The News
Trellix disclosed on May 7 that an attacker accessed a "portion" of its source-code repository. The ransomware group RansomHouse claimed responsibility the same day, listing the company on its leak site. Trellix says it has "found no evidence that our source code release or distribution process was affected, or that our source code has been exploited."
Independent researchers at Cybernews who reviewed the leaked material assert the breach extended further, into critical VMware, Rubrik, and Dell EMC systems used inside Trellix's infrastructure.
The View
Trellix's statement covers the release pipeline. "No evidence that our source code release or distribution process was affected" is a claim about whether shipped product downstream of the repository was tampered with, and it says nothing about whether source was accessed. That matters because supply-chain integrity is what customers care about. If the build pipeline produced unaltered binaries, customers don't have a SolarWinds-style exposure even if the source itself was read.
"No source code has been exploited" tells you the company hasn't observed exploitation. It leaves open whether the source code itself left the building. Trellix is choosing words it can stand behind, and circumscribed language like this is what you write when the scope is still under forensic investigation and the legal team is in the room.
The Cybernews reporting is the bigger concern. It describes access to VMware, Rubrik, and Dell EMC systems, infrastructure for backup, virtualization, and storage that sits one layer below the source-code repository. If the attacker reached those, they had administrative-level access to Trellix's internal IT environment. That would make the source-code access a downstream consequence of a wider compromise, and it changes the threat model considerably.
Room for Disagreement
A more charitable read: ransomware groups have a strong incentive to overstate what they accessed in order to maximize extortion leverage, and Cybernews is reviewing material the attackers chose to publish. Trellix may hold telemetry that legitimately bounds the scope to the source-code repository alone. Until the forensics report lands, both readings are defensible.
Notable
- Trellix has notified law enforcement and engaged third-party forensic experts, the standard breach-response posture
- RansomHouse has been active throughout 2025–2026 with a pattern of source-code-targeted extortion; Trellix is among their highest-profile claims
- Trellix is a security company. The reputational damage compounds the technical damage, and every customer's compliance team is now writing memos about whether to extend or cancel
Bottom Line
If you're a Trellix customer, keep the product in place, read the next forensic update carefully, and check your own incident-response runbook for "what if our security vendor is compromised." If you don't have that runbook, write it this week regardless of vendor.