Courtney Pittman
December 3, 2017
CRJU4305/W01
On the 19th of April 2011 in San Diego, California, Sony was attacked by hackers at their
data center. The unauthorized access of customers data was gained through Sony’s PlayStation
Network servers. Strange activity was detected on the network, but the unauthorized access was
not noticed until the next day. “More than 77 million Qriocity and PSN users’ accounts and more
than 24.5 million Sony Online Entertainment user accounts were accessed for personal
information” (Gillies, 2011). This attack in 2011 was stated to be the largest personal data heist.
There were also many other victims of the attack such as, Sony Music Entertainment in Greece
and Japan and servers in Thailand.
When Sony detected the breach to their network system, they immediately turned off the
affected systems and paused restoration of PSN services for all users until May 1, 2011. The
users were then required to change not just their passwords, but their usernames as well to help
the prevention of anymore attacks. “Since the attackers had exploited Sony’s website via its
URL, they were thus forced to disable the page temporarily” (The Sydney Morning Herald,
2011). By utilizing the vulnerabilities in the software, the attackers gained access to the servers
and elevated their privileges. “The hackers could hide themselves from the administrators and
deleted the log files. Sony’s team did not identify the intrusion, as they were busy identifying the
DoS attacks” (Carlson, 2011).