Trellix Confirms Source Code Breach, Joins Growing List of Hacked Cybersecurity Firms
Cybersecurity firm **Trellix** has disclosed a data breach involving unauthorized access to a portion of its source code repository. The company is investigating the incident with the help of forensic experts and has notified law enforcement.

**Trellix**, a major player in the cybersecurity landscape, has revealed a security incident impacting its source code. This breach adds **Trellix** to the growing list of cybersecurity companies targeted by malicious actors this year.
### Breach Details
According to an official statement released by **Trellix**, the company detected unauthorized access to a portion of its source code repository. Upon discovery, **Trellix** initiated an investigation, bringing in external forensic experts to assist.
The company stated:
> "Trellix recently identified unauthorized access to a portion of our source code repository. Upon learning of this matter, we immediately began working with leading forensic experts to resolve it."
**Trellix** has also engaged law enforcement. As of now, the investigation has not revealed any evidence that the accessed source code has been exploited or that the company's source code release or distribution processes were affected.
A **Trellix** spokesperson reiterated the official statement when asked for further details, including the detection date, potential theft of corporate or customer data, and any ransom demands.
### Investigation Ongoing
While **Trellix** has not yet responded to requests for additional information, the company has indicated that it intends to share more details as the investigation progresses.
### A Troubling Trend
**Trellix** is not the first cybersecurity firm to suffer a breach this year. **Checkmarx** recently confirmed that the **LAPSUS$** hacking group leaked data stolen from its private **GitHub** repository. **Cisco** also disclosed a breach of its internal development environment, resulting in the theft of source code using compromised credentials related to the **Trivy** supply chain attack.
Furthermore, **HackerOne** notified employees of a data breach affecting their personal information after attackers compromised **Navia**, one of its benefits administrators.
