Trellix source code breach claimed by RansomHouse hackers
Check for signs of source code leakage and review access controls.
Check for signs of source code leakage and review access controls.
Summary
Trellix, a global cybersecurity firm with 53,000 customers in 185 countries, confirmed unauthorized access to a portion of its source code repository on May 1.
The breach was claimed by the RansomHouse threat group, which released screenshots of the appliance management system on April 17 and later posted images of the source code repository. Trellix stated that no evidence was found that its source code release or distribution process was affected or that the code had been exploited. RansomHouse added encryption utilities Mario and MrAgent to its toolkit, and the group had previously targeted the Japanese e‑commerce giant Askul, stealing 740,000 customer records. Instructure had earlier disclosed a 280 million‑record breach tied to its Canvas LMS. The investigation is ongoing and Trellix has not yet released further details. The incident highlights the importance of monitoring access to source code repositories and ensuring robust authentication controls.
Key changes
- Trellix confirmed unauthorized access to its source code repository on May 1.
- RansomHouse claimed intrusion on April 17 and released screenshots of the appliance management system.
- Trellix stated no evidence of source code distribution or exploitation.
- RansomHouse added encryption utilities Mario and MrAgent to its toolkit.
- Instructure had previously disclosed a 280 million‑record breach tied to its Canvas LMS.
- The investigation is ongoing and no further details have been released.
- Trellix serves 53,000 customers in 185 countries and employs 3,500 staff.