Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nishanthan
Participant

A phishing email bypassed the Check Point security controls

We are experiencing an issue with Harmony Email security and would like your assistance.

  • On 8th September, a phishing email was successfully blocked by Harmony Email.

  • On 19th September, a similar phishing email from a different sender was delivered to the customer’s mailbox.

  • The phishing email on 19th September was not blocked by Harmony Email and we were unable to find any related logs for this event.

  • Email tracing shows that the message hit the Microsoft external email header policy, but it did not trigger any Check Point policy enforcement.

  • Despite this, the email still reached the customer mailbox.

Concerns / Questions:

  1. Why did Harmony Email fail to block the phishing email on 19th September?

  2. Why are there no Harmony Email logs for this email?

  3. Why was the message processed only under Microsoft’s external header policy and not evaluated by Check Point’s security controls?

3 Replies
G_W_Albrecht
Legend Legend
Legend

Do you have a SR# wuth CP TAC open already to get these questions answered?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
the_rock
Legend
Legend

For something like this, I would definitely open TAC case. In the meantime, are there any relevant logs you can send us?

Andy

0 Kudos
PhoneBoy
Admin
Admin

Specific instances of false positives/false negatives should be addressed via TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events