Sony says hacker stole 2,000 records from Canadian site
IDG News Service - The problems keep coming for Sony. On Tuesday the company confirmed that someone had hacked into its website and stolen about 2,000 customer names and e-mail addresses.
Close to 1,000 of the records have already been posted online by a hacker calling himself Idahc, who says he's a "Lebanese grey-hat hacker." Idahc found a common Web programming error, called an SQL injection flaw, that allowed him to dig up the records on the Canadian version of the Official Sony Ericsson eShop, an online store for mobile phones and accessories.
The hacker got access to records for about 2,000 customers, including their names and e-mail addresses and a hashed version of users' passwords, said Ivette Lopez Sisniega, a Sony Ericsson Mobile Communications spokeswoman. "Sony Ericsson has disabled this e-commerce website," she said in an e-mail message. "We can confirm that this is a standalone website and it is not connected to Sony Ericsson servers."
Other than the names and e-mail addresses, no personal or banking information was compromised, she said.
Sony Ericsson is a mobile-phone company run jointly by Sony and Ericsson.
Sony has been under continual cyber-attack since April, when its PlayStation Network was hacked and then pulled offline. Over the past week Sony BMG Japan, Sony BMG Greece, the Sony-run So-net Internet service provider, and a company server in Thailand all have been compromised, in what's becoming a free-for-all online attack on anything belonging to Sony.
Earlier this year Sony raised the hackles of hackers by suing George Hotz, a well-respected hacking enthusiast, who'd found a way to break Sony's controls and install Linux on his PlayStation 3. Sony eventually settled with Hotz, but to many it came off as a bully in the affair.
Now, increasingly, Sony looks like a company where security was merely an afterthought.
Earlier this week, Sony said the attacks will cost it at least US$170 million.
Sony's continued problems reflect a cavalier attitude toward computer security, said Scott Borg, CEO of the U.S. Cyber Consequences Unit, a Washington-based think tank that studies cyber-attacks. "It's a pretty obvious conclusion that they weren't managing their security well," he said.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
Data breaches
- U.K. spy agency reportedly snooped on delegates at G20 meetings in '09
- Cyberespionage campaign 'NetTraveler' siphoned data from hundreds of high-profile targets, researchers say
- LinkedIn aims to block hackers with two-factor login
- Drupal resets account passwords after detecting unauthorized access
- US weapons system designs were reportedly viewed by Chinese hackers
- Western Australia police silent on charges for 17-year-old hacker
- Schnucks wants federal court to handle data breach lawsuit
- Microsoft brushes off claim Xbox Live accounts were compromised
- Twitter aims to become safer with two-step sign-in
- Yahoo Japan says 22 million user IDs may have been stolen
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Top Three Reasons Why Customers Deploy EMC VNX with EMC VPLEX What if you could build a cost effective, continuously available storage infrastructure? Learn the top reasons users are deploying EMC VNX with EMC...
- Clearing the Clouds for Midmarket Businesses The 10-point checklist included in this expert brief has been developed to help small and midsize businesses select the cloud model and cloud...
- Perforce Case Study Learn how EMC cost-effectively transformed their infrastructure and improved storage performance by 60% by unifying storage, deploying virtualization and leveraging Flash to meet...
- Data Center Transformation: Balancing user demands with IT mandates There's a flood of user requirements, computing trends, and new technologies driving the need for you to look closely at your IT infrastructure.
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Desktop Apps White Papers | Webcasts
