Sony Networks Compromised with Brute-Force Attack

Wednesday, October 12, 2011

Headlines

69dafe8b58066478aea48f3d0f384820

Sony Corporation have yet again been breached, compromising 60,000 PlayStation Network and 33,000 Sony Online Entertainment client accounts.

The source of the attack is unknown, but a report in The Hacker News indicates that the infiltrators used login credentials from an unnamed third-party to gain access to the systems between October 7th and 10th using valid logins.

Sony Corporation had announced in September the appointment of former Department of Homeland Security Deputy Undersecretary Philip Reitinger as the company's first Chief Information Security Officer.

Reitinger has released the following statement via the Sony PlayStation blog:

We want to let you know that we have detected attempts on Sony Entertainment Network, PlayStation Network and Sony Online Entertainment (“Networks”) services to test a massive set of sign-in IDs and passwords against our network database. These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites or other sources. In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks. We have taken steps to mitigate the activity.

Less than one tenth of one percent (0.1%) of our PSN, SEN and SOE audience may have been affected. There were approximately 93,000 accounts globally (PSN/SEN: approximately 60,000 accounts; SOE: approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts. Only a small fraction of these 93,000 accounts showed additional activity prior to being locked. We are currently reviewing those accounts for unauthorized access, and will provide more updates as we have them. Please note, if you have a credit card associated with your account, your credit card number is not at risk. We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet.

As a preventative measure, we are requiring secure password resets for those PSN/SEN accounts that had both a sign-in ID and password match through this attempt. If you are in the small group of PSN/SEN users who may have been affected, you will receive an email from us at the address associated with your account that will prompt you to reset your password.

Similarly, the SOE accounts that were matched have been temporarily turned off. If you are among the small group of affected SOE customers, you will receive an email from us at the address associated with your account that will advise you on next steps in order to validate your account credentials and have your account turned back on.

We want to take this opportunity to remind our consumers about the increasingly common threat of fraudulent activity online, as well as the importance of having a strong password and having a username/password combination that is not associated with other online services or sites. We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account.

The announcement of Reitinger's appointment is the culmination of a heady year for Sony where information security issues are concerned.

The Sony breach saga first began in April when the company announced that the PlayStation network servers had been hacked, exposing the records of more than 70 million customers. During the course of the investigation, Sony discovered that the company's Online Entertainment network had also been compromised, exposing another 25 million customer records.

After that it was all downhill for Sony corporation, with new security breach events being announced every few days. Security experts began to speculate on whether the rash of data loss events at Sony could threaten the long-term health of what has notably been a stable company for decades.

Possibly Related Articles:
11593
Breaches
Passwords Headlines Network Security Third Party Sony hackers breach Brute Force Login Philip Reitinger
Post Rating I Like this!
The views expressed in this post are the opinions of the Infosec Island member that posted this content. Infosec Island is not responsible for the content or messaging of this post.

Unauthorized reproduction of this article (in part or in whole) is prohibited without the express written permission of Infosec Island and the Infosec Island member that posted this content--this includes using our RSS feed for any purpose other than personal use.

Most Liked