ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Check Point denies severity of alleged data breach amid hacker claims

A cybercriminal using the alias “CoreInjection” has claimed to possess a trove of “highly sensitive” data from Check Point, a leading American-Israeli cybersecurity firm. The alleged breach was advertised on a cybercrime forum, with CoreInjection claiming access to internal network maps, architectural diagrams, user credentials, proprietary source code, and employee contact information.


Despite these claims, Check Point has strongly refuted the severity of the incident, dismissing it as an exaggeration and labeling the supposed leak as recycled, outdated information. The company maintains that no customer systems, production environments, or security architectures were compromised.


According to screenshots shared by CoreInjection, the hacker purportedly accessed Check Point’s Infinity security management portal, even showing themselves modifying users’ two-factor authentication settings. However, Check Point insists that the event in question was an isolated, previously addressed incident affecting only a few organizations.


“This is an old, known, and very pinpointed event which involved only a few organizations and a portal that does not include customers’ systems, production, or security architecture,” the company stated. “This was handled months ago and did not include the description detailed on the dark forum message. These organizations were updated and handled at that time, and this is not more than the regular recycling of old information.”


Further clarifying on its support page, Check Point revealed that the breach, which occurred in December 2024, was the result of compromised credentials granting limited access to a portal account. The impacted data reportedly included a list of account names with product names, three customer accounts with contact names, and a list of Check Point employees’ emails. The company assured that internal security measures were in place and that the hacker’s claims about the extent of the breach were misleading.


Alon Gal, co-founder and CTO of cybersecurity firm Hudson Rock, was among the industry experts who initially raised concerns over the hacker’s allegations. He noted that the screenshots appeared “highly convincing,” citing CoreInjection’s track record of legitimate leaks and prior attacks on Israeli companies. However, after Check Point’s response, Gal acknowledged that the scope of the breach might be more limited than initially feared.


“One of the screenshots appears to show an admin panel listing more than 120,000 accounts, with 18,824 of them appearing to be active and paying,” Gal noted. “I want to make sure people are not freaking out and can differentiate between what the hacker is claiming and what they have actually shown. This could end with a limited impact that does not affect customers or Check Point’s intellectual property.”


Despite the concerns raised, Check Point has declined to provide further comments on the matter, maintaining its stance that there was no significant security risk to its customers or infrastructure. 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543