Sony confirms PlayStation Network hack exposed user info

By | April 26, 2011, 2:02pm PDT

Sony Computer Entertainment on Tuesday admitted that user information on its PlayStation Network and Qriocity services has been compromised, and that credit card information may have been compromised, as well.

In a post to the PlayStation blog, senior director of corporate communications and social media Patrick Seybold relayed the message following a six-day outage - and an outage of information for which Sony has been strenuously criticized.

“…certain PlayStation Network and Qriocity service user account information was compromised in connection with an illegal and unauthorized intrusion into our network,” reads the missive.

Sony says that it has engaged an outside security firm to investigate. Erring on the side of caution, Sony said that personal information may have been gleaned from user accounts, including name, address, and credit card information - they really aren’t sure how extensive the security failure is at this point.

Once service has been restored, Sony suggests that PSN and Qriocity users change their user name and password; the company has also provided details on how users can check their credit reports - surely cold comfort for users affected by this problem.

“We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience. Our teams are working around the clock on this, and services will be restored as soon as possible,” reads the note.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

A long-time veteran of the Apple news business, Peter has also spent more than fifteen years covering games and the game industry. A self-proclaimed Alpha Nerd, Peter also professes a love for anime, sci-fi cons, gadgets of all kinds and various geek subcultures.

Disclosure

Peter Cohen

Peter Cohen does not own any stock or have any investments in any of the companies he writes about.

Biography

Peter Cohen

A resident of Cape Cod, Massachusetts, Peter has spent more than fifteen years writing about games and the game industry. For a decade Peter was senior editor for Macworld magazine, writing online news and covering the Apple game beat in Macworld's Game Room column.

Peter is currently executive editor for The Loop, an Apple news and analysis site founded by former Macworld editors. He's cohost of Angry Mac Bastards, a weekly podcast that viciously eviscerates some of what passes for Apple-related news and analysis in the tech blogosphere.

Peter is also a freelance technology journalist and reviewer whose words can be found in Macworld, Mac|Life, MacUser, MacFormat and Tap! Magazine.

49
Comments

Join the conversation!

Just In

RE: Sony confirms PlayStation Network hack exposed user info
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
how do you change user name and password
@ciaranl95 Can't - not until the service is back up & operational
@ciaranl95
Ask them.
0 Votes
+ -
@ciaranl95 you can't ever change your username, not even when you can connect. your only option is to delete your account and start over with a different username
@diskreaderror@...

They might change that if the breach is that damned widespread.
@ciaranl95
I looked at the forum that was linked yesterday in an article and it was filled with children who's biggest complaint was how long it would take to recover. I hope this gets enough news coverage that parents know their information may have been compromised if they allow their kids to play on their account or ever let them use their credit card for a purchase on there.
L O L
Sony really messed with the wrong people when they killed the linux support and then went after geohotz.. even though he has nothing to do with this.. im sure some hackers took this as a direct insult.
0 Votes
+ -
Message has been deleted.
kadengt Updated - 27th Apr 2011
@kadengt Thats if they don't beat the crap out of you.Not being mean.

I'm and PSN and Xbox live lover but it still just don't believe that some wanna be hackers would want to hack PSN.If i were PSN i would first track there Virus or whatever they used to hack PSN then i would connect to the computer and get to the bottom of this.
0 Votes
+ -
@kadengt

"Your an idiot."

Oh the irony in that statement.

He made a valid point even though you don't agree with it. No, it's no laughing matter but that very well may be the motivation behind the attacks.
  • Flagged
0 Votes
+ -
Nobody killed Linux support....
johnmckay 26th Apr 2011
@shdw_knt@...

a) It was never there officially.
b) You could keep it if you didn't choose the updated firmware.

c) Loads of us downloaded it but never converted.... way too much hassle. I soon got over it... so should they.

d) Dont try to justify this; because who knows what info they have. Hopefully it's yours and not mine but info goes back along way.
0 Votes
+ -
@shdw_knt@...

You really are an idiot! Whoever did this has not attacked Sony, they've attacked users. These low-lifes have gone for account information and no doubt particularly for credit card information. That affects ordinary people with almost no impact on Sony. If these bastards had wanted to make a point to Sony, there are so many more ways in which they could have done it without stealing credit card and other information. The bottom line, these people are not moralistic martyrs . . . they are nothing more than bottom feeding criminals!
@ptorning
Actually, the stolen credit card details *are* Sony's problem, and not the people who own the cards, Sony are the ones that have to mop up, yes, it will be inconvenient to sort out your card being used by criminals, but you are covered by your bank, by Visa, by Mastercard, AMEX, *and* by the fact that Sony are at fault, it is going to cost Sony a fortune.
The background debated over on Maker Blog put GeoHotz and his followers firmly in the OS framework, therefore not a cracker - the only difference from the WII and Kinnect hacks being the reaction of the target company, as GeoH pointed out at the time - if they'd have intended cracking them, it would have been midwinter, not now. Although some may walk the back alleys, it's not their style, in any case. Much more likely it's Chinese.
@mikejade

you can't while the service is offline. yikes, #epic failure
0 Votes
+ -
Quick!
symbolset 26th Apr 2011
Change your birth date.
@symbolset

You use your actual birthday on any site?
It's a gaming network!

Is criticism of Sony still accepted in talkbacks even though MS criticism is deleted? Does anyone have a copy of the new rules?
That's horrible.It should have never happened.
Sony = Epic Fail. They tried to copy Xbox Live, but kinda forgot about security!
0 Votes
+ -
Oh Oohh!
rseaman79 26th Apr 2011
I thinks me smell a class action lawsuit.
0 Votes
+ -
their interface is horrible, even before this happened I couldn't add any money to my kids account. both calls to their support desk told me go to buy play station network cards... really? they lost interest and the site went down oh well
Well, we all know that it is Bush's fault.
0 Votes
+ -
Seriously...
Wolfie2K3 27th Apr 2011
@BigJohnLg
Exactly how can it be a former US president's fault? Sony is a Japanese company. It happened on Obama's watch - 2+ years after he took office.

Oh, wait... You're one of them left wing tards who has to blame everything on Bush.
@Wolfie2K3 Sarcasm's hard to get on the internet. He's making fun of the people that randomly blame everything unrelated on Bush.
@Wolfie2K3 Kinda like the right wing tards that blame anything and everything on Obama?
now I can't shotgun people in the face in Black Ops.
I'm sad.
Realize all your accounts with same user/email/password combo are at risk too. No one use same info though wink
0 Votes
+ -
Another reason.....
msims@... Updated - 26th Apr 2011
To buy an XBOX 360 and join XBOX Live. I love XBOX Live becuase it ever rarely goes down, it constantly updates itself and all you game content. An best of all...You can change your username and password.
0 Votes
+ -
@msims@...

You can do all of those wonderful things . . . except when your XBox 360 is RRoD! I think I'll go and watch a BlueRay now . . .
@ptorning

I did suffer the RRoD and it was horrible. Fortunately, Microsoft didn't put up a fuss and expressed me a shipping box right away. Oh yeah, my Xbox was beyond its warranty and modded. Now I have two 360s and I watch more Netflix and ESPN 3 on them than I play games.
@ptorning

How very 2006 of you to say.
@jmiller

2006? Try 2010 and 2011 when so many people connected a Kinect only to have it RRoD their XBox.

My point is that, unfortunately, examples of major problems related to electronics items and their related software can easily be found with many manufacturers.
0 Votes
+ -
Three of a kind in Japanese abuse
JelMin Updated - 27th Apr 2011
Given that this should happen to the inventors of the Root Kit, how exquisitely painful must this loss of face be! They sat on it for a good week into the bargain, exposing their customers to the possibility the nasties could have wiped their accounts out, and putting them firmly alongside TEPCO and Toyota as totally irresponsible Japanese managers on the grounds of gross prevarication at other peoples' expense. Perhaps the Banks who will take the hit would care to pull their credit lines?
0 Votes
+ -
Only biometrics from here on in
JelMin Updated - 27th Apr 2011
As they've compromised huge amounts of baseline data, and Epsilon seem to have lost the rest, it's surely now time to abandon all but biometric data held by Government in escrow, not just for Sony but all IDs. The Belgians have a start with ID cards to which this can be added: the Escrow agency provides half the key, the card the rest, to match the biometric of the cardholder. That way there's no way for the bank or its agent the seller to falsify the key as they don't hold it.
0 Votes
+ -
Wow! I haven't been able to log in for serveral months. (I must update) or some-such (even though I have several times since). If I can ONLY change my account when logged in, then I guess I've got serious problems.
0 Votes
+ -
What took Sony so long?
bartly 27th Apr 2011
I guess most of the people commenting are like me and don't have an account with the PS3 or I would think there would be a lot more indignation over Sony finally saying: "Hey, we've been down for six days and criminals have had your credit card and personal information to play with the whole time, but we're trying our best to make it better."
0 Votes
+ -
@bartly Umm... I'm a customer that has had his information lost by Sony and I'm not too happy about it...nor am I too upset about it. To begin with, I won't provide these services with too much information. Why they ask for it and why people give it is baffling to me.

They asked for a birthdate. Why the heck do they need my DOB?? Why not just ask my age...either of them ie easy enough to lie about. Oh, I see you won't let me register without one...great, I gave them one (Just not mine). They also require a credit card...great, I gave them one (a virtual number that is now closed). They had to have the billing address...great, I gave them one (Well, not really. They just match street number and zip code.)

Steal my identity with that information...good luck.
i don't own any consoles but a friend who does said this was an attack that was revenge based for something the PSN did. according to my source he said a group of hackers warned Sony they'd bring the network down. it supposedly wasn't an attempt to steal anything but i'm sure to swing public sentiment to their side Sony would play it that way. i wish i could remember the details but he told me there were warnings about this days before it happened and in fact he told me it was going to happen before it did.

i may well be wrong, but it does seem odd if people who used the PSN knew about the planned attack ahead of time.
0 Votes
+ -
"Sony got a bad luck again after the PS3 hack. Sony Corporations online data of PlayStation Gamers just got stolen. It included the theft of 77 million user accounts that consisted of their names, addresses and credit card data. Due to this Sony has shut down its all servers. Reports say that this theft took place 7 days ago by an illegal and unauthorized person. Sony immediately shut down all its networks thus preventing the players to play online and even the online purchases. This theft is said to be the biggest internet security break-ins ever. Sony claimed that there is only a small probability of credit cards of users are being stolen but it could not promise it. The data stolen is estimated of worth about $5oo millions. Alan Pailer, the research director of SANS institute said that they didnt pay enough attention to the security system of the servers as they were more focused on the innovation of the new products. This could be a major reason for this security break-in. Pailer suspected that Hackers succeeded to break-in security system by taking over the PC of a system administrator who had the rights to access the information about Sonys customers. He also claimed that they hacked into the administrators system by sending an email that contained malware. Reports also say that the same group of hackers hacked into the systems of other major corporations. To all its online buyers, Sony suggested to place fraud alerts on their credit cards accounts through three U.S credit card bureaus. Sony said it could restore some of the networks services within a week."

http://www.techextant.com/sony-playstation-data-break/
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix