57 total SONY hacks in 12 years

Over the last two months, the multi-national Sony Corporation has come under a wide range of attacks from an even wider range of attackers. The backstory about what event prompted who to attack and why will make a mediocre made-for-TV movie someday. This article is not going to cover the brief history of hacks; readers can find details elsewhere. Instead, the following only serves to create an accurate and comprehensive timeline regarding the recent breaches, a cliff notes summary for easy reference.

Other than Steve Ragan and The Tech Herald, most recent articles about Sony make vague references to ongoing problems, but do not enumerate the full history. This is likely because the past events, while only 45 days old at most, are convoluted and confusing. The table below should serve to fix that, hopefully giving journalists and security professionals a concrete and clear history.

One thing should be noted; the attacks against Sony are not coordinated, nor are they advanced. Sony has demonstrated they have not implemented what any rational administrator or security professional would consider "the absolute basics". Storing millions of customer's personal details and passwords without using any form of encryption is reckless and ridiculous. Even security books from the '80s were adamant about encrypting passwords at the very least. Several of Sony's sites have been compromised as a result of basic SQL injection attacks, nothing elaborate or complex.

If anyone... ANYONE at all uses the term "advanced persistent threat" in describing the attacks on Sony, please hit them very hard before disregarding them as ignorant charlatans hell-bent on serving their own interests. Given the wide variety of attackers (see below), the attacks on Sony can only be described as an uncoordinated effort at best.

That said, welcome to the recently coined term, "Sownage". The state of being thoroughly "owned like Sony is".

IncidentDateSiteStockWho (allegedly)Observation2011-04-04Anonymous Engages in Sony DDoS Attacks Over GeoHot PS3 Lawsuit31.45The group Anonymous declares Sony an enemy and begins a DDoS attack against PSN over the 'GeoHot' lawsuit filed earlier in the year.2011-04-20Sony PSN Offline30.14PSN taken offline by Sony due to hack.Network World has a timeline of events related to PSN.2011-04-26PSN Outage caused by Rebug Firmware29.79Sony drops PSN Network due to problems with the 'REBUG' firmware allowing developer access, and rumors of widespread piracy. Initial speculation said the outage was the result of a second DDoS attack by Anonymous. They denied it in a press release saying "for once we didn't do it".12011-04-26PlayStation Network (PSN) Hacked29.79Anonymous (?)Sony admits attack took place between April 17 and 19, but did not disclose until around the 26th. Anonymous blamed by Sony initially, but denies involvement in hack.Records breached: 77 million names, addresses, email addresses, birthdates, PlayStation Network/Qriocity passwords and logins, handle/PSN online ID, profile data, purchase history and possibly credit cards obtained (DatalossDB Entry)2011-04-27Ars readers report credit card fraud, blame Sony29.032011-04-28Sony PSN hack triggers lawsuitSony says SOE Customer Data Safe28.3922011-05-02Sony Online Entertainment (SOE) hackedSOE Network Taken Offline28.80(unknown)Sony Press Release.Records breached: 24.6 million customer dates of birth, email addresses and phone numbers, including 12,700 non-U.S. credit or debit card numbers and expiration dates and about 10,700 direct debit records including bank account numbers (DatalossDB Entry)2011-05-03Sony Online Entertainment (SOE) issues breach notification letter28.442011-05-05Sony Brings In Forensic Experts On Data Breaches27.98"Data Forte, Guidance Software, and Protiviti will investigate who hacked into Sony's servers and how they cracked the company's defenses."2011-05-06Sony Networks Lacked Firewall, Ran Obsolete Software: Testimony28.06Gene Spafford wrote an article describing his testimony, and how many media outlets misquoted him.32011-05-07Sony succumbs to another hack leaking 2,500 "old records"n/aSonyNote: This information was available via a Sony website and indexed by Google. This was not a "hack" by any means. File originally found at products.sel.sony.com/shared/santa/dbs/sweepstake.xls (now offline)Records Breached: 2,500 names and partial addresses of 2001 Sony sweepstakes2011-05-12Lawyers take aim at Sony hack, may miss on payout28.232011-05-14Sony resuming PlayStation Network, Qriocity servicesn/aAll SOE games/services were down for a total of 24 days.42011-05-17PSN Accounts still subject to a vulnerability28.07unknownWith this vulnerability, an attacker has the ability to change a user's password using only their account's email and date of birth. Rumors suggest it was being exploited by bad guys.TNW article titled "Not so fast: Sony's PlayStation Network hacked again" is misleading.Sony blog on incident (vulnerability fixed)2011-05-18Prolexic rumored to consult with Sony on security27.80"got a call from a recruiter who swore some company called prolexic was hired to protect Sony from Anonymous"Update: Prolexic did provide services to Sony, but only for DDoS mitigation.52011-05-20Phishing site found on a Sony server27.05unknown(additional article)62011-05-21Hack on Sony-owned ISP steals $1,220 in virtual cash (So-net Entertainment Corp)n/aunknown(additional article)Records Breached: e-mail and virtual currency of 128 accounts72011-05-21Sony Music Indonesia Defaced By k4L0ng666n/ak4L0ng666No evidence of personal information being compromised.82011-05-22Sony BMG Greece the latest hacked Sony siten/ab4d_viperaApparently done via SQL Injection. Pastebin dumpRecords Breached: 8,500 usernames, email addresses, phone numbers and password hashes (DatalossDB Entry)92011-05-23LulzSec leak Sony's Japanese Websites26.59LulzSecSQL Injection in www.sonymusic.co.jp (article)Sophos says databases do "not contain names, passwords or other personally identifiable information"2011-05-23Sony forecasts a $3.1B loss for FY 2011 due to quake, PSN failurePSN breach and restoration to cost $171M, Sony estimates26.59102011-05-24Sony says hacker stole 2,000 records from Canadian site (Sony Erricson)27.90IdahcSony Ericsson Got Hacked by Idahc - Lebanese hacker via SQL InjectionIdahc dumped 1,000 of the cords to http://pastebin.com/4YGAWxQZ (since removed)Records Breached: Email addresses, passwords and names of 2,000 users (DatalossDB Entry)2011-05-25Sony Begins Providing ID Theft Protection for PlayStation Hack27.65112011-06-02LulzSec versus Sony Pictures26.54LulzSecSophos says 4.5 million records exposed. LulzSec initially thought to target the elderly, but clarify they dumped the database by DoB and stopped at 1943.Lulz? Sony hackers deny responsibility for misuse of leaked dataRecords breached: Over 1,000,000 users' passwords, email addresses, home addresses, dates of birth, as well as administrator login passwords. Information taken from AutoTrader users database, Summer of Restless Beauty users database, Sony Wonder coupons database, Sony Wonder music codes database, Seinfeld Del Boca Vista database (DatalossDB Entry)122011-06-02Sony BMG Belgium (sonybmg.be) database exposed26.54LulzSecRecords Breached: Email addresses, usernames, cleartext passwords, internal release dates of records, sales reports (DatalossDB Entry)132011-06-02Sony BMG Netherlands (sonybmg.nl) database exposed26.54LulzSecRecords Breached: Usernames, cleartext passwords2011-06-02Sony, Epsilon Testify Before Congress26.54Tim Schaaff, President of Sony Network Entertainment International Witness Testimony (PDF)"Sony Network Entertainment and Sony Online Entertainment have always made concerted and substantial efforts to maintain and improve their data security systems."142011-06-03Sony Europe database leaked26.38IdahcDump of the apps.pro.sony.eu database via SQL InjectionRecords Breached: 120 names, phone numbers and e-mail addresses (DatalossDB Entry)2011-06-05Latest Hack Shows Sony Didn't Plug Holes"Group members said their motivation was to show Sony execs weren't telling the truth when they tried to reassure customers they had revamped security to prevent the simple, almost identical exploits that allowed a range of hackers to take over one of its networks after another beginning in mid-April."152011-06-05Sony Pictures Russia (www.sonypictures.ru) databases leakedunknownAnother SQL injection attack. @LulzSec confirms they did not find it.Records Breached: all (?) databases of Sony Pictures Russia2011-06-06LulzSec member arrestedBased on a post to Full-Disclosure, rumors that a member of LulzSec was arrested circulated widely. This news was included in several articles that did not validate the information. LulzSec issued a statement saying the news was wrong, and that "ev0" was not a member of the group. Arik Hesseldahl actually contacted a source at the FBI to confirm this and covered the details in an article.162011-06-06LulzSec Hackers Post Sony Computer Entertainment Developer Network (SCE Devnet)25.76LulzSec(additional article #1), (additional article #2), LulzSec "press release" on incidentData Leaked: 54meg torrent of Sony Computer Entertainment Developer Network (SCE Devnet) source code172011-06-06LulzSec hits Sony BMG, leaks internal network maps>25.76LulzSecWhile @LulzSec released the data in one torrent, the group confirmed the BMG maps did not come from SCE Devnet (tweet since deleted), making this a distinct and separate compromise.Data Leaked: Sony BMG internal network maps182011-06-08Sony Portugal latest to fall to hackers25.25IdahcDump of the sonymusic.pt database. Idahc says he found SQL injection, cross-site scripting (XSS) and Iframe injection vulnerabilities in the site.Records Breached: Customer e-mail addresses (DatalossDB Entry)192011-06-08Spoofing lead to fraud via shopping coupons at Sonisutoa / My Sony Club (Google Translation)25.25unknownThrough "spoofing", an attacker used 95 accounts to exchange online shopping coupons worth 278,000 points at Sonisutoa (My Sony Club), defrauding Sony of ~ 280,000 yen (~ US$3,500). Sony cannot confirm if e-mail addresses or passwords were leaked.2011-06-11Spain Arrests 3 Suspects in Sony Hacking CaseFrom the article: "According to a police statement, the suspects are part of Anonymous.."202011-06-20SQLI on sonypictures.fr24.28Idahc and Auth3ntiqSQL injection reveals hashed passwords and e-mail addresses. Idahc announced the day before that the site was vulnerable.Records Breached: 177,172 e-mail addresses (DatalossDB Entry)2011-06-23Class Action Lawsuit Filed Against Sony/SCEASuit alleges Sony fired employees in network security weeks before breach2011-06-28Sony CEO asked to step down on heels of hacking fiasco25.42".. the CEO sidestepped the request and instead pointed out that Sony is hardly the only company to face this kind of cyber assault."212011-07-06Hackers posts fake celebrity stories on Sony site26.93sonymusic.ie (Ireland) defaced to include the fake stories.2011-10-12Sony Press Release: 93,000 PSN Account Passwords Compromised20.06Note: The attack was performed using brute force guessing of accounts. The problem was due to customers using weak passwords. It could be argued that Sony should enforce a stronger password policy.

Given the recent testimony from Tim Schaaff, President of Sony Network Entertainment International, one may be led to believe that Sony has been proactive in their digital security. Schaaff told the Subcommittee on Commerce, Manufacturing and Trade, part of the House of Representatives Energy & Commerce Committee, that "Sony Network Entertainment and Sony Online Entertainment have always made concerted and substantial efforts to maintain and improve their data security systems." Looking at a brief, and very likely incomplete, history of Sony's hacking problems, this statement seems absurd.

Schaaff goes on to say "The attack on us was, we believe, unprecedented in its size and scope." With the string of recent high-profile attacks against Lockheed Martin, RSA Security, and HBGary Federal (by the same group allegedly involved in the Sony PSN hack), this comment seems disingenuous. Further, between 2001-02-05 and 2001-05-05, Sony was attacked and compromised 11 times. While this is a slightly bigger time frame than the recent activity (2011-04-17 to 2011-06-02), given the first run was in 2001 and attacks were arguably less frequent (while defacements were considered high profile and got a lot of attention), can Sony really back up this comment?

Note: This list is likely incomplete, and just represents a quick search of past Sony activity related to the insecurity of their networks. Events involving vulnerable Sony software or the manyrootkit fiascos are not included.

Jun 4 Update: Elinor Mills pointed out the 06/03 Europe database eventJun 4 Update: Kane Lightowler sent 20 legacy eventsJun 4 Update: Gene Spafford sent a link to his blog about his testimonyJun 4 Update: Several pointed out Sony rootkit drama. Updated note disclaiming scope of legacy tableJun 4 Update: @pctservices01 provided link about PS3 Hackers UnbanningJun 4 Update: Tuna informs me that Prolexic provided DDoS mitigation services onlyJun 5 Update: Peter Downey provided link about PS3 Hackers / Modern Warfare 2Jun 5 Update: Added SNE closing stock price for the day of each incident. Idea courtesy Ryan RussellJun 5 Update: @LulzSec points out two missing compromises on Jun 6Jun 5 Update: Sony Music Brazil defacement confirmed as happening ~ 2010-11-12, and remains unfixed since (thanks Kane Lightowler)Jun 6 Update: Added Network World's timeline for the PSN breachJun 6 Update: Added confirmation to Sony Russia, that @LulzSec was not responsibleJun 6 Update: Added clarification about LulzSec targeting elderly to 6/2 Sony Pictures incidentJun 6 Update: Added entry to cover the supposed news of a LulzSec member being arrestedJun 9 Update: Added link to DatalossDB for #14Jun 9 Update: Thanks to @MasafumiNegishi and @superspryte for translation helpJun 12 Update: Added original DDoS and REBUG links. Thanks Laurens Vets for REBUG info.Jun 18 Update: Alldas.de sent us a copy of their defacement mirror from ~ 2001. Updated the legacy list to include a lot of defacementsDec 8 2014 Update: Added new huge Sony Pictures breach as separate table, since three years later

http://attrition.org/security/rant/sony_aka_sownage.html