Trellix on the Collapse of Digital Trust in 2026
News | 18.09.2026
Adversaries in 2026 are no longer breaking into corporate networks — they are simply logging in. By weaponizing trusted third-party providers, SaaS platforms and stolen identities, attackers have industrialized deception at machine speed. Trellix calls this shift the collapse of digital trust, and it directly impacts every CISO, CIO and procurement leader who relies on external providers to run the business.
What was announced
Trellix published the first blog in a new series analyzing the 2026 threat landscape. The report documents how adversaries pivot from breaching a single vendor to compromising entire industries, using legitimate infrastructure to bypass reputation-based defenses.
Key incidents highlighted by Trellix include:
- GrayCharlie campaign: Between November 2025 and February 2026, at least 15 U.S. law firms were compromised through a shared IT service provider, SMB Team. Attackers used fake browser update pop-ups to deliver NetSupport RAT and Stealc infostealer via MivoCloud and HZ Hosting Ltd infrastructure.
- Dutch telecommunications breach: In February 2026, ShinyHunters exposed passports and bank account numbers for more than 6 million accounts, fueling future synthetic identity fraud.
- Atlassian Jira Cloud abuse: In January 2026, threat actors used the legitimate Jira Cloud domain to send spear-phishing emails targeting government and corporate entities across six language groups.
- ShinyHunters MFA bypass: A global consumer social platform lost 10 million records, while a commercial market intelligence provider lost 2 million records after vishing attacks compromised administrative SSO credentials.
Why this matters
For CISOs, CIOs, IT directors and procurement leaders, the message from Trellix is direct: compliance is not security. Traditional indicators of compromise are becoming obsolete when adversaries operate from trusted domains and legitimate SaaS platforms. Vendor concentration risk turns a single weak provider into an industry-wide breach vector, and static personal data leaks fuel years of downstream fraud.
Enterprise defense must move from static, perimeter-based posture to continuous readiness anchored in identity integrity and behavioral verification.
The perimeter has not just moved — it has vanished. It is time to log in to a new reality
Technical details
- Vendor concentration audits: Identify third-party providers with high-level access and mandate phishing-resistant MFA for every login.
- Behavioral biometrics: Verify users through keystroke dynamics, mouse movement patterns and transaction rhythms, not only static credentials.
- SaaS notification hardening: Tighten controls on third-party cloud-generated email and remove sole-link authorization from high-value workflows.
- Just-in-time access: Replace persistent admin grants with privileges valid only for a specific task and duration.
- Identity-first architecture: Prioritize SSO protection, ITDR, and continuous verification over perimeter controls.
Softprom and Trellix
Softprom is the official distributor of Trellix. Our team helps enterprises design identity-first defense strategies, deploy XDR and ITDR capabilities, and address vendor concentration risk with continuous verification models.
Learn more about solutions and request a consultation from Trellix.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.