www.securityweek.com 5/8/2026, 8:10:43 AM · via preferred

RansomHouse claims Trellix breach, posts service screenshots

RansomHouse claims Trellix breach, posts service screenshots

RansomHouse claims it breached Trellix, leaks data on Tor

On 8 May 2026, RansomHouse claimed responsibility for the Trellix breach, adding the security firm to its Tor data leak site and publishing screenshots they allegedly show access to internal Trellix systems. The article notes that in early May Trellix disclosed unauthorized access to part of its source code repository and that the company began an…

First seen 2026-05-02T06:58:41.927Z · Last seen 2026-05-08T21:19:39.364Z

CyberSIXT Evidence Panel
Threat Actor

RANSOMHOUSE has taken credit for the recent attack on the Trellix cybersecurity firm, publishing screenshots to demonstrate access to internal Trellix services. The Trellix source code repository breach was disclosed by the company on its website, with Trellix saying there is no evidence that its source code release or distribution process was affected or exploited.

RansomHouse named Trellix on its leak site on Thursday, but has not stated how much data was stolen, and officials have not commented on the data type claimed. SecurityWeek reported that the timing of the attack suggested a potential connection to a recent supply chain attack linked to TeamPCP and Lapsus$, though the connection has not been confirmed.

RansomHouse, which emerged in 2022 as a ransomware-as-a-service provider, is listed on its Tor-based leak site as having more than 170 victims. according to SecurityWeek

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline