Checkmarx Cyberattack Exposes Sensitive Data on Dark Web
On April 27, 2026, Checkmarx, a prominent cybersecurity firm, revealed that sensitive data from its GitHub repository has surfaced on the dark web. This incident is linked to a supply chain attack that occurred on March 23, where a cybercriminal group known as LAPSUS$ claimed responsibility for breaching Checkmarx’s systems.
The published data includes source code, employee databases, API keys, and database credentials. Fortunately, Checkmarx confirmed that customer data is not stored in the affected repository, but they are continuing their investigation to assess the full extent of the breach.
To protect against potential risks, Checkmarx has secured the compromised repository and is closely monitoring the situation. They have pledged to notify customers if any personal information is found to be involved.
Risk Level: High
Organizations should remain vigilant and implement robust security measures to safeguard sensitive information from similar attacks.
Source: View Original Report
