Cyber Security News

Check Point Acknowledges Data Breach, Claims Information is ‘Old

Check Point Software Technologies has confirmed a data breach following claims by threat actor CoreInjection on March 30th, 2025, but insists the incident is an “old, known and very pinpointed event” from December 2024 that had already been addressed. 

The cybersecurity giant released an official statement on March 31st through their support portal, downplaying the significance of the breach while security researchers raise questions about its true scope.

Breach Details and Company Response

According to Check Point’s security alert, the breach stemmed from “compromised credentials of a portal account with limited access” and affected “3 organizations’ tenants in a portal that does not include customers’ systems, production or security architecture.” 

According to the firm, the exposed data consisted of a list of multiple account names with product names, three customer accounts with contact names, and the emails of certain Check Point employees.

“We believe that at no point was there a security risk to Check Point, its customers or employees,” the company stated in their response to Co-Founder & CTO at Hudson Rock Alon Gal. 

Check Point emphasized that the breach did not match the description detailed in CoreInjection’s dark web forum post, calling it “recycling of old, irrelevant information.”

Alon Gal, who first publicized Check Point’s acknowledgment, highlighted several inconsistencies in the company’s explanation.

“The screenshot they confirm shows 121,120 accounts (18,864 paying), which is far more than ‘3 organizations,’ and suggests admin-level access (edit accounts, reset 2FA), which doesn’t align with their ‘limited access’ claim,” Gal noted in his LinkedIn update.

Further raising concerns, no public report or SEC filing from December 2024 regarding this breach has been identified, despite the Security and Exchange Commission’s requirements for such disclosures. 

The breach comes amid heightened security concerns for Check Point products. In May 2024, the company warned about threat actors targeting Check Point Remote Access VPN devices with insecure password-only authentication. 

Additionally, a serious vulnerability (CVE-2024-24919) discovered in May 2024 allowed attackers to read sensitive information on Check Point Security Gateways, including password hashes for local accounts.

This vulnerability received a high severity CVSS v3 score of 8.6 and was quickly added to the US Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities catalog.

While Check Point maintains the breach is contained and poses “no risk to Check Point customers,” security experts continue to question how the attackers initially gained access, the true extent of compromised data, and why there appears to be no public disclosure from December 2024 when the breach allegedly occurred.

As Gal summarized: “The intrusion method remains unknown; they mention compromised credentials but don’t say how (phishing, reuse, etc.), which is concerning for a cybersecurity firm.”

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago