Sony warns users of data loss from PlayStation network hack
With network down 6 days and counting, Sony admits security breach
Computerworld - It's been six days and the PlayStation Network is still offline, and now Sony has acknowledged that the problem involved a security breach.
The online multiplayer gaming site, along with Qriocity, Sony's cloud music subscription service, went down last Wednesday and may not be back for another week.
Today, the company posted information online admitting that the hack had breached users' account information, including name, address, birth date, purchase history and online ID.
Patrick Seybold, a senior director at Sony, also noted in the blog post that there's no evidence users' credit card information was stolen. However, he added that "out of an abundance of caution," Sony is advising users that their credit card number and expiration date may have been obtained.
"We have discovered that between April 17 and April 19, 2011, certain PlayStation Network and Qriocity service user account information was compromised in connection with an illegal and unauthorized intrusion into our network," the company wrote. "We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience. Our teams are working around the clock on this, and services will be restored as soon as possible."
Users were first frustrated with their inability to get online and play their favorite games; now, they're frustrated about the security breach and what it might mean for them financially. And they've been taking to Twitter to vent about it.
Tylerbaird tweeted: "I hate to say it, but could this be the death of the #PlayStation? Sounds like the hackers even took the kitchen sink."
And Ctrlzee tweeted: "Another upsetting thing about the PS3 data theft - you can't even protect your account by changing your password since the service is down."
Dan Olds, an analyst with The Gabriel Consulting Group, said the site outage alone was causing trouble for Sony. The data breach acknowledgement just heaps on more.
"This is the nightmare scenario for any videogame network vendor," said Olds. "Not only were they hacked, but it's taken them down for almost a week so far. Plus, they don't know the extent of the damage so far. They can't say if personal data or credit cards have been stolen. This is bad."
He added that compounding the problem is the number of kids and teenagers who use the PlayStation Network. Parents aren't going to be happy that their children's information, as well as their own data and possibly even their credit card information, has been breached.
"This incident is a huge blow to the trust between customers and Sony," he noted. "If hackers have accessed personal info and credit card data, it could cripple Sony's online gaming business. And it could have a very negative impact on their video game console business overall. If enough users perceive that Sony's network can't be trusted, they'll flee."
That, he added, could hurt Sony's entire gaming platform.
Sharon Gaudin covers the Internet and Web 2.0, emerging technologies, and desktop and laptop chips for Computerworld. Follow Sharon on Twitter at @sgaudin or subscribe to Sharon's RSS feed . Her e-mail address is email@example.com.
- Healthcare organizations still too lax on security
- Why would Chinese hackers want US hospital patient data?
- About 4.5M face risk of ID theft after hospital network hacked
- Supervalu breach shows why move to smartcards is long overdue
- Grocery stores in multiple states hit by data breach
- Update: Payment cards with chips aren't perfect, so encrypt everything, experts say
- U.S. agencies halt background checks by contractor after cyberattack
- Five unanswered questions about massive Russian hacker database
- Massive Russian hack has researchers scratching their heads
- Russian hackers amass 1.2B stolen Web credentials
Read more about Security in Computerworld's Security Topic Center.
- Securing Mobile App Data - Comparing Containers and App Wrappers Analysts agree that Mobile Device Management (MDM) is not enough when it comes to securing app data. Although it remains a critical component...
- PCI 3.0 Compliance In this white paper, learn how PCI-DSS 3.0 effects how you deploy and maintain PCI compliant networks using CradlePoint devices.
- Mitigating Security Risks at the Networks Edge This white paper provides strategies and best practices for distributed enterprises to protect their networks against vulnerabilities, threats, and malicious attacks.
- 5 Strategies for Modern Data Protection Read the five strategies for modern data protection that will not only help solve your current data management challenges but also ensure that...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!