link Sony announced on Tuesday that hackers broke into the accounts of more than 93,000 customers by trying to log in to Sony using a large list of usernames and passwords. Sony said it believed the intruders collected the log-in credentials from another source, not from Sony’s networks, and were able to gain access to the Sony accounts because customers used the same credentials with their Sony accounts. Phil Reitinger, Sony’s new chief information security officer, made the announcement on the company’s blog. He wrote that intruders tested a “massive set of sign-in IDs and passwords” at web sites for several of its properties — Sony Entertainment Network (SEN), PlayStation Network (PSN) and Sony Online Entertainment (SOE). Most of the log-in credentials failed to gain the intruders access, but about 60,000 credentials matched those use by SEN and PSN users; another 33,000 matched credentials for SOE accounts. “[G]iven that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks,” Reitinger wrote. He noted that a “small fraction” of the accounts showed activity after they were breached, but that the intruders couldn’t access credit card account information. Sony had since locked all of the accounts accessed through the attack until customers can be notified to change their passwords. “We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet,” he wrote. Reitinger’s quick announcement was a departure from the company’s previous handling of a breach it suffered earlier this year, when the company waited a week to tell customers that its PlayStation Network had been hacked, and then was slow to release details. News reports indicate that the newest breach occurred primarily over the weekend between Oct. 7 and 10, just two working days before the company’s announcement. In the previous case, Sony first discovered evidence of the breach on its PlayStation Network last April 20, but waited until the 26th to notify PSN customers. The company said it notified customers the day after forensic investigators told it that the intruders had hacked its network and obtained the personal information of more than 75 million customers. This was followed by another breach at Sony Online Entertainment, which compromised an additional 25 million customers, and still more breaches at Sony Pictures and Sony BMG. The initial intrusion forced Sony to take its PlayStation Network offline for 40 days. The tech giant was subsequently hit with a class-action lawsuit by customers complaining in part that the company failed to adequately secure their data, failed to notify customers of the breach in a timely manner and deprived customers of the use of the network for an extended period of time. Sony has estimated that the breaches last spring would cost it more than $170 million this year, including expenses for shoring up its network against future attacks. The company hired Reitinger last month as part of its efforts to improve the security of its networks in the wake of those earlier breaches. Reitinger has heavyweight credentials in the security community. He was previously Deputy Under Secretary of the National Protection and Programs Directorate and Director of the National Cyber Security Center at the Department of Homeland Security. Before that, he was chief trustworthy infrastructure strategist for Microsoft.
Not really hacked, if you read it Sony believes that the usernames/passwords were not even taken from Sony but from another source, and since people use the same passwords for everything that's how the accounts were compromised...
Agreed with these posts. Kind of sad what the media calls "hacking." And not like this is as hard to research as the Kraken either. Still not good, although not really much to fault Sony on, unlike earlier in the year (unless I'm missing something). No idea what the best practice is for monitoring this type of activity, so maybe they dropped the ball there (e.g., should have only been 10K users before Sony noticed/responded to it), but it sounded OK to me. The response in general seems much better than before as well. I'm going to go back to playing Dark Souls.
That was exactly my thought. I'm glad Sony seems to have learned from their last outage and is actually being forthcoming about details this time instead of hiding behind "all is well" platitudes.
Yeah, the article pretty much makes it sound like these "hackers" got a whole bunch of username/password pairs from somewhere else, and they were checking for people on PSN who were using the same pair. I know that I sometimes use the same username/password when signing up for a service as I do for a different service... this just goes to show that it's a bad idea. So yeah... big whoop. I'm not inclined to blame Sony on this one.