Ransomware victim disclosure
← All victimsTrellix (McAfee & FireEye)
Claimed by Ransomhouse · listed 13 days ago
Status timeline
- Listed
May 7, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- United States
- Sector
- cybersecurity
- Listed on leak site
- May 7, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileTrellix is a global cybersecurity company formed in October 2021 from the merger of McAfee Enterprise and FireEye. It provides an open and native extended detection and response (XDR) platform serving over 40,000–50,000 business and government customers worldwide and protecting more than 200 million endpoints. The company is headquartered in the United States and reports annual revenue of approximately $1.5–2 billion.
- Industry
- Cybersecurity – Extended Detection & Response (XDR)
- Employees
- 5000
- Founded
- 2021
Attack summary
Severity: critical — Trellix is a major cybersecurity vendor serving 40,000–50,000 business and government clients and 200 million+ endpoints; encryption and threatened publication of data from such a target poses critical risk to regulated government/enterprise customer data, sensitive threat-intelligence holdings, and national-security-adjacent operations.RansomHouse claims to have encrypted Trellix's systems on 17 April 2026; the post is currently in an 'EVIDENCE' / 'NOT YET published' state, indicating data has not yet been publicly released but is being held as leverage. No explicit exfiltration volume is listed for this specific victim in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Encrypted internal systems
- Potential business and government customer data
- Endpoint telemetry and security intelligence data
- Corporate operational data
What the group claims
Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
