GameSpot may receive revenue from affiliate and advertising partnerships for sharing this content and from purchases through links.

Sony answers Congress' questions, details PSN attack

Complete account of PlayStation Network outage offered; info stolen from all 77 million PSN accounts; no fraudulent credit card transactions reported; Anonymous possible culprit.

954 Comments

Yesterday, Sony said it would answer a list of detailed questions presented by a US Congressional subcommittee looking into the PlayStation Network outage and data leak. Today, the company offered up its answers, which gave a detailed timeline of the data breach and subsequent downtime resulting from the cyberattack. Unfortunately, one of the responses confirmed the worst-case scenario--that all 77 million PlayStation Network and Qriocity service accounts had data stolen from them.

Sony has now officially confirmed that all 77 million PSN accounts had data stolen from them.
Sony has now officially confirmed that all 77 million PSN accounts had data stolen from them.

In a letter sent to the subcommittee--which can be viewed in its entirety here--Sony Computer Entertainment America chairman and Sony Corp. executive vice president Kaz Hirai offered a detailed timeline of the aforementioned attack. The saga began at 4:15 p.m. PDT on April 19, when employees of Sony Network Entertainment America, which took over PSN operations in March, noticed that "certain systems were rebooting when they were not scheduled to do so."

The following day, SNEA noticed "evidence that indicated an unauthorized intrusion had occurred and that data of some kind had been transferred off the PlayStation Network servers without authorization." However, SNEA couldn't determine exactly what type of information had been taken, so it then took down the PSN as a precaution.

Also on April 20, Sony called in an external computer forensics firm to look into the incident. To complete the investigation, the firm had to mirror all the servers that had been hacked, which was a time-intensive process. The investigation grew even more complex once the full extent of the attack became clear, causing Sony to enlist a second computer security company to help in the investigation on April 21.

It took until the afternoon of April 22 for the two firms to complete the mirroring of nine of the 10 servers that had been compromised. It then took until the following evening (April 23) for the two companies to confirm that "intruders had used very sophisticated and aggressive techniques to obtain unauthorized access, hide their presence from system administrators, and escalate privileges inside servers." The intruders deleted log files to cover their tracks, Sony said.

By April 24--Easter Sunday--Sony said it had realized it was dealing with a "sophisticated hacker" and called in a third outside firm to "determine the scope of the data theft." By Monday, April 25, all three teams could confirm the scale of the personal data that had been stolen, but couldn't say definitively whether or not credit card information had been taken as well.

The following day, Sony announced to the public that personal--and possibly credit card data--had been compromised. Hirai's letter then confirmed that "information appears to have been stolen from all PlayStation Network user accounts, although not every piece of information in those accounts appears to have been stolen. The criminal intruders stole personal information from all of the approximately 77 million PlayStation Network and Qriocity accounts."

Of the 77 million, some 12.3 million account holders had credit card information on file, with 5.6 million being in the US. (Those numbers include active and expired credit card accounts.) Luckily, Hirai said that, to date, "the major credit card companies have not reported that they have seen any increase in the number of fraudulent credit card transactions as a result of the attack." Last week, Wells Fargo, American Express, and MasterCard gave a similar account to the press.

The good news is that Hirai said that Sony now believes it has indentified the cause of the breach. However, the company does not want to make the information public out of security concerns. It has, however, taken a variety of steps to beef up security, including moving its servers to a new facility, adding additional firewalls, enhancing data encryption and protection, and increasing automated software monitoring.

When asked if Sony had indentified the individuals behind the attack, Hirai answered with a flat, "No." However, he did say that when Sony Online Entertainment discovered its own data theft this past Sunday, intruders had "planted a file on one of those [compromised] servers named 'Anonymous' with the words 'We are Legion.'" Though it was openly behind attacks on the PSN in early April, the hacker collective known as Anonymous has denied sanctioning the attack that has now kept the PSN down for two weeks. However, the loose nature of the collective, which has no official leaders, means that rogue elements could be behind the intrusion.

Got a news tip or want to contact us directly? Email news@gamespot.com

Join the conversation
There are 954 comments about this story
954 Comments  RefreshSorted By 
GameSpot has a zero tolerance policy when it comes to toxic conduct in comments. Any abusive, racist, sexist, threatening, bullying, vulgar, and otherwise objectionable behavior will result in moderation and/or account termination. Please keep your discussion civil.

Avatar image for Superzone
Superzone

3733

Forum Posts

0

Wiki Points

0

Followers

Reviews: 54

User Lists: 0

Ugh, it's been two weeks....

Upvote • 
Avatar image for Jman251
Jman251

86

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Just My Two Cents: 1) SONY PSN was attacked by hackers. (Main reason we all can't play online!) 2) SONY should have taken better measures to prevent this situation from happening in the first place. 3)Am I mad at SONY? No, I'm mad at the hackers. 4) Am I Dissapointed with SONY? Yes. I think the matter could have been handled alil better and to some degree prevented. 5) Am I content with "Welcome Back" package? Somewhat. Sony didn't have to give us anything cuz they were a victim of a cyber attack. So free stuff for my time not being able to play online helps. Yet, it doesn't make up for the fact that SONY didn't protect my personal info better.

Upvote • 
Avatar image for caketoo
caketoo

1783

Forum Posts

0

Wiki Points

0

Followers

Reviews: 12

User Lists: 0

This is what happens when theres all this free time. We get engaged in speculation. I cant wait til people get charged for PS Plus after the free 30 days cause it auto re-news and most people prob wont see that part. Of course whos gonna leave there CC info stored now.

Upvote • 
Avatar image for wickdawg01
wickdawg01

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 16

User Lists: 0

All of you conspiracy theorists crack me up. Pretty much what this world is transforming into anymore. Anytime something major happens the conspiracy people come crawling outta the wood work telling "what they believe". Next thing you know, they have a nice following and everyone is on board. Give me a break

Upvote • 
Avatar image for MrJellyfish
MrJellyfish

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@Takashi_Miike It's no coincidence Anonymous hacks PSN several days before this happens. I'm of the opinion Anonymous is related to the entire outage. Now it's a matter if whether Anonymous will turn up it's own 'rogue' hackers responsible for the theft...

Upvote • 
Avatar image for Takashi_Miike
Takashi_Miike

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

"Remember These hackers did not do this to show that it could be done. Then to brag about it. No these hackers did it to steal your/ours personnel identification and use it for malicious means" At the moment though that statement is just completely innacurate. They left a note saying it was them (if indeed its not another group trying to throw people off the correct trail) and so far there hasnt been a single reported case of any details being used for criminal activity

Upvote • 
Avatar image for Takashi_Miike
Takashi_Miike

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

"If you ask me, the Anonymous should be put in jail. Maybe they didn't do it after all, but we know they're not saints, and you gotta know that, when you look like a thief, when you walk among thiefs, when you do some thief stuff, well, people will most likely confuse you with a thief and put you in jail anyway." I know Americans are pretty fond of locking people up with no evidence but you cant actually think this is a good idea. Anonymous seem like the types that if they did it, they would say they did it. Thats the whole point, to look big and scary. This whole thing has got stitch up written all over it. What better time for some criminal hackers to nip in and steal peoples details than just after a known hacker group have said they will launch an attack on Sony. Plus you do realize theyre called 'Anonamous' for a reason right? Meaning noone knows who they are

Upvote • 
Avatar image for henrikimaru
henrikimaru

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

paranormalnut I don't know if it is stupid or not. But, I can't imagine how the people can blame the victmin for what happened the it.

Upvote • 
Avatar image for SuicideSekt
SuicideSekt

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 5

User Lists: 0

I dont car eanymore, i changed my bank card and everything! I'm just waiting for the network to be back up!!!! TICK TOCK TICK TOCK!

Upvote • 
Avatar image for elkornu
elkornu

108

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

first psn then sony online entertainment damn sony u got served

Upvote • 
Avatar image for paranormalnut
paranormalnut

802

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@henrikimaru That was stupid to post..

Upvote • 
Avatar image for sdhanna88
sdhanna88

27

Forum Posts

0

Wiki Points

0

Followers

Reviews: 24

User Lists: 0

BURRNN lol

Upvote • 
Avatar image for paranormalnut
paranormalnut

802

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

'We are Legion.'" Sone one knows the Bible..

Upvote • 
Avatar image for slippship
slippship

280

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

@CHROMEFLAMIN Sony haven't upset me in the slightest, or done anything that has taken away my enjoyment of my systems, of which I have three of the current generation. This thread is purely opinion based and for the most part wiki is made up, do you copy your homework from there as well?

Upvote • 
Avatar image for henrikimaru
henrikimaru

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

If you blame Sony for the attack it suffered, then you'll have to blame the government U.S. for the attack of September 11. And if you ever murdered, you will have to blame yourself for failing to defend yourself against the aggressor. Simple as that.

Upvote • 
Avatar image for DAVEYBOY1987
DAVEYBOY1987

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

why dont all you xbox players naff of and let us ps3 users discuss our problem between ourselves, why the F*** av you got to get involved when its F*** all to do with you and doesnt affect you in any way

Upvote • 
Avatar image for CHROMEFLAMIN
CHROMEFLAMIN

1902

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@slipship "And they've never put a foot wrong" Uh oh... << LINK REMOVED >><< LINK REMOVED >> Nice try grammar nazi

Upvote • 
Avatar image for slippship
slippship

280

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

@CHROMEFLAMIN LAID your hand on! Your diction, and opinions, are plain ridiculous.

Upvote • 
Avatar image for BxBadBoy69
BxBadBoy69

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

The only thing good that came out of this is that, our military finally put there joysticks down and got Osama!!!

Upvote • 
Avatar image for Darthree
Darthree

65

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@MrJellyfish dude ur right i jst cant understand y some people get pissed at sony.

Upvote • 
Avatar image for sdhanna88
sdhanna88

27

Forum Posts

0

Wiki Points

0

Followers

Reviews: 24

User Lists: 0

sure you do....

Upvote • 
Avatar image for CHROMEFLAMIN
CHROMEFLAMIN

1902

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@sdhanna88 Yeah a fanboi of common sense. I know how terrible sony is, I own a PS 3. Worst console I have ever layed my hands on.

Upvote • 
Avatar image for Mcgnnis1
Mcgnnis1

811

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

Goddamn those bloody hackers...thanks to your idiocy..we gamers are suffering...

Upvote • 
Avatar image for slippship
slippship

280

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

@CHROMEFLAMIN THERE as in over there! THEY'RE as in THEY ARE! THEIR as in their past history! Lesson over, my past history with PS goes back to '96 and they've never put a foot wrong. This isn't their fault either in my mind; it's just idiot boys in a basement eating burgers. And the PS3 can use the internet fine thanks, but the online gaming function PSN is down so we can't play online. And just to let you know, my XBOX is sat next to my PS3 and is still gathering dust.

Upvote • 
Avatar image for sdhanna88
sdhanna88

27

Forum Posts

0

Wiki Points

0

Followers

Reviews: 24

User Lists: 0

where did you read may 3rd? i only read sometime this week and psn store by the end of the month

Upvote • 
Avatar image for TomBergman909
TomBergman909

467

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Sony said themselves that PSN would be up and running by May 3rd its now May 5th. They should offer us a Free game that we can 'own" reguardless if your a PS+ memeber.

Upvote • 
Avatar image for sdhanna88
sdhanna88

27

Forum Posts

0

Wiki Points

0

Followers

Reviews: 24

User Lists: 0

@CHROMEFLAMIN.....clearly a fanboy.....so sad

Upvote • 
Avatar image for MrJellyfish
MrJellyfish

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Sony didn't do anything wrong. No system is hack-proof. It can, and will, happen anywhere to anyone.

Upvote • 
Avatar image for CHROMEFLAMIN
CHROMEFLAMIN

1902

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@Fabolous206 Sony does not know what there doing. Look at there past history, time and time again. At best you can just chalk that date up as another one of sonys lies.

Upvote • 
Avatar image for SpideR_CentS
SpideR_CentS

4766

Forum Posts

0

Wiki Points

0

Followers

Reviews: 8

User Lists: 0

Just glad my credit union didn't charge me a fee to change my cards. I do feel sorry for you guys with only one system or with that brand new game you wanted to play online. Be patient. And hope that when PSN comes back online, Sony has secured it better then before.

Upvote • 
Avatar image for Fabolous206
Fabolous206

161

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I thought we were getting PSN back on May 3rd, so what happened with that?

Upvote • 
Avatar image for 2prize
2prize

45

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

I blame Osama!!! Oh I can't do that anymore.. I blame Gaddafi!!!

Upvote • 
Avatar image for Leir_Bag
Leir_Bag

314

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

I can't believe people are still blaming Sony for all that happened. Yes, maybe Sony needs to be slapped on the face for some sucky security matters, but still, blame the hackers for not being able to play for the past two weeks, not Sony. I know what happens now. The Anonymous will say "we didn't do it", Sony will say "yes you did" and it'll start all over again. If you ask me, the Anonymous should be put in jail. Maybe they didn't do it after all, but we know they're not saints, and you gotta know that, when you look like a thief, when you walk among thiefs, when you do some thief stuff, well, people will most likely confuse you with a thief and put you in jail anyway. And the worst part is that I'm having a feeling that I'll have to pay to play on PSN in a not so distant future, and that just sucks.

Upvote • 
Avatar image for BoneyHead95
BoneyHead95

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Sony lost so mach money out of this! I hope there stop this and get PSN back up and running. And get the hackers and make them pay! :D

Upvote • 
Avatar image for steve4123456789
steve4123456789

412

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Heard a rumor its been hacked again. just in the passed few days, no jokes.

Upvote • 
Avatar image for Agreb91
Agreb91

7169

Forum Posts

0

Wiki Points

0

Followers

Reviews: 28

User Lists: 0

This hack is certainly going to hurt Sony, not only with consumer trust but also growing the PSN to get more exclusives and content.

Upvote • 
Avatar image for awheaten
awheaten

833

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Can't stay long today. Just looking at some of the comments. I've learned that there are some really immature people out there. Like its ok to be funny. But, to try and be funny and be wrong is another. For example, people blaming Sony for hackers hacking their system for our data that no one know if they really have. But, blaiming Sony for that is like you leaving a gold watch at my house (for what ever reason) for example, then someone came and stole the watch. Is it my fault that your watch is gone, especially if I locked the door that night? I'd like to see you win that one in court.

Upvote • 
Avatar image for elancion
elancion

295

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@mapmaker187, you can still just type in your user name. thats what i did to login.

Upvote • 
Avatar image for StingrayX5
StingrayX5

634

Forum Posts

0

Wiki Points

0

Followers

Reviews: -1

User Lists: 0

@dizzyracer I third that, Kesarion is a waste of oxygen

Upvote • 
Avatar image for awheaten
awheaten

833

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@dizzyracer I'd second that...

Upvote • 
Avatar image for dizzyracer
dizzyracer

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@Kesarion You're a douche.

Upvote • 
Avatar image for Insomniak1
Insomniak1

29

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@the_guard: Hm, I'm not for conspiracy theories, but your point has some merit. I don't believe they weren't hacked, but Sony has fueled a lot of distrust just by the half-baked communication they provide. And looking at it from "let's turn this incident into a promotion for PS+ and Qriocity", rather that truly "make good" with their customer base seems kind of industry standard practices. Nothing ever is in reality given "free" from a business standpoint, this "cost" will be covered by new continued subscriptions to PS+ and Qriocity and of course by the games we buy for the PS3.

Upvote • 
Avatar image for weatherman2006
weatherman2006

59

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

The hack is epic, who got nailed down as the mastermind behind this is gonna stay behind bars for centuries....

Upvote • 
Avatar image for deactivated-5c13ed0e6897f
deactivated-5c13ed0e6897f

506

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Apparently firmware update 3.61 is up in Japan or will be soon. Sony is waiting to get this update out to each country, and once everyone has gotten it they should be bringing up the servers. A glimmer of hope?

Upvote • 
Avatar image for Quandry
Quandry

132

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Remember These hackers did not do this to show that it could be done. Then to brag about it. No these hackers did it to steal your/ours personnel identification and use it for malicious means. I hope these cowards are caught and are used as a example to others that when you do malicious activity with the intent to do harm to others that the worst possible punishment be awarded to you.

Upvote • 
Avatar image for Cthulad
Cthulad

197

Forum Posts

0

Wiki Points

0

Followers

Reviews: 7

User Lists: 0

All I want to say is that it is too bad, that they went down, and the security was breached. I remember someone refering this as to a modern day mugging. It pretty much feels like it at times. The only thing I don't think should happen is Sony getting sued for breach of security. Banks get robbed, and stuff, but they don't get sued. There really was nothing they could have done about the breach except what they did. It takes time to find out what happens, and monitoring the system 24-7 is what they were doing. Hackers are smart, arrogant, and selfish, but know what, and how to do what they do. I don't like them, and know you can not trust one. It's just a sad, sad time for all of gamers not able to get back onlint, and feel ou security has been removed. It is a new world mugging. 77 million people mugging.

Upvote • 
Avatar image for gothic_kane
gothic_kane

58

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

I have to agree with DragonRift on this yes Sony failed big time but a majority of blame lies with the hackers! I waited 4 years b4 I got a PS3 which has now been unused for two weeks with PSN down. Not that I have to be on PSN but I do use both HOME and BLACK OPS neither of which i can use right now

Upvote •