> Source: [sk183307](https://support.checkpoint.com/results/sk/sk183307)

# sk183307 - Check Point response to the BreachForum post on 30 March 2025

| Property | Value |
|----------|-------|
| Solution ID | sk183307 |
| Date Created | 2025-03-31 |
| Last Modified | 2025-04-03 |
| Technical Level | General |
| Products | Other |
| Versions | Not Version-Specific |

## Solution

<br />

On**March 30th, 2025**, a BreachForum post offered to sell alleged hacked Check Point data. This relates to an old, known, and pinpointed event from several months ago, which we addressed at the time and had no security implications.

This event included 3 organizations' tenants in a portal that does not include customers' systems, production or security architecture. The event did not include the description detailed in the post.

The event was addressed immediately and thoroughly investigated. These organizations were updated and handled at the time, and this post is recycling this old, irrelevant information.

We are sharing here some additional context which helps scope this event:

* The post relates to an event from December 2024, stems from compromised credentials of a portal account with limited access.

* It was limited to a list of several account names with product names, 3 customers' accounts with contact names, and a list of some Check Point employees' emails. As said, this does not include customers' systems, production, or security architecture.

* The content of the post falsely implies exaggerated claims which never happened. The portal has different internal mitigations.

* Our thorough investigation concluded that there is no risk to Check Point customers and there are no security implications.

**Update on April 1st, 2025**

A recent post on BreachForum dated April 1st, 2025, highlights our previous statement (above) regarding the outright false and deliberately deceptive information shared by this actor, and how this actor recycles old, irrelevant information and takes a known event from the past and falsely implies a breach.

* None of the information in the post was leaked from Check Point. All of it was probably collected over time by infostealers on individuals' devices - just like on any attempt to steal accounts' credentials.
* Moreover, this portal implements strong mitigations that prevent access without multi-factor authentication or the leveraging of stolen credentials, which we continuously monitor across various threat actor forums. In simple terms, this data cannot be used for access.
* This data has been known to us for a long time, investigated, and found irrelevant due to these mitigations.
* The post also includes a screenshot of an email allegedly from Check Point, but anyone can see this is a fake email, from a non-existent Check Point account, describing a breach which never occurred, violating privacy practices, using emails taken from the email bulk described above, while even misspelling Check Point's name.

While threat actors continue to spread misinformation, we will persist in safeguarding our customers from bad actors.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
