Something went wrong. Try again later

Giant Bomb News

170 Comments

PSN Hacked: What Sony's Security Breach Means for You (And What Comes Next)

The possible fallout for Sony, PSN and data pulled from 77 million accounts on PSN.

Sony confirmed many of our worst fears yesterday afternoon, revealing an outside party had accessed PlayStation Network and gained access to vital personal information abouts its 77 million registered accounts. The company has not been able to verify whether credit card information was available to the currently unknown hacker or hacker group, but it (still) cannot not rule out the possibility of it, either. 

The news understandably panicked many, as evidenced by the number of Giant Bomb users who've confessed to considering canceling their cards. I've spent the last day speaking with experts to gain a better sense of what happened, what might happen with the data and any legal fallout from this ordeal. 

Rumor quickly spread yesterday that banks may have been aware of the leak ahead of time. I contacted Bank of America and Chase, two financial institutions that I actually have accounts at, and both denied this. Pushing back on rumors Sony waited days to inform PSN users their data was accessed, senior director of corporate communications and social media Patrick Seybold better clarified Sony's timeline.

"There’s a difference in timing between when we identified there was an intrusion and when we learned of consumers’ data being compromised," said Seybold. "We learned there was an intrusion April 19th and subsequently shut the services down. We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident. It was necessary to conduct several days of forensic analysis, and it took our experts until yesterday to understand the scope of the breach. We then shared that information with our consumers and announced it publicly this afternoon."   

The PlayStation Store home page. You can't access this bad boy right now.
The PlayStation Store home page. You can't access this bad boy right now.
The timeline has been a point of contention for PSN users, though understandably so. The matter is rather complicated, as the requirements for disclosing data breaches like this legally vary from state-to-state. 

== TEASER =="There are a number of legal implications, depending on the point-of-view," said Andrew Ehmke, an attorney at Texas-based Haynes and Boone, LLP. "Many states have laws that require notification to individuals if the individuals' information is hacked (and each state's law is slightly different about the how, when, and what of the notification, as well as the effect for failure to notify). Another place that people may look are the terms of use and privacy policy and whether those were complied with by Sony. The true legal implications won't be known until more facts come out about what actually happened."

If you're not interested in waiting, you can actually pull up your own state's laws concerning breach disclosure through the National Conference of State Legistures website. For example, in California:

"Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system."

PlayStation Network icon
PlayStation Network icon
The laws allow companies to hold back on disclosing the breach, if criminal activity could be involved. Given Sony has been under siege from hacking groups, including Anonymous, there would be reason for Sony to adhere to this. That's not to say Sony did, only that there's the option, at least under California law.

"The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made after the law enforcement agency determines that it will not compromise the investigation."

And while most folks aren't really concerned about what Sony's legal response is, it's certainly a factor. It was hacked, and whatever security issues PSN may or may not have had, that's not something it'll let pass.

"From Sony's perspective," added Ehmke, "there are laws against attacking computer systems and taking information, and Sony could take action against the people who did the attack under those laws. Sony may also be able to take action for violation of the terms of use."

The initial legal shot was fired today, with Krisopher Johns of Alabama filing the first class action lawsuit on behalf of PSN users in the US District Court for the North District of California. Part of his argument: 

"This action is brought on behalf of plaintiff individually, as representative of the common or general interest and as class representatives for all others similarly situated nationwide against SONY to redress defendant’s breach of warranty, negligent data security, violations of consumers’ rights of privacy, failure to protect those rights, and failure and on-going refusal to timely inform consumers of unauthorized third party access to their credit card account and other nonpublic and private financial information."


Sony is not the first company to encounter such a breach, and will not be the last. In 2009, Heartland Payment Systems was hit, resulting the acquisition of a whopping 130 million credit and debit cards. In 2007, retailer TJ Maxx owned up to a data breach that had existed since 2005, thanks to an unsecured wireless network at one of their stores. Tens of millions of credit and debit card numbers were obtained over the course of nearly two years. The hacker, Albert Gonzalez, was eventually sentenced to 20 years.

Whether legal action is taken against Sony won't put the genie back in the bottle, so to speak. Your data, along with the data of 77 million other consumers who put their faith in Sony's system, was improperly accessed last week. It's more helpful (but disconcerting) to wonder what might now happen with the data. 

No Caption Provided
"This is actually a phenomenally economically viable database for the organized crime groups because it is very easy to convert what they have into targeted emails," explained Alan Paller, director of research at  SANS Institute, a computer and information security training and research organization. "What they've got in this database is all these people who are already proven to willing invest in games, so they know what their interests are.  People can craft emails--thousands of different, very personal kinds of emails."

Sony has warned PSN users to pay close attention to their email, a move Paller backed emphatically, as targeted emails designed to trick consumers is exactly what the data picked up from PSN is used for. 

"It's very unlikely that they will not be attacked this way," said Paller. "They [organized crime groups] can make tens of millions of dollars with that kind of highly personalized phishing. It's a tough thing to beat and the more people we can directly tell 'you're gonna get hit this way,' the more we can protect."

The full extent of the damage won't be known for days, weeks or even months. Scattered reports are emerging of credit card theft, but at this point, it's impossible to know if it's related to PSN--it may be coincidental. Then again, it might not. If you learn your information's been compromised, let us know
Patrick Klepek on Google+

170 Comments

Avatar image for levio
Levio

1953

Forum Posts

11

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

Edited By Levio

Is this how Mad Max started?  Australian hackers ruining the national infrastructure?

Avatar image for aneternalenigma
AnEternalEnigma

299

Forum Posts

4436

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By AnEternalEnigma

Identity theft is not possible in this situation since the PSN does not use social security numbers. The most is credit/debit card fraud.

Avatar image for theking
TheKing

856

Forum Posts

232

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By TheKing

Sony fumbled this big time. What a fucking joke.

Avatar image for mikewrestler5
Mikewrestler5

637

Forum Posts

42

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Mikewrestler5

I'm glad Sony is getting sued. This shouldn't have happened.

Avatar image for rhaknar
Rhaknar

6300

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

Edited By Rhaknar

checked with my credit card associated with PSN today and nothing was touched, so im not canceling it tbh. Ill se what happens. Canceling cards is a fucking hassle here.

Funny sidenote tho, when i called them, i asked to check my latest movements to see if there was anything unusual, and the lady goes:

"well sir, there seems to be a unusual ammount of transactions the last few months to a steamstore?" to which i go "yeah...thats normal" :P

Avatar image for spazmaster666
spazmaster666

2114

Forum Posts

42

Wiki Points

0

Followers

Reviews: 9

User Lists: 16

Edited By spazmaster666

Good thing the CC that I used for PSN was an old one that's no longer tied to my current account.

Avatar image for jameskond
JamesKond

243

Forum Posts

65

Wiki Points

0

Followers

Reviews: 2

User Lists: 11

Edited By JamesKond

90 millions fake identities seem like the biggest identity theft event ever conducted.

Avatar image for august
august

4106

Forum Posts

332

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By august
@tropico89 said:
" I like how some people feel that because Xbox live charges a yearly fee that it some how makes it hacker proof.  This can happen to any company people and not just because its a free service.  "
Thanks for the info Solid Snake!
Avatar image for walker_after_dark
Walker_after_dark

87

Forum Posts

296

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

@SpiritOf said:
"  Krisopher Johns of Alabama, I don't know you, but you're a Grade A douche nozzle. "
Agreed. I've had the great good fortune of being included in a couple of class action suits in the course of my life. In one, I think I could have recovered $2.50, and in the other I think it was as much as $10.00. Mr. Johns and his firm are the only ones that are going to benefit from the suit. 
Avatar image for the_bowman_007
The_Bowman_007

46

Forum Posts

345

Wiki Points

0

Followers

Reviews: 0

User Lists: 8

Edited By The_Bowman_007

Canceled my card just in case.  I had my number stolen a few months ago, and even though the situation was fixed within a few hours of discovering the problem, I'd rather not have to go through that again if I can help it.


I don't harbor any ill-feelings toward Sony, though, as long as they fix the issue.  It's those dern hackers we should be mad at!  We shouldn't blame the victim(s), as tempting as it may be to do so.
Avatar image for loganwtf
loganwtf

115

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By loganwtf

My e-mail was hacked on monday and sent out a bunch of spam to my contact list. It may or may not have been related but it's a bit of a coincidence in my eyes.

Avatar image for solidpython
solidpython

86

Forum Posts

79

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By solidpython

My email was hacked today, sent out a shit ton of spam emails to my contacts. I assume it was due to the hack. But I suppose that's what I get for using the same password on everything. :/

Avatar image for scooper
Scooper

7920

Forum Posts

1107

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Scooper

Damn. Could this be the end for Sony in the console market? With the way they've been treated after making their platform nice and open and friendly only for the hackers to piss on their own cake and ruin it all. This is why we can't have nice things.

Avatar image for gahathat
gahathat

171

Forum Posts

249

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Edited By gahathat

77 million credit cards charged all at once would make for a real life Eve-Online scenario.

Avatar image for tepidshark
TepidShark

1493

Forum Posts

16438

Wiki Points

0

Followers

Reviews: 1

User Lists: 14

Edited By TepidShark

All I know is I got the debit card I used for PlayStation Network replaced.

Avatar image for digital_sin
digital_sin

1896

Forum Posts

5480

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By digital_sin

OMG H4X!

No Caption Provided
Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel

As a precaution, I chose to close my credit card account today and be issued a new number.  It's a hassle, but it's better than the possibility that someone was able to get their hands on it through this leak.

Avatar image for xtrafries
XTraFries

257

Forum Posts

7

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By XTraFries

As bummed as I am about this PSN situation, both for the thievery of my information and my inability to play MK online, I am so stoked that Klepek is around to give us the shit and do some digging. 

We've been getting some quality journalism up in this bitch since he signed on. Gives the rest of the crew more time to handle the quick looks and other non-news content while we get some legit newsings. 

everyone wins....well, everyone who didn't have a card attached to their PSN account. 

Avatar image for claude
Claude

16672

Forum Posts

1047

Wiki Points

0

Followers

Reviews: 2

User Lists: 18

Edited By Claude

The whole internet has been acting funny the last week. I can't access my email and I don't even have a PSN account. Tried to pay my Dell bill online and it's down. Crazy. First Whiskey Media goes down and then my internet goes down, not related, but damn. What the hell is going on?

Avatar image for detectivepbert
detectivepbert

273

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By detectivepbert
@JamesKond:   If not the largest identity theft it is certainly one of the largest.  I could care less if Sony loses the console wars.
Avatar image for shaanyboi
Shaanyboi

1804

Forum Posts

3224

Wiki Points

0

Followers

Reviews: 1

User Lists: 5

Edited By Shaanyboi

Sony can't catch a break, lately... yeesh...

I guess NOW I'm glad that I don't have a PS3

Avatar image for sarkhan
Sarkhan

1249

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Edited By Sarkhan
@Benny said:
"

                    I love that Giant Bomb has Patrick to cover this, great, informative articles and it's straight from GBHQ rather than elsewhere. Top Stuff Top Men!

                   

                "

This. Im really glad that Patrick joined GB and started putting out some quality news articles :)

As someone said before me: Take a deep breath. I can understand the panic that started last night(uk time) but we dont know if any CC info have been taken yet.

Anyway, this is ofc no fun for anybody that have anything to do with PSN. I got called up from my bank today just to informe me that Sony had been in contact and that the bank is watching closely.

So i think we should all just do our precursion steps and just follow the news. Im sure Mr Klepek will be the man to bring it to us :)
Avatar image for loganwtf
loganwtf

115

Forum Posts

25

Wiki Points

0

Followers

Reviews: 0

User Lists: 7

Edited By loganwtf
@solidpython: same thing happened to me. My passwords weren't the same but were very similar. 
Avatar image for dreamfall31
Dreamfall31

2036

Forum Posts

391

Wiki Points

0

Followers

Reviews: 2

User Lists: 8

Edited By Dreamfall31
@TepidShark said:
" All I know is I got the debit card I used for PlayStation Network replaced. "
This is something everyone should probably do.  Its a great alternative to cancelling a credit card when you haven't been effected yet.
Avatar image for krakn3dfx
Krakn3Dfx

2746

Forum Posts

101

Wiki Points

0

Followers

Reviews: 4

User Lists: 3

Edited By Krakn3Dfx
@Mikewrestler5 said:
" I'm glad Sony is getting sued. This shouldn't have happened. "
@TheKing said:
" Sony fumbled this big time. What a fucking joke. "
It should never happen, and yet it happens all the time, with many, many companies.

Also, it is a joke, but assuming Sony fumbled is just random assumption not backed up by any facts regarding their system or any security measures they may or may not have in place.

The biggest jokes are posts like these.
Avatar image for rubberfactory
RubberFactory

333

Forum Posts

245

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By RubberFactory

That's some damn good journalism.

Avatar image for minos
Minos

168

Forum Posts

1212

Wiki Points

0

Followers

Reviews: 1

User Lists: 4

Edited By Minos

Thank you Patrick, great coverage.!!

Avatar image for golguin
golguin

5471

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 10

Edited By golguin

I've never bought anything through PSN so my credit card info is fine, but I guess they have my name and email. I don't remember if I had to put an address when I signed up.

Avatar image for raccoonusdoodus
raccoonusdoodus

330

Forum Posts

438

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By raccoonusdoodus

Really hope no one suffers too bad from this and really hoping that Sony will recover and this can be resolved quickly. I'm starting to get worried, you hackers fucking suck.

Avatar image for minos
Minos

168

Forum Posts

1212

Wiki Points

0

Followers

Reviews: 1

User Lists: 4

Edited By Minos

What if these dude just charge 2 dollars out of all the accounts, insignificant amount for each account but the whole $154 md. 

Avatar image for kowalski
Kowalski

320

Forum Posts

26181

Wiki Points

0

Followers

Reviews: 1

User Lists: 5

Edited By Kowalski
@CrazyBagMan said:

" @Kowalski said:

" This is why I never have used my credit card on the PSN, only vouchers. "
In case someone hacks the PSN and steals 775 million peoples information?

This was completely unpredictable. No one, not even you could have known this was going to happen.
"
This wasn't unpredictable, information is being stolen on the net all the time. If it's 5 people or 77 million that are affected doesn't matter to me if they get my credit card info. have you been under a rock for the last decade? This is big business on the internet.    
Avatar image for radar
Radar

933

Forum Posts

334

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

Edited By Radar
@Hailinel said:
" As a precaution, I chose to close my credit card account today and be issued a new number.  It's a hassle, but it's better than the possibility that someone was able to get their hands on it through this leak. "
Why would you close the account? Just request a new card and for the previous to be voided. Closing the account entirely hurts your credit score.

I personally got my debit card voided and got a new one. No hassle, took 3 minutes on the phone.
Avatar image for sharpshooter
Sharpshooter

914

Forum Posts

876

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By Sharpshooter
@RVonE said:
"


I love these in-depth articles Patrick produces for this site!

LOVE IT!

"
Preaching to the choir on that one dude

I'm lucky I never used my credit card on PSN. I used my brothers once about two years ago but thankfully thats long expired.

Sony arn't idiots (or at least I hope the ain't) I'm sure they had systems in place to keep that data safe. Its just this time they were hacked by someone with the skills, equipment and drive to get past those systems. It could happen anytime to anyone. Though to be honest if Microsoft and Valve arn't running checks on their systems I'd be very surprised.
Avatar image for warihay
Warihay

617

Forum Posts

354

Wiki Points

0

Followers

Reviews: 2

User Lists: 7

Edited By Warihay

Great story Patrick! These in depth articles are exactly what Giant Bomb was falling short on before.

Avatar image for tdot
TDot

480

Forum Posts

39

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By TDot

Someone from ohio tried to log into my facebook account this morning. I had the same e-mail and password as my PSN account. BE WARNED!

Avatar image for big_jon
big_jon

6533

Forum Posts

2539

Wiki Points

0

Followers

Reviews: 2

User Lists: 18

Edited By big_jon

So I am worried, Is my email account compromised? Because that has everything linked to it.

Are passwords and such possibly  known?

Avatar image for hailinel
Hailinel

25785

Forum Posts

219681

Wiki Points

0

Followers

Reviews: 10

User Lists: 28

Edited By Hailinel
@Radar said:
" @Hailinel said:
" As a precaution, I chose to close my credit card account today and be issued a new number.  It's a hassle, but it's better than the possibility that someone was able to get their hands on it through this leak. "
Why would you close the account? Just request a new card and for the previous to be voided. Closing the account entirely hurts your credit score.

I personally got my debit card voided and got a new one. No hassle, took 3 minutes on the phone.
"
When i said close the account, I meant get a new card.  Before they mail you a new card, they put a close on the old one.
Avatar image for galacticpunt
GalacticPunt

1512

Forum Posts

4

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By GalacticPunt

Great thorough coverage, Mr. Klepek.  Giant Bomb is now more than my favorite entertainment site, it will be my go-to for videogame news.  Suck it, Destructoid.

BRB, changing my email passwords again!

Avatar image for ezdude
ezdude

457

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

Edited By ezdude

ahh, this is really annoying

Avatar image for stealthraptor
StealthRaptor

568

Forum Posts

32

Wiki Points

0

Followers

Reviews: 0

User Lists: 4

Edited By StealthRaptor

I just got a lovely e-mail from Sony basically telling me to panic. Great. Has anyone else received anything from them?

Avatar image for meatball
MEATBALL

4235

Forum Posts

790

Wiki Points

0

Followers

Reviews: 0

User Lists: 10

Edited By MEATBALL

Welp. This really sucks. What do we know about the level of security that was protecting this information in the first place? They were hacked, but does that mean Sony had poor security in place? I know people are spinning this into a case of incompetence on Sony's part, but is there any evidence to suggest that's actually the case? Or is the mere fact that there was a successful hack enough evidence itself?

I'd like to think that Sony would be a name you could trust to keep information safe, just as I would other reputable companies I've entrusted such information to. Is that foolish of me? If so, what makes other places that store my personal information more trustworthy?

Basically, do we actually know anything about how much Sony are at fault here? Is this just a simple case of the sort of risk you run providing your information to any online service or was this a case of particular incompetence and misplaced trust?

Avatar image for thedudeofgaming
TheDudeOfGaming

6115

Forum Posts

47173

Wiki Points

0

Followers

Reviews: 6

User Lists: 1

Edited By TheDudeOfGaming
@Kowalski said:
" This is why I never have used my credit card on the PSN, only vouchers. "
This, also Vanishing Point...kick ass movie dude :)
Avatar image for xxnbxx
xxNBxx

1110

Forum Posts

9033

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

Edited By xxNBxx
@big_jon:  Anyone that had/has an account with PSN should change passwords to all of their important accounts as well as contact their credit card provider and request a new card.  Better to do this now then have to worry in the future.
Avatar image for wolf_blitzer85
wolf_blitzer85

5460

Forum Posts

2

Wiki Points

0

Followers

Reviews: 0

User Lists: 6

Edited By wolf_blitzer85

Who else read "77 million" as well...you know.

Avatar image for tadthuggish
TadThuggish

1073

Forum Posts

334

Wiki Points

0

Followers

Reviews: 2

User Lists: 41

Edited By TadThuggish

It was just a week ago I looked at my PlayStation Plus account and was able to admit that Sony and Microsoft are finally on par.


Nope!  Microsoft doesn't graciously allow hackers to steal my personal information, then make me do a day's work to clean up their mess.
Avatar image for ninjahunter
NinjaHunter

1005

Forum Posts

138

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

Edited By NinjaHunter

Well I just changed my passwords to pretty much every site that needs one and canceled my card. So my mind is a little more at ease. 

Avatar image for penguindust
penguindust

13129

Forum Posts

22

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

Edited By penguindust

"Organized crime"?  You mean the Russian mafia or the Yakuza hacked PSN?  I don't remember that in any GTA game. 

Avatar image for deactivated-653d2db498d3a
deactivated-653d2db498d3a

155

Forum Posts

155

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

CRAP.

Avatar image for rhombus_of_terror
Rhombus_Of_Terror

2544

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 3

I cancelled my bank card this morning as a precaution. I think vouchers may be the way forward at this point if I purchase stuff from PSN again.

Avatar image for bloodgraiv3
Bloodgraiv3

2730

Forum Posts

2380

Wiki Points

0

Followers

Reviews: 9

User Lists: 9

Edited By Bloodgraiv3


Here's hoping that they can fix this soon.