The recently disclosed cyberattack targeting Trellix’s source code repository now appears to be attributed to the ransomware group RansomHouse. The group has reportedly released a limited number of images as evidence that it has gained access to the company’s internal systems, raising concerns about a possible wider breach. Meanwhile, new screenshots posted on a dark web channel suggest access to the company’s device management system, but their authenticity has not been independently confirmed by security researchers or third-party analysts.

Trellix, one of the most well-known cybersecurity companies with a client base that includes Fortune 100 organizations, manages thousands of enterprise customers in more than 180 countries. The company's scale makes any security incident particularly critical, not only for itself but also for the security ecosystem it serves.
See also: Polish security service reports ICS violations at water facilities
Trellix's official position and the ongoing investigation
The company publicly confirmed the breach in early May, saying that unauthorized access to part of its source code repository had been detected. According to the announcement, incident response protocols and collaboration with specialized analysts to identify the source of the attack and limit the damage.
Trellix has also informed law enforcement authorities, stressing that there is currently no indication that the code has been modified or exploited operationally. However, the investigation remains ongoing and the company declined to provide details on the possible attacker or the exact access points exploited by the attackers.
RansomHouse's involvement and team profile
RansomHouse, according to the data it published, claims that the initial access to the Trellix environment took place in mid-April and led to data extortion for the purpose of extortion. The group first appeared in 2022 and has evolved into one of the most active players in the field of data extortion, not always relying on classic ransomware payloads, but focusing mainly on data leakage.
See also: Canvas breach affects schools and universities in the US
Over time, the group has enriched its technical arsenal with tools that enable more complex attacks, such as automated encryption on virtual infrastructures or double file encryption, making data recovery even more difficult for victims. This transition shows a clear trend of professionalization in the cybercrime ecosystem.

The broader footprint and implications for the security industry
Trellix is not an isolated incident in the modern cyberattack landscape. In recent years, similar attacks have targeted large technology and infrastructure companies, aiming to access source code repositories, which are considered particularly valuable for understanding internal security mechanisms.
The potential source code leak poses serious risks, as it can reveal vulnerabilities that have not yet been discovered or patched. This in turn gives attackers a significant time advantage to develop targeted exploits. The cybersecurity industry is closely following the case, as a company in the industry itself is now in the shoes of the victim.
See also: Claude AI used to attack water systems

Uncertainty and next steps of the research
Despite RansomHouse's announcements and claims, much remains unconfirmed. It is unclear whether the breach was limited to the source code repository or extended to other internal systems. There is also no official confirmation as to whether customer data was compromised or whether the attack had a broader operational impact.
Trellix has pledged to continue the investigation and release more information once the analysis of the findings is complete. Until then, the case remains another example of the increasing pressure even cybersecurity companies themselves are under in the face of organized and evolving threats.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
