Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
R
OrganisationUS

Rubrik

A cloud data management and backup vendor whose infrastructure was visible in alleged Trellix internal screenshots posted by RansomHouse in May 2026.

Last refreshed: 20 May 2026 · Appears in 1 active topic

Key Question

If RansomHouse accessed Trellix's Rubrik backup console, could Trellix still recover without paying?

Timeline for Rubrik

View full timeline →
Common Questions
What is Rubrik and what does it do?
Rubrik is a US enterprise data-management and backup security vendor, founded in 2014 and NYSE-listed since April 2024. It provides ransomware recovery and cloud data management, helping organisations restore encrypted data without paying ransoms.
Was Rubrik involved in the Trellix ransomware breach?
Rubrik itself was not confirmed as a victim. RansomHouse's May 2026 leak of alleged internal Trellix screenshots reportedly showed access to Trellix's Rubrik backup infrastructure, raising questions about Trellix's recovery capability, but the authenticity and full scope of the screenshots had not been confirmed.Source: ThaiCERT

Background

Rubrik is a US enterprise data-management and backup vendor headquartered in Palo Alto, California, founded in 2014. The company's platform focuses on cloud data management, ransomware recovery, and data security posture, positioning itself as a resilience layer that enables organisations to recover encrypted data without paying ransoms. Rubrik listed on the New York Stock Exchange in April 2024 and had a market capitalisation of approximately $7 billion post-IPO. Its customers span large enterprises, financial institutions, and government agencies across North America, Europe, and Asia-Pacific.

Rubrik's name surfaced in the May 2026 Trellix breach when RansomHouse posted alleged internal screenshots from inside Trellix's systems, reportedly showing access to Trellix's Rubrik backup infrastructure. The screenshots, if authentic, would indicate that RansomHouse had visibility into Trellix's backup estate, a critical detail because backup infrastructure is the primary recovery mechanism against ransomware encryption. Access to a victim's backup management console does not automatically mean the backups themselves were compromised or deleted, but it raises the question of whether Trellix's recovery capability was impaired.

The Rubrik mention in the Trellix screenshots is significant for Rubrik's own commercial position: the company sells ransomware resilience and backup security as core product features. A leak that visually implies access to a Rubrik estate inside a cybersecurity vendor creates an uncomfortable proof point. Rubrik has not issued a public statement on the Trellix screenshots.

Source Material