Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
20MAY

RansomHouse posts Trellix internal screenshots as extortion leverage

3 min read
09:58UTC

RansomHouse posted alleged internal system screenshots from inside Trellix to its leak site on or around 11 May, 24 days after the 17 April intrusion and 21 days after Trellix's 8 May self-disclosure, withholding the full source-code dump as extortion leverage.

TechnologyDeveloping
Key takeaway

Trellix's 45-day disclosure-to-extortion timeline is the data point the UK reporting bill will be argued against.

RansomHouse, the extortion crew, posted alleged internal system screenshots from inside Trellix to its leak site on or around Monday 11 May 2026 1. The screenshots reportedly show access to Trellix's appliance management console, its VMware estate, Rubrik backup infrastructure, and Dell EMC storage. Trellix, the US cybersecurity vendor formed from the McAfee Enterprise and FireEye merger, confirmed unauthorised repository access on 8 May but stated there was no evidence the source code had been altered or weaponised. The full source-code dump has not been published; RansomHouse is holding it as leverage.

RansomHouse says the original compromise occurred on 17 April 2026. Trellix self-disclosed on 8 May, a 21-day intrusion-to-disclosure gap . The leak-site posting on 11 May added a further three days before the first public extortion artefact landed, totalling roughly 24 days from initial access to leak-site publication. RansomHouse's incremental disclosure tactic, screenshots first and dump later, is by now a standard pattern for the operator.

The UK Cyber Security and Resilience Bill, at Report Stage in Parliament since 2 March 2026, proposes a 24-hour initial-notification window and a 72-hour full-report requirement . Trellix's 21-day gap is well beyond the bill's proposed initial threshold. The case is now a worked example for parliamentary debate: a US-headquartered cybersecurity vendor with UK customers, an intrusion-to-disclosure interval running into weeks, and an attacker-controlled second disclosure window opened beyond it. The Capita ICO precedent has already shown the regulator willing to treat NCSC guidance as enforceable; the bill would put a statutory clock on top of that.

Deep Analysis

In plain English

Trellix sells cybersecurity software used by large organisations to detect and respond to attacks. The group RansomHouse broke into Trellix on 17 April 2026, and rather than releasing all stolen data immediately, posted screenshots of Trellix's internal systems on 11 May to pressure the company into paying. Trellix confirmed the break-in but claimed the hackers had not altered its software.

First Reported In

Update #4 · AI joins the breach column on both sides

ThaiCERT· 20 May 2026
Read original
Causes and effects
This Event
RansomHouse posts Trellix internal screenshots as extortion leverage
A worked example of the disclosure-gap problem the UK Cyber Security and Resilience Bill is trying to close: 45 days total from initial access to first public extortion artefact, with the bill's proposed 24-hour reporting clause currently before Parliament.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.