Security disasters continue at Sony: They finally got Play Station Network back up and running after a series of hacks severely compromised it, only to have another Hacker group (LulzSec) compromise their SonyPictures servers and steal 1,000,000 customer accounts. It turns out that these accounts weren’t even encrypted!
What are the qualifications for getting a job in their IT Security Dep’t.? Knowing how to boil water without burning it?
You can see the hackers’ statement here.
They managed to get passwords, e-mail addresses, full home addresses, and dates of birth all by the simplest of methods: SQL injection.
“Sony Pictures accounts also have a number of opt-in features that contain further information about each user depending on what each signs up for. LulzSec state all of that detail was available to them. They also managed to get the details of all admin accounts for the website.” – Matthew Humphries, Geek.com
The Hackers also stole 75,000 music codes and 3.5 million music coupons.
So, I’m bringing this to you because if you’re a SonyPictures customer, you probably need to change passwords, and probably your Credit Card number as quickly as possible so that you don’t end up liable for debts run up as a result of their incompetence.
I wonder when this level of incompetence becomes legally actionable? Really: Wasn’t their PSN disaster enough to get them in gear?
Source:
http://www.geek.com/articles/geek-pick/sonypictures-com-hacked-one-million-user-accounts-compromised-2011062/