Trellix published a May 2026 statement saying it had identified unauthorized access to a portion of its source code repository. The cybersecurity company said it engaged forensic experts and notified law enforcement.
Trellix said that, based on its investigation to date, it found no evidence that its source code release or distribution process was affected, or that its source code had been exploited. Security reporting noted that the exact access path and scope had not yet been disclosed. Coverage also highlighted a subsequent RansomHouse forum narrative with alleged screenshots—material readers should reconcile with Trellix's audited statements rather than accepting wholesale.
Canonical record: Trellix 2026 source-code repository incident on BreachHistory.
Sources: Trellix statement, The Hacker News, Security Affairs, BleepingComputer (disclosure), BleepingComputer (RansomHouse claim)