Congress wants answers from Sony on PlayStation hack
IDG News Service - A U.S. congressional committee has asked Sony Computer Entertainment to explain several issues surrounding the massive potential leak of information on customers of its PlayStation Network.
The network, which serves as an e-commerce and online gaming platform for the PlayStation 3, has been offline for more than a week after Sony discovered an intruder broke through its cyberdefenses and into the network. The service remains unavailable and Sony has warned its 77 million subscribers that their personal information may have been leaked, including, potentially, credit card numbers.
A subcommittee of the House of Representatives' Committee on Energy and Commerce sent a letter to Sony on Friday that seeks answers to many of the same questions that Sony's users have about the attack and the company's response.
Chief among those is Sony's apparent slowness in taking the network offline and informing customers. The company said it became aware of an intrusion on April 19 but didn't take the network offline until a day later. It didn't publicly acknowledge an attack until April 22, and only on April 26 did it warn customers their information may have been stolen.
The letter, a copy of which is on the committee's website, also seeks answers to other questions, including whether the account data of all customers was stolen, or just subset; how the breach occurred; and if Sony has identified those responsible.
"Sony's public statements suggest there is no evidence credit card data was taken, but such a scenario cannot be ruled out," the letter says. "Given the amount and nature of the personal information known to have been taken, the potential harm that could be caused if credit card information was also taken would be quite significant."
The letter is addressed to Kaz Hirai, chairman of Sony's U.S. gaming unit. Hirai also heads Sony's global gaming operations.
The subcommittee on Commerce, Manufacturing and Trade expects to introduce legislation on data security later this year and plans to meet May 4 to discuss data theft issues. It is seeking Sony's response as part of those discussions.
Martyn Williams covers Japan and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn's e-mail address is martyn_williams@idg.com
Data breaches
- N.J. mayor arrested on hacking, conspiracy charges
- Security researcher urges IT to keep up with SAP patches
- Anonymous claims it hacked a DOJ site
- Banking malware spies on victims by hijacking webcams, microphones, researchers say
- Utah CTO takes fall for data breach
- UNC Charlotte: 350,000 SSNs exposed in decade-long breach
- Twitter says many leaked passwords inaccurate, duplicates
- Hackers blackmail Belgian bank with threats to publish customer data
- Russian cybercriminals earned $4.5 billion in 2011
- Nissan, Under Armor report breaches of employee information


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Gov't Legislation/Regulation White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Gov't Legislation/Regulation Webcasts
