iTnews
  • Home
  • News
  • Technology
  • Security

Sony Pictures still struggling eight days after hack

By Staff Writers on Dec 4, 2014 11:10AM
Sony Pictures still struggling eight days after hack

Execs confirm 'large amount' of confidential data stolen.

Eight days after a massive attack on the internal systems of Sony Pictures Entertainment, the Hollywood studio was still struggling to restore some systems as investigators combed for evidence to identify the culprit.

Some employees at the Sony entertainment unit were given new computers to replace ones that had been attacked with the rare data-wiping virus, which had made their machines unable to operate, according to a person with knowledge of Sony's operations.

In a memo to staff, studio co-chiefs Michael Lynton and Amy Pascal acknowledged that "a large amount of confidential Sony Pictures Entertainment data has been stolen by the cyber attackers, including personnel information and business documents".

The company was "not yet sure of the full scope of information that the attackers have or might release," according to the memo, which also encouraged employees to take advantage of identity protection services being offered.

The executives' concern underscores the severity of the breach, which experts say is the first major attack on a US company to use a highly destructive class of malicious software.

Government investigators led by the FBI are considering multiple suspects in the attack, including North Korea, according to a US national security official with knowledge of the investigation.

The FBI today said it was working with its counterparts in Sony's home country of Japan in the investigation.

The agency on Monday warned US businesses about the use of malware and suggested ways to defend themselves. The warning said some of the software used by the hackers had been compiled in the Korean language, but it did not discuss any possible connection to North Korea.

Sony's troubles

The November 24 attack only affected computers running Windows software, meaning Sony employees using Apple Macs (most of the marketing department) had not been affected, according to the person familiar with Sony's operations.

Sony Pictures Entertainment shut down its internal computer network last week to prevent the data-wiping software from causing further damage, forcing employees to use paper and pen.

The studio has brought some systems back online, focusing first on those from which the company generates revenues, including those involved with marketing and distributing its films and TV shows, according to the person.

The hack comes at a tough time for Sony, following soon after a denial-of-service attack on Sony's PlayStation Network in August. Sony was also victim of a notorious 2011 breach that compromised data of tens of millions of PlayStation Network users.

It also comes just as the company's CEO Kazuo Hirai is trying to grow the entertainment business to help offset losses in its mobile division.

He has been under pressure to prove the segment's growth potential after rejecting a proposal by US hedge fund Third Point to spin it off last year.

Forensic investigation

People claiming responsibility for the attack have posted high-quality digital copies of yet-to-be-released Sony films and purported sensitive data about the company's operations and employees online, making them freely available to the public in a series of releases over the past five days.

Sony's holiday musical "Annie", which is due to be released December 19 in the United States, was available for download on a popular piracy site last night.

Daniel Clemens, chief executive of cyber security firm PacketNinjas, said he had reviewed the files released to date and believed they were stolen from Sony.

He said he found business contracts as well as Social Security numbers, salary information and medical data about employees.

"This is a horrible compromise," Clemens said.

The US national security official, who asked to remain anonymous, said the forensic investigation was in its early stages and no clear suspects had yet emerged.

However, the tools used in the attack were based on ones used in similar attacks conducted against South Korea by North Korea, a person familiar with the company's investigation said today.

The person, who was not authorised to publicly discuss Sony's probe into the attack, said that investigators hired by the company made the connection to North Korea as they reviewed evidence left by the hackers.

Sony is reportedly investigating whether hackers working on behalf of the North Korean government were responsible for the attack as retribution for the company's backing of the film "The Interview".

The Pyongyang government denounced the film as "undisguised sponsoring of terrorism, as well as an act of war" in a letter to UN Secretary-General Ban Ki-moon in June.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
breachhacksecuritysonysony pictures

Partner Content

The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • Micro Focus Information Management & Governance (IM&G) Forum 2022
  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
  • Forrester Technology & Innovation Asia Pacific 2022
By Staff Writers
Dec 4 2014
11:10AM
0 Comments

Related Articles

  • 'Back from vacation' - Lapsus$ hackers claim breach of Globant
  • T-Mobile says hackers stole about 7.8m postpaid customers' personal data
  • Hacker claims to have stolen 1 billion records of Chinese citizens
  • Carnival fined US$5m for cyber security violations
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Australia scraps digital passenger cards for international arrivals

Australia scraps digital passenger cards for international arrivals

PayTo rollout kicks off

PayTo rollout kicks off

Services Australia spends $50m on IBM Power hardware upgrade

Services Australia spends $50m on IBM Power hardware upgrade

NSW gov adds six providers to cloud panel

NSW gov adds six providers to cloud panel

Digital Nation

Case Study: EY invests in AI to improve approach to flexible working
Case Study: EY invests in AI to improve approach to flexible working
Case Study: Good360 deploys NetSuite, Magento and Salesforce
Case Study: Good360 deploys NetSuite, Magento and Salesforce
Case study: AFL kicks goals with its new digital platform
Case study: AFL kicks goals with its new digital platform
Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Multicloud business drivers at MLC Life Insurance
Personalisation strategies need to be built from the ground up
Personalisation strategies need to be built from the ground up
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.