Ransomware victim disclosure
← All victimsTrellix
Claimed by Ransomhouse · listed 13 days ago
Status timeline
- Listed
May 8, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- United States
- Sector
- cybersecurity
- Listed on leak site
- May 8, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileTrellix is a global cybersecurity company formed in October 2021 from the merger of McAfee Enterprise and FireEye, formally launched in 2022. It provides an open and native extended detection and response (XDR) platform serving over 40,000–50,000 business and government customers worldwide and protecting more than 200 million endpoints. The company is headquartered in the United States and generates estimated annual revenue of $1.5–2 billion.
- Industry
- Cybersecurity — Extended Detection & Response (XDR)
- Address
- 1204 Carnegie Street, Rolling Meadows, IL 60008, United States
- Employees
- 5000
- Founded
- 2022
Attack summary
Severity: critical — Trellix is a major cybersecurity vendor protecting 200M+ endpoints and 40,000+ government and enterprise customers; 743 GB of exfiltrated data from such an entity likely contains sensitive government, enterprise, and security-intelligence data at scale, and encryption of a critical cybersecurity provider constitutes significant operational disruption to downstream protected entities.RansomHouse claims to have encrypted Trellix systems on 17 April 2026 and lists the case status as 'EVIDENCE' with data not yet published, suggesting exfiltration of approximately 743 GB of data is threatened pending ransom payment of $740.
Data the group says was taken
AI dossier — extracted from the leak post- Encrypted corporate files
- 743 GB of exfiltrated data (threatened publication)
- Business and government customer data (potential)
- Internal cybersecurity operational data (potential)
What the group claims
Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436317"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
