Sony's data breach expands to SOE servers

By Peter Smith  2 comments

Things went from bad to worse for Sony (and its customers) yesterday. In addition to the ongoing effort to recover from the PSN data breach and outage, now Sony Online Entertainment has discovered that some of its data, too, was compromised. Let's look at each situation in turn.

SCEA (the Sony PS3/PSN branch) posted another update to the Playstation blog attempting to clear up some of the misinformation being spread about the breach. One story that has been making the rounds is that a group of crackers offered to sell the stolen data back to Sony. On the blog Sr. Director, Corporate Communications & Social Media Patrick Seybold clarified:

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

(My understanding is that the rumor was started when a security expert lurking in an IRC channel or forum frequented by crackers saw some anonymous users making this claim. The expert relayed the story, emphasizing that he had no knowledge of whether or not the info was legitimate, but of course the internet ran with it, leaving his caveats in the dust.)

Seybold also clarified the situation with the passwords that were stolen. Sony said the information wasn't encrypted, which led to many blog commenters deriding the company for storing passwords in clear text. Seybold wanted to make users aware that the passwords were not encrypted but they were hashed (pretty standard practice for passwords). The rest of the personal data was in clear text, though.

Seybold also reiterated Sony's apology to its users.

So now let's talk about Sony Online Entertainment. This is the branch of Sony that runs, among other things, MMOs like Everquest 2, Free Realms and DC Universe Online. The SOE servers were in the same data center as the PSN servers but were otherwise separate systems, but in the course of investigating the PSN breach it was discovered that there'd been an intrusion into the SOE servers as well (part of the same attack).

The SOE system was immediately taken down, and as of the time of this writing (Tuesday morning) remains down. They've put up a web page to keep customers updated.

SOE has begun notifying affected customers of this breach. The company says that data from approximately 24.6 million accounts that may have been stolen. That data includes: name, address. e-mail address, birthdate, gender, phone number, login name and hashed password.
SOE ensures us its main credit card database is stored in a separate and secure environment. So once again personal data stolen, credit cards not. With one glaring exception. There was apparently an old database (from 2007) on the compromised servers that held 12,700 non-US credit card numbers and expiration dates (but not CCV codes) and 10,700 direct debit records listing bank account numbers of certain customers in Germany, Austria, Netherlands and Spain. This database may have been stolen. Sony is reaching out to everyone in this database to make them aware of what has happened.

Most of SOE's products carry a monthly subscription of about $15/month, and SOE has already stated that they are giving all subscribers a free month of service plus an additional day for every day the system is offline.

For more details on the SOE side of this breach, please see Sony's press release.

Follow Peter on Google+

Peter Smith writes about personal technology for ITworld.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question