Trellix Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Trellix
Active investigation Data breach · Cybersecurity Notices mailed Aug 28, 2026

Received an August 2026 breach notice from Trellix?

Dapeer Law, P.A. is investigating a potential class action against Musarubra US LLC d/b/a Trellix, the Milpitas, California cybersecurity company formed from the merger of McAfee Enterprise and FireEye, on behalf of individuals whose Social Security numbers may have been exposed in the security incident disclosed in the notice letters Trellix began mailing in August 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
Not disclosed
Trellix has not stated when the incident occurred
Notification delay
Not disclosed
No discovery date stated, notices August 2026
Credit monitoring
24 months
Through IDX, activate by November 28, 2026
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Trellix dated August 2026.
  • Your letter offered enrollment in two years of complimentary identity and credit monitoring through IDX, with an activation code and a November 28, 2026 enrollment deadline.
  • You had personal information, including your Social Security number, held by Trellix or by its predecessor businesses McAfee Enterprise or FireEye, whether as an employee, a contractor, or a customer contact.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Musarubra US LLC, which does business as Trellix, disclosed a security incident involving personal information in a notice filed with the Massachusetts Attorney General under the Commonwealth's breach statute (MGL c. 93H). The notice letter, signed by Trellix Chief Privacy Officer Brian Gin and dated August 28, 2026, tells recipients that the company is writing "to inform you about a recent incident involving certain personal information relating to you." Trellix identifies itself in the letter as the successor to McAfee Enterprise and FireEye. The filing reports one affected Massachusetts resident.

The notice states that an unauthorized party had access to the recipient's Social Security number. Trellix says it has not detected any misuse of the information to date, and the company states that it regrets the incident occurred and takes the security of personal information seriously. Trellix is offering affected individuals two years of complimentary identity and credit monitoring through IDX, which includes credit monitoring, fraud consultation, and identity restoration support. Enrollment must be completed by November 28, 2026 using the activation code printed in the individual letter. The letter also advises recipients to review account statements and credit reports and to report suspicious activity to their financial institutions, the Federal Trade Commission, or law enforcement.

The public filing does not state when the incident occurred, when Trellix discovered it, how the unauthorized access happened, or how many people were notified nationwide. It also does not explain the gap between the incident and the August 2026 notice letters. Those unanswered questions are central to our investigation, along with whether a cybersecurity vendor that sells extended detection and response products to enterprises maintained reasonable safeguards over the Social Security numbers in its own systems. Because a Social Security number cannot be changed on request, exposure of that data element carries a risk of identity theft and fraudulent account openings that can persist for years after the notice letter arrives.

Massachusetts Attorney General Social Security Numbers Cybersecurity Vendor Breach IDX Identity Monitoring McAfee Enterprise FireEye Incident Date Not Disclosed
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Trellix notice letter. The letter contains your IDX activation code and documents that your Social Security number was involved in the incident, which is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free two-year IDX identity and credit monitoring

Enroll in the IDX identity and credit monitoring offered in your letter before the November 28, 2026 deadline, using the unique activation code Trellix provided. Enrollment is available at app.idx.us or by calling 1-833-788-9712. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because a Social Security number was involved, also place a free security freeze with Equifax, Experian, and TransUnion, order your free annual credit reports, and consider requesting an Identity Protection PIN from the IRS to guard against fraudulent tax filings.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your Trellix notice, explain your options, and advise whether you may be eligible to pursue claims under Massachusetts data breach law (MGL c. 93H) or other legal theories.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

Not disclosed Passed
Unauthorized party gains access to personal information held by Trellix
Not disclosed Passed
Trellix discovers the incident and begins its review
August 28, 2026 Passed
Notice letters mailed, security breach notice filed with the Massachusetts Attorney General
November 28, 2026 Active
Deadline to activate the complimentary IDX identity and credit monitoring
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, fraudulent accounts or loans opened in your name, fraudulent tax filings, credit freeze and restoration costs, and the time you spent responding to the incident, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Trellix to implement stronger safeguards over the Social Security numbers and other personal information it holds, including data minimization, encryption at rest, and prompt notification of affected individuals in the event of a future incident.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Trellix. What should I do? +

Keep your Trellix notice letter and the IDX activation code it contains, enroll in the two years of complimentary identity and credit monitoring before the November 28, 2026 deadline, place a free security freeze with Equifax, Experian, and TransUnion, order your free annual credit reports, watch your financial statements for unfamiliar activity, consider requesting an Identity Protection PIN from the IRS, document any time or money you spend responding to the incident, and consider speaking with a data breach attorney. If you experience identity theft, report it to the FTC at ftc.gov/idtheft or (877) 438-4338 and file a police report, keeping a copy for your records.

Am I eligible to join a class action against Trellix? +

Individuals who received a Trellix notice letter dated August 2026 are the most direct candidates. Eligibility for any legal claim will also depend on your state of residence, the categories of your information that were involved, and any documented losses or out-of-pocket expenses. Because the notice reports that a Social Security number was accessed, recipients may have stronger claims than in incidents limited to contact information. A free case review can help you understand your options.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notice filed with the Massachusetts Attorney General, an unauthorized party gained access to the affected individual's Social Security number. The filing does not identify any additional categories of information, and it does not state how the access occurred. Your individual letter is the most reliable source for exactly what was involved in your case, so we recommend reviewing it carefully and saving a copy.

Did Trellix offer free credit monitoring? +

Yes. Trellix is offering two years of complimentary identity and credit monitoring through IDX, which the company says includes credit monitoring, fraud consultation, and identity restoration support. Enrollment requires the unique activation code printed in your letter and must be completed by November 28, 2026, either at app.idx.us or by calling 1-833-788-9712. Enrolling does not waive your right to pursue legal action.

How many people were affected by the Trellix breach? +

The notice filed with the Massachusetts Attorney General reports one affected Massachusetts resident. That figure covers Massachusetts only. Trellix has not publicly disclosed how many people were notified nationwide, and filings in other states, if any, could raise the total. This page will be updated if additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Trellix filed the security breach notice with the Massachusetts Attorney General, and it can be downloaded from the mass.gov link in the Sources & References section below. If you cannot locate your individual letter, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Musarubra US LLC d/b/a Trellix, IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on August 28, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

McDermott Will & Schulte Data Breach Lawsuit Investigation

Next
Next

Primary Jane Data Breach Lawsuit Investigation