2026 Trellix - unauthorized access to portion of source code repository
Data compromised
Portion of source code repository; no evidence of source code exploitation or release-process impact reported by Trellix
Technical writeup
Trellix published a May 2026 statement saying it had identified unauthorized access to a portion of its source code repository. The company said it began working with forensic experts, notified law enforcement, and had found no evidence that its source code release or distribution process was affected or that its source code had been exploited. Security reporting noted that the exact data accessed and intrusion path had not yet been disclosed. BleepingComputer separately reported that the RansomHouse group claimed the intrusion and circulated alleged internal Trellix screenshots—claims not mirrored in Trellix's initial disclosure emphasis on repository scope.
Root cause
Unauthorized access to a source code repository; intrusion path under investigation
References
- https://www.trellix.com/statement/
- https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html
- https://securityaffairs.com/191584/data-breach/trellix-discloses-the-breach-of-a-code-repository.html
- https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/
- https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers/