Cybersecurity firm Trellix said it is investigating a data breach after attackers gained unauthorized access to a portion of its source code repository, with no evidence so far that the code was exploited or altered.
KEY FACTS
- Incident Unauthorized access to part of the source code repository.
- Response The company brought in outside forensic experts and notified law enforcement.
- Impact Trellix said it has found no evidence of code exploitation or changes.
- Status The investigation is ongoing, with more details expected later.
The disclosure said the company identified the issue and began working with forensic experts immediately. It also said its source code release and distribution process was not affected.
Trellix did not say when the breach was detected or whether any corporate or customer data was taken. A spokesperson gave the same statement when asked for those details, including whether the attackers had made a ransom demand.
The company said it plans to share more information as appropriate after the investigation ends. Trellix is a global cybersecurity company formed from the 2021 merger of McAfee Enterprise and FireEye, and it says it serves more than 50,000 business and government customers.
WHY IT MATTERS
Source code access can raise concern because it may help attackers understand how software works, even when there is no confirmed alteration or theft. The case adds to a recent series of breaches affecting cybersecurity vendors, including disclosures by Checkmarx, Cisco and HackerOne.

