CheckMarx admits it was hit by major cyberattack that saw data leaked onto Dark Web
CheckMarx has confirmed it suffered a data breach following a supply chain attack on March 23, 2026, which led to stolen data being leaked on the dark web. The compromised data originated from its GitHub repository and may include source code and sensitive credentials. Investigations are ongoing, and the company has restricted access to the affected systems while assessing the full impact.
- ▪CheckMarx confirmed a data breach after its data appeared on the dark web in April 2026.
- ▪The breach stemmed from a supply chain attack on Trivy, which allowed threat actors to access CheckMarx's GitHub repository.
- ▪Stolen data potentially includes source code, API keys, database credentials, and employee information.
- ▪The hacking group Lapsus$ claimed responsibility for exfiltrating sensitive data and published it on their leak site.
- ▪CheckMarx has blocked access to the compromised repository and is investigating whether user data was impacted.
TechRadar publishes from United Kingdom and files mainly under tech. We currently carry 1,334 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | TechRadar |
| Canonical URL | https://www.techradar.com/pro/security/checkmarx-admits-it-was-hit-by-major-cyberattack-that-saw-data-leaked-onto-dark-web |
| Publication time | Tue, 28 Apr 2026 13:37:33 +0000 |
| Retrieval time | 2026-04-28T13:44:31.943Z |
| Last seen | 2026-04-28T13:44:31.943Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | Ugfc_GHBH7MH |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Pro Security CheckMarx admits it was hit by major cyberattack that saw data leaked onto Dark Web News By Sead Fadilpašić published 28 April 2026 March 2026 attack did result in CheckMarx data theft When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. OpenVPN-protokollet - därför är det så bra (Image credit: Shutterstock) Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter CheckMarx confirms breach tied to a recent supply chain attackStolen data originated from its GitHub repository, with investigations still ongoingThreat actors later claimed to have exfiltrated source code and sensitive…
Excerpt limited to ~120 words for fair-use compliance. The full article is at TechRadar.