The 2011 PlayStation Network outage (sometimes referred to as the PSN Hack) was the result of an "external intrusion" on Sony's PlayStation Network and Qriocity services, in which personal details from approximately 77 million accounts were compromised and prevented users of PlayStation 3 and PlayStation Portable consoles from accessing the service.[1][2][3][4] The attack occurred between April 17 and April 19, 2011,[1] forcing Sony to deactivate the PlayStation Network servers on April 20. The outage lasted 23 days.[5]
Government officials in various countries voiced concern over the theft and Sony's one-week delay before warning its users. The breach resulted in the exposure and vulnerability of personally identifiable information including usernames, physical addresses, email addresses, dates of birth, passwords, and financial details such as credit card and debit card information.[6]
Extent of the breach
Personal details from approximately 77 million accounts were compromised and prevented users of PlayStation 3 and PlayStation Portable consoles from accessing the service.[1][2][3][4]
Credit card data was encrypted, but Sony admitted that other user information was not encrypted at the time of the intrusion.[7][8]The Daily Telegraph reported that "If the provider stores passwords unencrypted, then it's very easy for somebody else – not just an external attacker, but members of staff or contractors working on Sony's site – to get access and discover those passwords, potentially using them for nefarious means."[9]
On May 2, Sony clarified the "unencrypted" status of users' passwords, stating that:[10]
While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form.
On April 26, nearly a week after the outage, Sony confirmed that it "cannot rule out the possibility"[11] that personally identifiable information such as PlayStation Network account username, password, home address, and email address had been compromised. Sony also mentioned the possibility that credit card data was taken—after claiming that encryption had been placed on the databases, which would partially satisfy PCI Compliance for storing credit card information on a server.
Subsequent to the announcement on both the official blog and by e-mail, users were asked to safeguard credit card transactions by checking bank statements. This warning came nearly a week after the initial "external intrusion" and while the Network was turned off.[12]
At the time of the outage, with a count of 77 million registered PlayStation Network accounts,[13] it was not only one of the largest data security breaches, but also the longest PS Network outage in history.[14][15] It surpassed the 2007 TJX hack which affected 45 million customers.[16]
The attack, which may have leaked credit card details for millions of users, has never been traced to any group – although Sony suggested not long afterwards that Anonymous might have been involved.
Since then it has given no further details about who it suspects of carrying out the attack, and no data from the attack has ever been posted publicly.[17]
Timeline of the outage
April 20, 2011
Sony acknowledged on the official PlayStation Blog that it was "aware certain functions of the PlayStation Network" were down. Upon attempting to sign in via the PlayStation 3, users received a message indicating that the network was "undergoing maintenance".[18][19] The following day, Sony asked its customers for patience while the cause of outage was investigated and stated that it may take "a full day or two" to get the service fully functional again.[20] Sony suspended all PlayStation Network and Qriocity services worldwide.[21]
While most games remained playable in their offline modes, the PlayStation 3 was unable to play certain Capcom titles in any form. Streaming video providers throughout different regions such as Hulu, Vudu, Netflix and LoveFilm displayed the same maintenance message. Some users claimed to be able to use Netflix's streaming service[22] but others were unable.[23]
April 22, 2011
Sony announced an "external intrusion" had affected the PlayStation Network and Qriocity services.[24]
Sony expressed their regrets for the downtime and called the task of repairing the system "time-consuming" but would lead to a stronger network infrastructure and additional security.[25]
April 25, 2011
Sony spokesman Patrick Seybold reiterated on the PlayStation Blog that fixing and enhancing the network was a "time intensive" process with no estimated time of completion.[26] However, the next day Sony stated that there was a "clear path to have PlayStation Network and Qriocity systems back online", with some services expected to be restored within a week. Furthermore, Sony acknowledged the "compromise of personal information as a result of an illegal intrusion on our systems."[27]
April 26, 2011
On April 26, 2011, Sony explained on the PlayStation Blog why it took so long to inform PSN users of the data theft:[28]
There’s a difference in timing between when we identified there was an intrusion and when we learned of consumers’ data being compromised. We learned there was an intrusion April 19th and subsequently shut the services down. We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident. It was necessary to conduct several days of forensic analysis, and it took our experts until yesterday to understand the scope of the breach. We then shared that information with our consumers and announced it publicly this afternoon.
April 27, 2011
Sony to provide an update in regards to a criminal investigation in a blog posted on April 27: "We are currently working with law enforcement on this matter as well as a recognized technology security firm to conduct a complete investigation. This malicious attack against our system and against our customers is a criminal act and we are proceeding aggressively to find those responsible."[7]
May 1, 2011
Sony announced a "Welcome Back" program for customers affected by the outage. The company also confirmed that some PSN and Qriocity services would be available during the first week of May.[29][30]
May 2, 2011
Sony issued a press release, according to which the Sony Online Entertainment (SOE) services had been taken offline for maintenance due to potentially related activities during the initial criminal hack. Over 12,000 credit card numbers, albeit in encrypted form, from non-U.S. cardholders and additional information from 24.7 million SOE accounts may have been accessed.[31][32]
During the week, Sony sent a letter to the US House of Representatives, answering questions and concerns about the event.[33] In the letter Sony announced that they would be providing Identity Theft insurance policies in the amount of US$1 million per user of the PlayStation Network and Qriocity services, despite no reports of credit card fraud being indicated. This was later confirmed on the PlayStation Blog, where it was announced that the service, AllClear ID Plus powered by Debix, would be available to users in the United States free for 12 months, and would include Internet surveillance, complete identity repair in the event of theft and a $1 million identity theft insurance policy for each user.[34][35]
May 3, 2011
Sony Computer Entertainment CEO Kazuo Hirai reiterated said the "external intrusion" which had caused them to shut down the PlayStation Network constituted a "criminal cyber attack".[36] Hirai expanded further, claiming that Sony systems had been under attack prior to the outage "for the past month and half", suggesting a concerted attempt to target Sony.[37]
On May 3 Sony stated in a press release that there may be a correlation between the attack that had occurred on April 16 towards the PlayStation Network and one that compromised Sony Online Entertainment on May 2.[31] This portion of the attack resulted in the theft of information on 24.6 million Sony Online Entertainment account holders. The database contained 12,700 credit card numbers, particularly those of non-U.S. residents, and had not been in use since 2007 as much of the data applied to expired cards and deleted accounts. Sony updated this information the following day by stating that only 900 cards on the database were still valid.[38] The attack resulted in the suspension of SOE servers and Facebook games. SOE granted 30 days of free time, plus one day for each day the server was down, to users of Clone Wars Adventures, DC Universe Online, EverQuest, EverQuest II, EverQuest Online Adventures, Free Realms, Pirates of the Burning Sea, PlanetSide, Poxnora, Star Wars Galaxies and Vanguard: Saga of Heroes, as well as other forms of compensation for all other Sony Online games.
May 4, 2011
Sony announced that it was adding Data Forte to the investigation team of Guidance Software and Protiviti in analysing the attacks. Legal aspects of the case were handled by Baker & McKenzie.[39] Sony stated their belief that Anonymous, a decentralized unorganized loosely affiliated group of hackers and activists may have performed the attack.[40] No Anons claimed any involvement.[41]
May 6, 2011
Sony stated they had begun "final stages of internal testing" for the PlayStation Network, which had been rebuilt.[42] However, the following day Sony reported that they would not be able to bring services back online within the one-week timeframe given on May 1, because "the extent of the attack on Sony Online Entertainment servers" had not been known at the time.[43] SOE confirmed on their Twitter account that their games would not be available until some time after the weekend.[44]
Reuters began reporting the event as "the biggest Internet security break-in ever".[45] A Sony spokesperson said:[46]
Sony had removed the personal details of 2,500 people stolen by hackers and posted on a website
The data included names and some addresses, which were in a database created in 2001
No date had been fixed for the restart
May 14, 2011
Various services began coming back online on a country-by-country basis, starting with North America.[47] These services included: sign-in for PSN and Qriocity services (including password resetting), online game-play on PS3 and PSP, playback of rental video content, Music Unlimited service (PS3 and PC), access to third party services (such as Netflix, Hulu, Vudu and MLB.tv), friends list, chat functionality and PlayStation Home.[47] The actions came with a firmware update for the PS3, version 3.61.[48] As of May 15 service in Japan and East Asia had not yet been approved.[49]
May 18, 2011
Sony shut down the password reset page on their site following the discovery of another exploit[50] that allowed users to reset other users' passwords, using the other user's email address and date of birth.[51] Sign-in using PSN details to various other Sony websites was also disabled, but console sign-ins were not affected.[50]
May 23, 2011
Sony stated that the outage costs were $171 million.[52]
Reaction
Graham Cluley, senior technology consultant at Sophos, said the breach "certainly ranks as one of the biggest data losses ever to affect individuals".[53]
Security experts Eugene Lapidous of AnchorFree, Chester Wisniewski of Sophos Canada and Avner Levin of Ryerson University (now Toronto Metropolitan University) criticized Sony, questioning its methods of securing user data. Lapidous called the breach "difficult to excuse" and Wisniewski called it "an act of hubris or simply gross incompetence".[54][55][56][57]
Government reactions
US Senator Richard Blumenthal of Connecticut demanded answers from Sony about the data breach[58] by emailing SCEA CEO Jack Tretton arguing about the delay in informing its customers and insisting that Sony do more for its customers than just offer free credit reporting services. Blumenthal later called for an investigation by the US Department of Justice to find the person or persons responsible and to determine if Sony was liable for the way that it handled the situation.[59]
Congresswoman Mary Bono Mack and Congressman G. K. Butterfield sent a letter to Sony, demanding information on when the breach was discovered and how the crisis would be handled.[60]
Privacy Commissioner of CanadaJennifer Stoddart confirmed that the Canadian authorities would investigate. The Commissioner's office conveyed their concern as to why the authorities in Canada weren't informed of a security breach earlier.[61]
Following a formal investigation of Sony for breaches of the UK's Data Protection Act 1998, the Information Commissioner's Office fined Sony £250,000 ($395k) and issued a statement highly critical of the security Sony had in place:
If you are responsible for so many payment card details and log-in details then keeping that personal data secure has to be your priority. In this case that just didn't happen, and when the database was targeted – albeit in a determined criminal attack – the security measures in place were simply not good enough.
There's no disguising that this is a business that should have known better. It is a company that trades on its technical expertise, and there's no doubt in my mind that they had access to both the technical knowledge and the resources to keep this information safe.[62]
Legal action against Sony
A lawsuit was posted on April 27 by Kristopher Johns from Birmingham, Alabama on behalf of all PlayStation users alleging Sony "failed to encrypt data and establish adequate firewalls to handle a server intrusion contingency, failed to provide prompt and adequate warnings of security breaches, and unreasonably delayed in bringing the PSN service back online."[63][64] According to the complaint filed in the lawsuit, Sony failed to notify members of a possible security breach and storing members' credit card information,[65] a violation of PCI Compliance—the digital security standard for the Payment Card Industry.
A Canadian lawsuit against Sony USA, Sony Canada and Sony Japan claimed damages up to C$1 billion including free credit monitoring and identity theft insurance.[66] The plaintiff was quoted as saying, "If you can't trust a huge multi-national corporation like Sony to protect your private information, who can you trust? It appears to me that Sony focuses more on protecting its games than its PlayStation users".[67]
In October 2012 a California judge dismissed a lawsuit against Sony over the PSN security breach, ruling that Sony had not violated California's consumer-protection laws, citing "there is no such thing as perfect security".[68]
Compensation to users
In a press conference in Tokyo on May 1, Sony announced a "Welcome Back" program. As well as "selected PlayStation entertainment content" the program promised to include 30 days free membership of PlayStation Plus for all PSN members, while existing PlayStation Plus members received an additional 30 days on their subscription. Qriocity subscribers received 30 days. Sony promised other content and services over the coming weeks.[30]
Hulu compensated PlayStation 3 users for the inability to use their service during the outage by offering one week of free service to Hulu Plus members.[69]
On May 16, 2011, Sony announced that two PlayStation 3 games and two PSP games would be offered for free from lists of five and four,† respectively.[70][71] The games available varied by region[70][71] and were only available in countries which had access to the PlayStation Store prior to the outage.[71] On May 27, 2011, Sony announced the "welcome back" package for Japan[72] and the Asia region (Hong Kong, Singapore, Malaysia, Thailand and Indonesia).[73] In the Asia region, a theme - Dokodemo Issyo Spring Theme - was offered for free in addition to the games available in the "welcome back" package.[73]
^† 5 PSP games are offered in the Japanese market.[72]
^‡ Version of Killzone Liberation offered does not offer online gameplay functionality.[71]
Credit card fraud
There were reports on the Internet that some users experienced credit card fraud;[74][75][76] however, they were yet to be linked to the incident. Sony said that the CSC codes requested by their services were not stored,[77] but hackers may have been able to decrypt or record credit card details while inside Sony's network.[74]
On May 5, a letter from Sony Corporation of America CEO and President Sir Howard Stringer emphasized that there had been no evidence of credit card fraud and that a $1 million identity theft insurance policy would be available to PSN and Qriocity users.[35]
Sony PlayStation Controversies during a similar timeframe
In March 2010, Sony launched a firmware update for the PlayStation 3 which removed the ability to install third-party operating systems like Linux.[78][79] This move sparked significant backlash from the modding community.
George Hotz, also known as Geohot, managed to jailbreak the PS3 firmware on January 2, 2011, and began sharing the jailbreak online shortly afterward.[80] In response, Sony sued Hotz on January 11, 2011, for his jailbreaking activities.[81]
The hacker group Anonymous initiated "Operation Sony" on April 2, 2011, as a form of protest.[79] Sony eventually settled the lawsuit with Hotz by April 11.[82] Following this, Anonymous called for a public protest against Sony on April 13.[79]
American television personality Danielle StaubStaub in September 2011BornBeverly Ann Merrill[1] (1962-07-29) July 29, 1962 (age 61)[2]Wayne, New Jersey, U.S.[3]OccupationTelevision personalityYears active2001–presentSpouses Kevin Maher (m. 1986; div. 1987) Thomas Staub (m. 1993; div. 2007) Marty Caffrey (m. 2018; div....
This article is about the city. For the province, see Nakhon Ratchasima province. Khorat redirects here. For other uses, see Khorat (disambiguation). This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Nakhon Ratchasima – news · newspapers · books · scholar · JSTOR (April 2016) (Learn how and when to remove this...
Terremoto de Chillán de 1939 7,8[1] en potencia de Magnitud de Momento (MW)ParámetrosFecha y hora 24 de enero de 1939[2]Tipo Falla normal, intraplaca (Nazca)[3]Profundidad 60;[2] 80-100[3] km.Duración 60s[3]Coordenadas del epicentro 36°12′S 72°12′O / -36.2, -72.2ConsecuenciasZonas afectadas Provincias de Talca, Maule, Linares, Ñuble, Concepción, Arauco y Biobío, en ChileVíctimas Más de 30 000 muertos según cifras de...
Bids for the 2024 (2024) Summer Olympics and ParalympicsOverviewGames of the XXXIII Olympiad XVII Paralympic GamesDetailsCityHamburg, GermanyNOCGerman Olympic Sports FederationPrevious Games hosted The Hamburg bid for the 2024 Summer Olympics (Low Saxon: Hamborg 2024) was a cancelled bid of Hamburg to host the 2024 Summer Olympics. A referendum on 29 November 2015 rejected the bid.[1] Bid history In October 2012, Thomas Bach, president of the IOC, stated that Hamburg will apply f...
Race car model developed for Le Mans Toyota TS050 HybridThe Toyota TS050 Hybrid on display at the 2018 Osaka Auto MesseCategoryLMP1-HConstructorToyotaDesigner(s)Pascal Vasselon[1]PredecessorToyota TS040 HybridSuccessorToyota GR010 HybridTechnical specificationsCompetition historyNotable entrants Toyota Gazoo RacingNotable drivers Kazuki Nakajima Mike Conway Anthony Davidson Stéphane Sarrazin Sébastien Buemi Kamui Kobayashi Yuji Kunimoto Nicholas Lapierre José María López Fernando...
جائزة الشخصية الشجاعةمعلومات عامةالبداية 1989 الاسم الرسمي The John F. Kennedy Profile in Courage Award (بالإنجليزية) [1][2] الاسم الأصل John F. Kennedy Profile in Courage Award (بالإنجليزية) [1][2] الاسم المختصر Profile in Courage Award (بالإنجليزية) [1] سُمِّي باسم جون كينيدي[1] البلد الولايات المتحدة تم
Penaklukan kota Astartu (dianggap sebagai Asyterot di tanah raja Og dari Bashan, timur Sungai Yordan), oleh raja Asyur Tiglath-Pileser III pada sekitar tahun 730–727 SM, digambarkan di relief istana yang kini disimpan di British Museum.[1] Asyterot-Karnaim (Ibrani: עַשְׁתְּרֹת קַרְנַיִם ʿAštərōṯ Qarnayīm), juga disebut sebagai Asytarot-Karnaim, adalah sebuah kota di tanah Bashan di timur Sungai Yordan. Asyterot-Karnaim disebutkan dalam Kitab Kejadian (...
Genus of fishes Ilyodon Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Chordata Class: Actinopterygii Order: Cyprinodontiformes Family: Goodeidae Subfamily: Goodeinae Genus: IlyodonC. H. Eigenmann, 1907 Type species Ilyodon paraguayense, a synonym of Ilyodon furcidensEigenmann. 1907[1] Ilyodon is a genus of splitfins found in the Pacific slope river basins of Balsas, Tuxpan (Coahuayana), Purificación, Chacala (Marabasco), Armería and Ameca in western Mexico. S...
Diving competition Men's 3 metre springboard at the 2022 Asian GamesVenueHangzhou Olympic Sports Expo CenterDate3 OctoberCompetitors17 from 12 nationsMedalists Wang Zongyuan China Zheng Jiuyuan China Yi Jae-gyeong South Korea← 20182026 → Diving at the2022 Asian Games1 m springboardmenwomen3 m springboardmenwomen10 m platformmenwomenSynchro 3 m springboardmenwomenSynchro 10 m platformmenwomenvte Main ...
Connie SutedjaConnie di Madjalah Aktuil Edisi 37 Tahun 1969LahirSukarni10 November 1944 (umur 79)Tasikmalaya, Masa Pendudukan JepangNama lainConnie SutedjaPekerjaanPemeranmodelTahun aktif1965—sekarangAnak1 Sukarni binti Sutedja (lahir 10 November 1944), lebih dikenal sebagai Connie Sutedja[1] adalah pemeran dan model Indonesia. Ia merupakan salah satu dari empat anggota Golden Girls bersama Nani Widjaja, Ida Kusumah dan Rina Hassim. Filmografi Film Tahun Judul Peran C...
Memoir by Jon Roberts American Desperado Front coverAuthorJon Roberts and Evan WrightCountryUnited StatesLanguageEnglishGenreMemoir, Crime, MilitaryPublisherCrownPublication dateNovember 1, 2011Media typeHardcover, EbookPages512ISBN978-0-307-45042-5 American Desperado is a 2011 book written by journalist Evan Wright and drug smuggler Jon Roberts, a subject of the 2006 documentary Cocaine Cowboys. Synopsis American Desperado is the reminiscences of Jon Roberts (born John Riccobono), conne...
Hierocracy redirects here. For the medieval theory, see Hierocracy (medieval).For other uses, see Theocracy (disambiguation). Form of government with religious leaders Roman emperor Augustus as Jupiter, holding scepter and orb (first half of 1st century AD).[1] Part of the Politics seriesBasic forms of government List of forms of government Source of power Democracy (rule by many) Demarchy Direct Liberal Representative Social Socialist Others Oligarchy (rule by few) Anocracy Aristocra...
السفارة السعودية في سلطنة عمان السعودية عمان الإحداثيات 23°36′19″N 58°25′48″E / 23.6052°N 58.4299°E / 23.6052; 58.4299 البلد سلطنة عمان المكان مسقط العنوان حي السفارات – شاطئ القرم – شارع جامعة الدول العربية السفير عبد الله بن سعود العنزي الموقع الالكتروني سفارة المملكة ا...
For the university known as Texas Wesleyan College from 1934 to 1989, see Texas Wesleyan University. Fort Worth University1908 postcard depicting the 3 buildings of the universityFormer nameTexas Wesleyan College (1881–1889)TypeprivateActiveJune 6, 1881 (1881-06-06)–1911Religious affiliationMethodist Episcopal ChurchLocationFort Worth, Texas, United States Fort Worth University was a college in Fort Worth, Texas operated from 1881 until 1911. Founded as Texas Wesleyan Colle...
British-Japanese skateboarder Sky Brownスカイ・ブラウンBrown at the 2020 Lausanne Youth Olympic VillagePersonal informationBorn (2008-07-07) 7 July 2008 (age 15)Miyazaki, JapanYears active2016–presentJapanese nameKanjiブラウン 澄海Kanaブラウン スカイ SportCountryGreat BritainSportSkateboardingPositionGoofy footedRank2nd (June 2021)[1]EventPark Medal record Women's park skateboarding Representing Great Britain Olympic Games 2020 Tokyo Park World C...
For the National Football League kicker, see John Potter (American football). John E. PotterPresident and Chief Executive Officer of the Metropolitan Washington Airports AuthorityIncumbentAssumed office July 18, 2011Preceded byLynn Hampton72nd United States Postmaster GeneralIn officeJune 1, 2001 – December 6, 2010PresidentGeorge W. BushBarack ObamaPreceded byWilliam J. HendersonSucceeded byPatrick R. Donahoe Personal detailsBorn1956 (age 66–67)New York City, U.S.Pol...
Hospital in ScotlandCowal Community HospitalNHS HighlandCowal Community HospitalShown in Argyll and ButeGeographyLocationArgyll Street, Dunoon, Argyll and Bute, Scotland, United KingdomCoordinates55°57′33″N 4°55′40″W / 55.959257°N 4.9277880°W / 55.959257; -4.9277880OrganisationCare systemPublic NHSTypeCommunity HospitalServicesEmergency departmentYes Accident & EmergencyBeds14HistoryOpened1885LinksWebsiteCowal Community HospitalListsHospitals in Scotlan...
Variety of grape Coda di Pecora is a white Italian wine grape variety that is grown in the Campania region of southern Italy, particularly in the province of Caserta. The name Coda di Pecora means goat's tail in the local dialect and for many years was thought to be a clonal variation of another white Campanian variety, Coda di Volpe, whose name means foxtail.[1] History The name Coda di Pecora translates to goat's tail in the local Campanian dialect and is thought to be a reference t...
Halaman ini berisi artikel tentang unsur kimia. Untuk kegunaan lain, lihat Uranium (disambiguasi). Uranium, 92UUranium yang diperkaya tinggi Garis spektrum uraniumSifat umumNama, lambanguranium, UPengucapan/uranium/[1] Penampilanmetalik abu-abu keperakan; teroksidasi menjadi hitam ketika terpapar dengan udaraUranium dalam tabel periodik Hidrogen Helium Lithium Berilium Boron Karbon Nitrogen Oksigen Fluor Neon Natrium Magnesium Aluminium Silikon Fosfor Sulfur Clor Argon...