PlayStation.Blog
Twisted Metal
Philip Reitinger's Avatar Oct 11 2011

An Important Message From Sony’s Chief Information Security Officer

+ Posted by Philip Reitinger // SVP & Chief Information Security Officer, Sony Group

We want to let you know that we have detected attempts on Sony Entertainment Network, PlayStation Network and Sony Online Entertainment (“Networks”) services to test a massive set of sign-in IDs and passwords against our network database. These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites or other sources. In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks. We have taken steps to mitigate the activity.

Less than one tenth of one percent (0.1%) of our PSN, SEN and SOE audience may have been affected. There were approximately 93,000 accounts globally (PSN/SEN: approximately 60,000 accounts; SOE: approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts. Only a small fraction of these 93,000 accounts showed additional activity prior to being locked. We are currently reviewing those accounts for unauthorized access, and will provide more updates as we have them. Please note, if you have a credit card associated with your account, your credit card number is not at risk. We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet.

As a preventative measure, we are requiring secure password resets for those PSN/SEN accounts that had both a sign-in ID and password match through this attempt. If you are in the small group of PSN/SEN users who may have been affected, you will receive an email from us at the address associated with your account that will prompt you to reset your password.

Similarly, the SOE accounts that were matched have been temporarily turned off. If you are among the small group of affected SOE customers, you will receive an email from us at the address associated with your account that will advise you on next steps in order to validate your account credentials and have your account turned back on.

We want to take this opportunity to remind our consumers about the increasingly common threat of fraudulent activity online, as well as the importance of having a strong password and having a username/password combination that is not associated with other online services or sites. We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account.

//Add Your Own

99 Comments

PAGE 1 2

1

+ Jeeves_Tremor on October 11th, 2011 at 7:12 pm said:

Well then, the more you know.

And Knowing is half the battle!


2

+ KazeEternal on October 11th, 2011 at 7:15 pm said:

Thank you for the update. Please keep up the good work.


3

+ Nick36542 on October 11th, 2011 at 7:16 pm said:

Thanks for letting everyone know so soon. It’s better to be aware.


4

+ hush404 on October 11th, 2011 at 7:18 pm said:

Thanks for the update, much appreciated :)


5

+ JamesL007 on October 11th, 2011 at 7:20 pm said:

That’s why I use PSN cards, but still quick response and all that is much appreciated big time.

Keep up the Great work all!!


6

+ jacob-813 on October 11th, 2011 at 7:20 pm said:

This is good that your letting us know this before everyone goes in another rage.


7

+ loganwolf13 on October 11th, 2011 at 7:21 pm said:

good job sony thats how u do it


8

+ Bxbombers007 on October 11th, 2011 at 7:26 pm said:

This needs to stop


9

+ OldKai on October 11th, 2011 at 7:27 pm said:

Thanks very much for letting us know.


10

+ Neo-CTU on October 11th, 2011 at 7:28 pm said:

Thank you so much for the info


11

+ remanutd5 on October 11th, 2011 at 7:30 pm said:

its great that you guys are letting us know soon but this hack thing needs to stop


12

+ vza004 on October 11th, 2011 at 7:31 pm said:

1 step ahead is always awesome. Thank you for the heads up!!


13

+ Kxpuc on October 11th, 2011 at 7:31 pm said:

#11 that’s like saying violence needs to stop, sounds good on paper never will happen


14

+ Kirkpad on October 11th, 2011 at 7:31 pm said:

Oh snaaaaapppp. Attempts at using log-ins acquired from other websites?! I hope everyone uses an alternate password!


15

+ playaplus on October 11th, 2011 at 7:31 pm said:

keep people posted


16

+ Blkant on October 11th, 2011 at 7:33 pm said:

Awesome catch. I’m glad to see you guys really stepped up your response time and over all security. :)


17

+ Emby25 on October 11th, 2011 at 7:33 pm said:

I appreciate Phil’s seemingly quick response to the situation, but I feel like they are sugar coating and trying to make 93,000 accounts being compromised seem fine and acceptable. Yes they may have gotten the PW’s and usernames from another source, but think about it for a second… where did that website get the usernames and passwords. Sony I love your gaming consoles, and games but I must admit if you keep dropping the ball with all these silly little IT mishaps you WILL start losing customers. Sorry for the tough love!

Emby25 (Matt)


18

+ Kasaix on October 11th, 2011 at 7:33 pm said:

Thanks for the heads up. You guys are up-front about issues like this, which is why I trust you.


19

+ NYYanks21 on October 11th, 2011 at 7:35 pm said:

Thanks for letting us know what’s going on. But hacked again?


20

+ Squall1979 on October 11th, 2011 at 7:36 pm said:

Thanks for the heads up Sony. Well done. Bravo!


21

+ blakseed on October 11th, 2011 at 7:36 pm said:

Nice. On the ball.


22

+ Dwayne_AKA_OE on October 11th, 2011 at 7:37 pm said:

Thank You for the Heads up


23

+ FredNation on October 11th, 2011 at 7:41 pm said:

Thank you for your time and effort of alerting us users.


24

+ OmegaJirachi on October 11th, 2011 at 7:43 pm said:

Sony, will you please not only locate the hackers, but KILL them too? Or at least put them in prison for life.


25

+ bakerarmy on October 11th, 2011 at 7:44 pm said:

They say only a small percent 0.1 but that is still 93,000 people. That is a lot of people. Can’t downplay that. Sure it is small compared to 74 million accounts.


26

+ Websblobs on October 11th, 2011 at 7:47 pm said:

Wow, looks like I got hacked. Great, going to be a lot of fun getting my account back. Oh well, I just hope it gets fixed.


27

+ OmegaJirachi on October 11th, 2011 at 7:48 pm said:

Anyway, thank you thank you THANK YOU for informing us. I just changed my password, instead of making it words, it’s a scramble of letters and numbers that would take me forever to memorize, character by character. Luckily I wrote it on a physical piece of paper. Take THAT, hackers!


28

+ hrfuknstuf on October 11th, 2011 at 7:49 pm said:

Cover yourselves, everyone, and use PSN cards… you can order them on Amazon, and they can e-mail you the activation code; it’s a win-win. Oh yeah; thanks for the speedy alert, Sony. :)


29

+ M-Easy on October 11th, 2011 at 7:50 pm said:

Great job Sony


30

+ FredPunella on October 11th, 2011 at 7:57 pm said:

Way to go Sony!

Sony/Gamers: 1
Script Kiddies: 0


31

+ kc_chang on October 11th, 2011 at 7:57 pm said:

Thanks for the update. Please take care of it. Should also inform FBI about this.


32

+ geist226 on October 11th, 2011 at 7:57 pm said:

Wow, that was… quick!


33

+ DMcgee627 on October 11th, 2011 at 7:57 pm said:

Sure am glad I opted out of the new EULA now. I figured something would happen again


34

+ darthmilo77 on October 11th, 2011 at 7:59 pm said:

How did any of them work if there were mandatory password changes in May?


35

+ JH-FallenReaper on October 11th, 2011 at 8:01 pm said:

so does this mean another lockdown in the future or just a warning not that i have anything valuable in my account!!


36

+ Kirkpad on October 11th, 2011 at 8:05 pm said:

@34, not everyone used PSN since the mandatory password change (meaning they never changed their password).

Furthermore, some people may have changed their PSN password to match a password they use on another website.

These two things are likely where the majority of “successful attempts” came from.


37

+ Kirkpad on October 11th, 2011 at 8:06 pm said:

P.S. This happens on Steam all the time. Hackers steal email/passwords from forums/websites with TERRIBLE security and try the passwords all at once on Steam.


38

+ IPumpMyGun on October 11th, 2011 at 8:06 pm said:

Come on Philip Reitinger…You and your team got to be no this 24/7, so Sony’s security won’t be breached again….


39

+ Assasin102 on October 11th, 2011 at 8:06 pm said:

Thank You Sony. Keep it Up. Good to know whats goin and that yall are right on the situation.


40

+ IPumpMyGun on October 11th, 2011 at 8:07 pm said:

Edit: On


41

+ jimmyfoxhound on October 11th, 2011 at 8:07 pm said:

wow.. PSN gonna be shut down again.. this sucks..


42

+ TomHoang on October 11th, 2011 at 8:08 pm said:

Thanks for the quick update this time and not waiting over a week to inform us.


43

+ WiZeGuY on October 11th, 2011 at 8:10 pm said:

WOW, glad to hear they are on top of things…


44

+ IPumpMyGun on October 11th, 2011 at 8:12 pm said:

I don’t think a shut down of PSN will be necessary this time.


45

+ Spurs2109 on October 11th, 2011 at 8:13 pm said:

Great. My account has been locked and am unable to access PSN and play online. Come on guys, this is getting old.


46

+ IPumpMyGun on October 11th, 2011 at 8:14 pm said:

Spurs2109: Would you rather hackers take control of your account? Safety measures are in place for a reason as opposed to last time and Sony not being on the ball quick enough.


47

+ IPumpMyGun on October 11th, 2011 at 8:16 pm said:

Spurs2109: If you’re one of those people Sony is contacting through email they have stated to change your password.


48

+ qwertyuiop357 on October 11th, 2011 at 8:17 pm said:

Thanks for letting us know! Looks like you guys learned a few things :)


49

+ Kchow23 on October 11th, 2011 at 8:18 pm said:

Good stuff, way to be on the ball this time!


50

+ DMcgee627 on October 11th, 2011 at 8:20 pm said:

inb4 They’ve known this for a week


PAGE 1 2

Leave a Comment