INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trellix Discloses Data Breach After Source Code Repository Hack Exploited
| 2026-05-04 16:25 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On 2026-05-04, cybersecurity firm Trellix disclosed a data breach after attackers gained access to "a portion" of its source code repository. The LAPSUS$ hacking group is believed to be behind the incident, according to Checkmarx and Cisco's revelations about their own breaches. As a result, over 50,000 business and government customers worldwide are affected by this attack, with more than 200 million endpoints protected. Trellix has not found evidence that the threat actors have exploited or altered the source code they accessed, but is investigating with outside forensic experts and notifying law enforcement.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
Global Scope
Incident Timeline
October 2021
Trellix disclosed a data breach after its source code repository was hacked, affecting over 50,000 business and government customers worldwide.
Click on any entity below to view its context and source!
victims
50,000 customers
It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
infrastructure
200 endpoints
It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
2026/05/04
Threat actors from the LAPSUS$ hacking group gained unauthorized access to Trellix's source code repository.
Click on any entity below to view its context and source!
threat_actor
LAPSUS$
Application security company Checkmarx confirmed last week that the
LAPSUS$ hacking group leaked data
stolen from its private GitHub repository, while Cisco revealed last month that hackers
breached its internal development environment
and stol…
Tactical Metrics
Metrics
victims
50,000
Customers
Click for context!
It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
Metrics
infrastructure
200,000,000
Endpoints
It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
Intelligence Sources
BleepingComputer
2026-05-04
Trellix discloses data breach after source code repository hack
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:39
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
organisation
Identified Entity
Checkmarx
entity
4x
timeline
Temporal Reference
2026/04/27
date
Contextual Telemetry
Context Block
5 METRICS
tactic
Cyber Operation Type
Data Breach
tactic
threat actor
APT Group
LAPSUS$
actor
general metric
May
14
may
victims
Customers
50,000
customers
infrastructure
Endpoints
200,000,000
endpoints
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.