Ransomware victim disclosure
← All victimsTrellix
listed as Cybersecurity Vendor · Claimed by ransomhouse · listed 23 days ago
Status timeline
- Listed
Apr 28, 2026
- Data leaked
At a glance
- Group
- ransomhouse
- Status
- Data leaked
- Sector
- Technology
- Listed on leak site
- Apr 28, 2026
About the victim
AI dossier — public-source company profileTrellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides an open and native extended detection and response (XDR) platform serving over 40,000–50,000 business and government customers worldwide and protecting more than 200 million endpoints. The company generates estimated annual revenue of $1.5–2 billion.
- Industry
- Cybersecurity / Extended Detection & Response (XDR)
- Employees
- 5000
- Founded
- 2021
Attack summary
Severity: high — The victim is a major cybersecurity vendor with government and enterprise customers globally; confirmed encryption of a $1.5–2B revenue company in the security sector represents significant operational and reputational impact. Data publication is threatened but not yet released, so critical-tier regulated-data exfiltration at scale is not yet confirmed.RansomHouse claims to have encrypted Trellix systems on or around 17 April 2026; the post indicates data publication is 'NOT YET' but lists the action as 'Encrypted' with evidence held pending victim response.
Data the group says was taken
AI dossier — extracted from the leak post- Encrypted internal systems
- Evidence files (unpublished)
Original description
AI-summarised, not from the leak postN/A "Cybersecurity Vendor" is a generic descriptive term rather than the name of a specific company. Without a precise company name, it is not possible to provide accurate and reliable threat intelligence information. Please provide the exact registered company name for a proper assessment.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"438632"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 23 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
