Breach report
GamingSony (PlayStation Network)
PlayStation Network Hacked: User Data Compromised
Hackers broke into Sony's PlayStation Network in April 2011, stealing personal data tied to about 77 million accounts and forcing the gaming service offline for more than three weeks.
Reported by SecurityWeek
Records exposed
77M
About 77 million accounts
Scale vs. largest on file
- When
- 2011
- How they got in
- Network intrusion into PlayStation Network servers
- Sector
- Gaming
Between April 17 and 19, 2011, intruders gained access to the servers behind Sony's PlayStation Network and its Qriocity music and video service. On April 20, Sony abruptly took both services offline, leaving millions of gamers unable to play online or buy content. It did not tell users that their personal information had been compromised until April 26, a delay that drew sharp criticism from customers and US lawmakers.
Sony said the attackers had obtained names, postal addresses, email addresses, dates of birth, PlayStation Network passwords and logins, and online handles for about 77 million accounts. It warned that profile data including purchase history, billing addresses and password security answers might also have been taken, and that it could not rule out that credit card numbers and expiration dates had been accessed, although card data was stored in encrypted form. Days later, Sony disclosed a related intrusion at Sony Online Entertainment that exposed data on roughly 24.6 million more accounts.
The outage stretched on for more than three weeks, with services gradually restored starting in mid-May after Sony rebuilt its systems and added new security measures. Executives, including then-deputy president Kazuo Hirai, publicly apologized, and the company offered affected users free games, a month of its premium service and identity theft protection. Sony later estimated the cost of the breach at around $171 million. The attackers were never publicly identified, although Sony pointed to a file left on its servers referencing the hacker collective Anonymous, which denied involvement.
Regulators and courts followed. In 2013 the UK Information Commissioner's Office fined Sony Computer Entertainment Europe £250,000, concluding that the attack could have been prevented with up-to-date software and better password protection. In the United States, Sony agreed to a class-action settlement offering games, service credits and reimbursement for identity theft losses.
The PlayStation Network breach was one of the first mass-market data breaches to directly disrupt a consumer service used daily by tens of millions of people. It became a reference point for incident communication, as the six-day gap between shutdown and disclosure fueled calls for faster breach notification. It also showed that gaming platforms, with their stored payment details and vast user bases, are high-value targets on par with retailers and banks.