why it matters

Trellix products protect tens of thousands of enterprise and government customers. Source code for a security vendor is a high-value prize: it can show attackers where detection logic lives and where weaknesses in agents or update paths might be found. The breach came amid a run of 2026 intrusions into security and developer-tool vendors, several of them linked to the theft of build and CI credentials.

Timeline

  1. Trellix discloses that it identified unauthorized access to a portion of its source code repository and has notified law enforcement.

  2. RansomHouse lists Trellix on its data-leak site, publishing screenshots it presents as proof of access.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers/
  3. thehackernews.comhttps://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html
  4. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/trellix-reveals-unauthorized/

Related incidents