INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trellix Discloses Data Breach After Source Code Repository Hack Exploited

| 2026-05-04 16:25 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On 2026-05-04, cybersecurity firm Trellix disclosed a data breach after attackers gained access to "a portion" of its source code repository. The LAPSUS$ hacking group is believed to be behind the incident, according to Checkmarx and Cisco's revelations about their own breaches. As a result, over 50,000 business and government customers worldwide are affected by this attack, with more than 200 million endpoints protected. Trellix has not found evidence that the threat actors have exploited or altered the source code they accessed, but is investigating with outside forensic experts and notifying law enforcement.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
Global Scope
Incident Timeline
‎October 2021
Trellix disclosed a data breach after its source code repository was hacked, affecting over 50,000 business and government customers worldwide.
victims 50,000 customers
infrastructure 200 endpoints
‎2026/05/04
Threat actors from the LAPSUS$ hacking group gained unauthorized access to Trellix's source code repository.
threat_actor LAPSUS$
Tactical Metrics
Metrics
victims
50,000
Customers
Metrics
infrastructure
200,000,000
Endpoints
Intelligence Sources
BleepingComputer 2026-05-04