Skip to main content
Breach Signal

Breach report

Gaming

Sony (PlayStation Network)

PlayStation Network Hacked: User Data Compromised

Hackers broke into Sony's PlayStation Network in April 2011, stealing personal data tied to about 77 million accounts and forcing the gaming service offline for more than three weeks.

Reported by SecurityWeek

Records exposed

77M

About 77 million accounts

Scale vs. largest on file

When
2011
How they got in
Network intrusion into PlayStation Network servers
Sector
Gaming

Between April 17 and 19, 2011, intruders gained access to the servers behind Sony's PlayStation Network and its Qriocity music and video service. On April 20, Sony abruptly took both services offline, leaving millions of gamers unable to play online or buy content. It did not tell users that their personal information had been compromised until April 26, a delay that drew sharp criticism from customers and US lawmakers.

Sony said the attackers had obtained names, postal addresses, email addresses, dates of birth, PlayStation Network passwords and logins, and online handles for about 77 million accounts. It warned that profile data including purchase history, billing addresses and password security answers might also have been taken, and that it could not rule out that credit card numbers and expiration dates had been accessed, although card data was stored in encrypted form. Days later, Sony disclosed a related intrusion at Sony Online Entertainment that exposed data on roughly 24.6 million more accounts.

The outage stretched on for more than three weeks, with services gradually restored starting in mid-May after Sony rebuilt its systems and added new security measures. Executives, including then-deputy president Kazuo Hirai, publicly apologized, and the company offered affected users free games, a month of its premium service and identity theft protection. Sony later estimated the cost of the breach at around $171 million. The attackers were never publicly identified, although Sony pointed to a file left on its servers referencing the hacker collective Anonymous, which denied involvement.

Regulators and courts followed. In 2013 the UK Information Commissioner's Office fined Sony Computer Entertainment Europe £250,000, concluding that the attack could have been prevented with up-to-date software and better password protection. In the United States, Sony agreed to a class-action settlement offering games, service credits and reimbursement for identity theft losses.

The PlayStation Network breach was one of the first mass-market data breaches to directly disrupt a consumer service used daily by tens of millions of people. It became a reference point for incident communication, as the six-day gap between shutdown and disclosure fueled calls for faster breach notification. It also showed that gaming platforms, with their stored payment details and vast user bases, are high-value targets on par with retailers and banks.

More from the wire

More in Gaming.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.