3

Sony confirms data breach affecting nearly 7,000 employees

 11 months ago
source link: https://www.engadget.com/sony-confirms-data-breach-affecting-nearly-7000-employees-075945888.html?_fsig=XqIDJvGmjR8B1VaRSZoqcQ--%7EA
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Sony confirms data breach affecting nearly 7,000 employees

Sony confirms data breach affecting nearly 7,000 employees

A file transfer platform was the source of the attack.

Reporter
Updated Fri, Oct 6, 2023, 4:59 PM GMT+9·1 min read
8b0f86a0-6417-11ee-9a9f-1ae6c75d56a9
Sundry Photography via Getty Images

Sony Interactive Entertainment (SIE) has warned around 6,800 current and former employees that their personal data was accessed via a data breach, according to a letter seen by Bleeping Computer. The nature of the personal information stolen by hackers was redacted, but the company stated that a file transfer app called MOVEit was the source of the breach. It's the second report of an attack on Sony's operations within the last two weeks.

A ransomware group called CL0P claimed credit for the attack on May 28th, and MOVEit's vendor Progress Software notified Sony about the vulnerability on May 31st "On June 2, 2023, [we] discovered the unauthorized downloads, immediately took the platform offline, and remediated the vulnerability," Sony states in the letter to employees. "An investigation was then launched with assistance from external cybersecurity experts. We also notified law enforcement."

The hackers reportedly gained access to personally identifiable information about US employees, so Sony is providing credit monitoring services to those affected.

Sony was victim of another breach first reported last week. In that case, the hackers accessed servers in Japan used for internal testing for its Entertainment, Technology and Services business, pilfering 3.14GB of data. A threat actor called Ransomed.vc took credit for the attack, but that was denied by another group calling itself MajorNelson, which posted a sampling of files as proof. Sony said it was investigating the attack, adding "there has been no adverse impact on Sony's operations."

The company's PlayStation network was attacked in 2011, and Sony Pictures was famously hacked in 2014, resulting in a massive leak of documents and content — including entire films.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK