Cybercrime
,
Fraud Management & Cybercrime
Hackers Claim on BreachForums to Have Stolen ‘Highly Sensitive’ Data

Israeli cybersecurity firm Check Point rejected Monday a hackers’ assertion that the company fell to a cyberattack resulting in “highly sensitive” information offered for sale on an online marketplace for illicit data.
See Also: Top 10 Technical Predictions for 2025
A hacker using the moniker “CoreInjection” posted Sunday onto BreachForums an offer to sell data including internal network maps, user credentials and proprietary source code purportedly stolen from Check Point. The asking price if five Bitcoins, roughly $413,000.
Check Point spokesperson Gil Messing is not impressed. “This is an old, known and very pinpointed event which involved only a few organizations and portals that do not include customers’ systems, production or security architecture,” he said in an email. “We investigated this event months ago and are positive this doesn’t pose any risks or has any security implications to our customers or employees.”
Screenshots apparently taken of a cloud-based security management Check Point Infinity Portal posted by CoreInjection on BreachForums “flatly imply things that just didn’t happen,” he said. One shot suggests the attacker had the ability to reset two factor authentication for company employees.
The screenshots may have been taken from a Check Point system, Messing conceded. But they don’t show “anything but a list of customers names and logos of products they used, not any customers system, production or security architecture.”
The CoreInjection moniker is a recent one, dating back to January on BreachForums. The same user also claims to be selling data stolen from a handful of other Israeli companies, including a “prominent digital screen company” and an “international car company.”
Other users on BreachForums expressed skepticism about CoreInjection’s claims. “This is legit just the standard user interface, nice try OP. Provide some more proof,” one wrote.
Granting more credence to the hacker is Along Gal, co-founder of Israeli cybercrime monitoring firm Hudson Rock. “With high certainty, Check Point Software has been hacked,” he wrote on LinkedIn.
Check Point is just months past its first change of CEO since its inception in 1993. Nadav Zafrir, longtime leader of Israeli cybersecurity incubator Team8, assumed leadership of the firm in December after long-time CEO and co-founder Gil Shwed transitioned to executive chairman of the board (see: Check Point Snags Team8’s Nadav Zafrir to Replace Gil Shwed).
The company announced acquisition of Tel Aviv-area Cyberint Technologies in August in a bid to mitigate risk such as stolen credentials and social media impersonation. “Leaked credentials and fake websites designed for malicious purposes are staggeringly prevalent today, with over 90% of organizations facing these threats,” Cyberint CEO Yochai Corem said at the time.