BigTech CompaniesCybersecurityNewswireTechnology

Trellix confirms data breach after source code theft

Originally published on: May 5, 2026
▼ Summary

– Trellix, a global cybersecurity company formed from the merger of McAfee Enterprise and FireEye, disclosed a data breach where attackers accessed a portion of its source code repository.
– The company is investigating the incident with the help of outside forensic experts and has notified law enforcement.
– Trellix has not found evidence that the attackers exploited or altered the accessed source code, nor that its source code release or distribution process was affected.
– Trellix has not yet provided details on when the breach was detected, whether customer data was stolen, or if a ransom demand was made.
– This breach follows recent cyberattacks on other security firms, including Checkmarx, Cisco, and HackerOne.

Cybersecurity firm Trellix has confirmed a data breach after unauthorized actors gained access to a portion of its source code repository. The company, formed in October 2021 through the merger of McAfee Enterprise and FireEye, serves more than 50,000 business and government clients worldwide and protects over 200 million endpoints.

In an official statement updated Monday, Trellix said it is actively investigating the incident with the help of outside forensic experts. So far, the company has found no evidence that the attackers have exploited or altered the source code they accessed.

“Trellix recently identified unauthorized access to a portion of our source code repository. Upon learning of this matter, we immediately began working with leading forensic experts to resolve it,” the company said. “We have also notified law enforcement. Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited.”

A Trellix spokesperson shared the same statement when BleepingComputer sought additional details, including when the breach was detected, whether corporate or customer data was stolen, or if a ransom demand had been made. Although Trellix has not yet responded to a follow-up email, the company stated it intends “to share further details as appropriate” once the investigation concludes.

Trellix is not the first cybersecurity company to face a breach this year. In recent weeks, Checkmarx confirmed that the LAPSUS$ hacking group leaked data from its private GitHub repository. Cisco also disclosed that attackers breached its internal development environment and stole source code using credentials compromised in the Trivy supply chain attack. Additionally, HackerOne notified hundreds of employees in March that their personal information was stolen after attackers hacked Navia, one of its U. S. benefits administrators.

(Source: BleepingComputer)

Topics

trellix data breach 95% cybersecurity incident response 90% source code theft 88% corporate breach disclosure 85% forensic investigation 82% law enforcement involvement 78% customer data exposure risk 75% cybersecurity company breaches 72% lapsus$ hacking group 70% supply chain attack 68%