2011 PlayStation Network outage
Date | April 20 – May 14, 2011 |
---|---|
Duration | 24 days (3 weeks and 3 days) |
Type | "External intrusion", data breach |
Target | PlayStation Network and Qriocity services |
Outcome |
|
The 2011 PlayStation Network outage (sometimes referred to as the PSN Hack) was the result of an "
Government officials in various countries voiced concern over the theft and Sony's one-week delay before warning its users. The breach resulted in the exposure and vulnerability of
Extent of the breach
Personal details from approximately 77 million accounts were compromised and prevented users of PlayStation 3 and PlayStation Portable consoles from accessing the service.[1][2][3][4]
Credit card data was encrypted, but Sony admitted that other user information was not encrypted at the time of the intrusion.[7][8] The Daily Telegraph reported that "If the provider stores passwords unencrypted, then it's very easy for somebody else – not just an external attacker, but members of staff or contractors working on Sony's site – to get access and discover those passwords, potentially using them for nefarious means."[9] On May 2, Sony clarified the "unencrypted" status of users' passwords, stating that:[10]
While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form.
On April 26, nearly a week after the outage, Sony confirmed that it "cannot rule out the possibility"
At the time of the outage, with a count of 77 million registered PlayStation Network accounts,[13] it was not only one of the largest data security breaches, but also the longest PS Network outage in history.[14][15] It surpassed the 2007 TJX hack which affected 45 million customers.[16]
Timeline of the outage
April 20, 2011
Sony acknowledged on the official PlayStation Blog that it was "aware certain functions of the PlayStation Network" were down. Upon attempting to sign in via the PlayStation 3, users received a message indicating that the network was "undergoing maintenance".[17][18] The following day, Sony asked its customers for patience while the cause of outage was investigated and stated that it may take "a full day or two" to get the service fully functional again.[19] Sony suspended all PlayStation Network and Qriocity services worldwide.[20]
While most games remained playable in their offline modes, the
April 22, 2011
Sony announced an "external intrusion" had affected the PlayStation Network and Qriocity services.[23]
Sony expressed their regrets for the downtime and called the task of repairing the system "time-consuming" but would lead to a stronger network infrastructure and additional security.[24]
April 25, 2011
Sony spokesman Patrick Seybold reiterated on the PlayStation Blog that fixing and enhancing the network was a "time intensive" process with no estimated time of completion.[25] However, the next day Sony stated that there was a "clear path to have PlayStation Network and Qriocity systems back online", with some services expected to be restored within a week. Furthermore, Sony acknowledged the "compromise of personal information as a result of an illegal intrusion on our systems."[26]
April 26, 2011
On April 26, 2011, Sony explained on the PlayStation Blog why it took so long to inform PSN users of the data theft:[27]
There’s a difference in timing between when we identified there was an intrusion and when we learned of consumers’ data being compromised. We learned there was an intrusion April 19th and subsequently shut the services down. We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident. It was necessary to conduct several days of forensic analysis, and it took our experts until yesterday to understand the scope of the breach. We then shared that information with our consumers and announced it publicly this afternoon.
April 27, 2011
Sony to provide an update in regards to a criminal investigation in a blog posted on April 27: "We are currently working with law enforcement on this matter as well as a recognized technology security firm to conduct a complete investigation. This malicious attack against our system and against our customers is a criminal act and we are proceeding aggressively to find those responsible."[7]
May 1, 2011
Sony announced a "Welcome Back" program for customers affected by the outage. The company also confirmed that some PSN and Qriocity services would be available during the first week of May.[28][29]
May 2, 2011
Sony issued a press release, according to which the
During the week, Sony sent a letter to the
May 3, 2011
Sony Computer Entertainment CEO
On May 3 Sony stated in a press release that there may be a correlation between the attack that had occurred on April 16 towards the PlayStation Network and one that compromised
May 4, 2011
Sony announced that it was adding Data Forte to the investigation team of Guidance Software and
May 6, 2011
Sony stated they had begun "final stages of internal testing" for the PlayStation Network, which had been rebuilt.[41] However, the following day Sony reported that they would not be able to bring services back online within the one-week timeframe given on May 1, because "the extent of the attack on Sony Online Entertainment servers" had not been known at the time.[42] SOE confirmed on their Twitter account that their games would not be available until some time after the weekend.[43]
Reuters began reporting the event as "the biggest Internet security break-in ever".[44] A Sony spokesperson said:[45]
- Sony had removed the personal details of 2,500 people stolen by hackers and posted on a website
- The data included names and some addresses, which were in a database created in 2001
- No date had been fixed for the restart
May 14, 2011
Various services began coming back online on a country-by-country basis, starting with North America.[46] These services included: sign-in for PSN and Qriocity services (including password resetting), online game-play on PS3 and PSP, playback of rental video content, Music Unlimited service (PS3 and PC), access to third party services (such as Netflix, Hulu, Vudu and MLB.tv), friends list, chat functionality and PlayStation Home.[46] The actions came with a firmware update for the PS3, version 3.61.[47] As of May 15 service in Japan and East Asia had not yet been approved.[48]
May 18, 2011
Sony shut down the password reset page on their site following the discovery of another exploit[49] that allowed users to reset other users' passwords, using the other user's email address and date of birth.[50] Sign-in using PSN details to various other Sony websites was also disabled, but console sign-ins were not affected.[49]
May 23, 2011
Sony stated that the outage costs were $171 million.[51]
Reaction
Graham Cluley, senior technology consultant at Sophos, said the breach "certainly ranks as one of the biggest data losses ever to affect individuals".[52]
Security experts Eugene Lapidous of AnchorFree, Chester Wisniewski of Sophos Canada and Avner Levin of Ryerson University (now Toronto Metropolitan University) criticized Sony, questioning its methods of securing user data. Lapidous called the breach "difficult to excuse" and Wisniewski called it "an act of hubris or simply gross incompetence".[53][54][55][56]
Government reactions
US Senator
Congresswoman
Privacy Commissioner of Canada Jennifer Stoddart confirmed that the Canadian authorities would investigate. The Commissioner's office conveyed their concern as to why the authorities in Canada weren't informed of a security breach earlier.[60]
Following a formal investigation of Sony for breaches of the UK's Data Protection Act 1998, the Information Commissioner's Office fined Sony £250,000 ($395k) and issued a statement highly critical of the security Sony had in place:
If you are responsible for so many payment card details and log-in details then keeping that personal data secure has to be your priority. In this case that just didn't happen, and when the database was targeted – albeit in a determined criminal attack – the security measures in place were simply not good enough. There's no disguising that this is a business that should have known better. It is a company that trades on its technical expertise, and there's no doubt in my mind that they had access to both the technical knowledge and the resources to keep this information safe.[61]
Legal action against Sony
A lawsuit was posted on April 27 by Kristopher Johns from
A Canadian lawsuit against Sony USA, Sony Canada and Sony Japan claimed damages up to
In October 2012 a California judge dismissed a lawsuit against Sony over the PSN security breach, ruling that Sony had not violated California's consumer-protection laws, citing "there is no such thing as perfect security".[67]
Compensation to users
In a press conference in Tokyo on May 1, Sony announced a "Welcome Back" program. As well as "selected PlayStation entertainment content" the program promised to include 30 days free membership of PlayStation Plus for all PSN members, while existing PlayStation Plus members received an additional 30 days on their subscription. Qriocity subscribers received 30 days. Sony promised other content and services over the coming weeks.[29]
Hulu compensated PlayStation 3 users for the inability to use their service during the outage by offering one week of free service to Hulu Plus members.[68]
On May 16, 2011, Sony announced that two PlayStation 3 games and two PSP games would be offered for free from lists of five and four,† respectively.[69][70] The games available varied by region[69][70] and were only available in countries which had access to the PlayStation Store prior to the outage.[70] On May 27, 2011, Sony announced the "welcome back" package for Japan[71] and the Asia region (Hong Kong, Singapore, Malaysia, Thailand and Indonesia).[72] In the Asia region, a theme - Dokodemo Issyo Spring Theme - was offered for free in addition to the games available in the "welcome back" package.[72]
^† 5 PSP games are offered in the Japanese market.[71]
Game | North America[69] | Europe (non-Germany)[70] | Germany[70] | Asia[72] | Japan[71] |
---|---|---|---|---|---|
Wipeout HD/Fury | Yes | Yes | Yes | Yes | Yes |
LittleBigPlanet | Yes | Yes | Yes | No | No |
InFamous | Yes | Yes | No | No | No |
Dead Nation | Yes | Yes | No | No | No |
Super Stardust HD | Yes | No | Yes | No | No |
Ratchet & Clank: Quest for Booty |
No | Yes | Yes | No | No |
Hustle Kings | No | No | Yes | Yes | Yes |
The Last Guy | No | No | No | Yes | Yes |
Trashbox | No | No | No | Yes | No |
Come on, LocoRoco!! BuuBuu Cocoreccho |
No | No | No | Yes | Yes |
Echochrome: Overture | No | No | No | No | Yes |
Game | North America[69] | Europe (non-Germany)[70] | Germany[70] | Asia[72] | Japan[71] |
---|---|---|---|---|---|
LittleBigPlanet |
Yes | Yes | Yes | Yes | Yes |
ModNation Racers | Yes | Yes | Yes | Yes | No |
Pursuit Force | Yes | Yes | No | No | No |
Killzone Liberation‡ |
Yes | Yes | No | No | No |
Everybody's Golf 2 | No | No | Yes | No | No |
Buzz Junior Jungle Party |
No | No | Yes | No | No |
Everybody's Stress Buster | No | No | No | Yes | Yes |
Locoroco Midnight Carnival | No | No | No | Yes | Yes |
Patapon 2 | No | No | No | No | Yes |
What Did I Do to Deserve This, My Lord? | No | No | No | No | Yes |
^‡ Version of Killzone Liberation offered does not offer online gameplay functionality.[70]
Credit card fraud
There were reports on the Internet that some users experienced credit card fraud;[73][74][75] however, they were yet to be linked to the incident. Sony said that the CSC codes requested by their services were not stored,[76] but hackers may have been able to decrypt or record credit card details while inside Sony's network.[73]
On May 5, a letter from Sony Corporation of America CEO and President Sir Howard Stringer emphasized that there had been no evidence of credit card fraud and that a $1 million identity theft insurance policy would be available to PSN and Qriocity users.[34]
Sony PlayStation Controversies during a similar timeframe
In March 2010, Sony launched a firmware update for the PlayStation 3 which removed the ability to install third-party operating systems like Linux.[77][78] This move sparked significant backlash from the modding community.
George Hotz, also known as Geohot, managed to jailbreak the PS3 firmware on January 2, 2011, and began sharing the jailbreak online shortly afterward.[79] In response, Sony sued Hotz on January 11, 2011, for his jailbreaking activities.[80]
The hacker group Anonymous initiated "Operation Sony" on April 2, 2011, as a form of protest.[78] Sony eventually settled the lawsuit with Hotz by April 11.[81] Following this, Anonymous called for a public protest against Sony on April 13.[78]
References
- ^ a b c "PlayStation Network Restoration Begins". PlayStation Network / PSN News. United Kingdom: Sony. 2011-05-17. Archived from the original on 2016-03-03. Retrieved 2011-10-20.
- ^ a b "Sony faces legal action over attack on PlayStation network". BBC News. bbc.co.uk. 2011-04-28. Retrieved 2011-04-29.
- ^ a b Richmond, Shane (2011-04-26). "Millions of internet users hit by massive Sony PlayStation data theft". London: Telegraph. Archived from the original on April 28, 2011. Retrieved 2011-04-29.
- ^ a b Griffith, Chris (2011-04-27). "PlayStation users in Australia urged to check credit card activity". Australian IT. The Australian. Retrieved 2011-11-20.
- ^ Owen Good (2011-05-20). "Welcome Back PSN: The Winners". Kotaku.com. Retrieved 2011-06-02.
- .
- ^ a b "Q&A #1 for PlayStation Network and Qriocity Services – PlayStation Blog". Blog.us.playstation.com. 2010-12-20. Retrieved 2011-04-29.
- ^ Stuart, Keith (2011-04-27). "PlayStation Network hack: why it took Sony seven days to tell the world | Technology | guardian.co.uk". London: Guardian. Retrieved 2011-04-29.
- ^ Williams, Christopher (2011-04-28). "PlayStation hack: Sony users urged to change passwords". London: Telegraph. Retrieved 2011-04-29.
- ^ "PlayStation Network Security Update – PlayStation Blog". Blog.us.playstation.com. 2011-05-02. Retrieved 2011-05-07.
- ^ "BBC News - Sony's PlayStation hack apology". Bbc.co.uk. 2011-04-19. Retrieved 2011-04-29.
- ^ Reynolds, Isabel (2009-02-09). "Furore at Sony after Playstation user data stolen". Reuters. Retrieved 2011-04-29.
- ^ "PlayStation Network and Qriocity Outage FAQ – PlayStation.Blog.Europe". Blog.eu.playstation.com. Retrieved 2011-04-29.
- ^ "PlayStation data breach deemed in 'top 5 ever' - Business - CBC News". Cbc.ca. 2011-04-27. Retrieved 2011-04-29.
- ^ "Video: Sony PlayStation - Hacker Breaks Into Network And Steals Details Of Millions Of Gamers | Technology | Sky News". News.sky.com. Retrieved 2011-04-29.
- ^ "PlayStation hack: top five data thefts". London: Telegraph. 2011-04-27. Retrieved 2011-04-29.
- ^ "Update on PSN Service Outages". United States: PlayStation Blog. 2011-04-20. Retrieved 2011-04-29.
- ^ "Timeline of Sony's PlayStation Network outage". hken.ibtimes.com. 2011-05-15. Archived from the original on 2011-05-18. Retrieved 2011-05-15.
- ^ "Latest Update on PSN Outage". United States: PlayStation Blog. 2011-04-21. Retrieved 2011-04-29.
- ^ "PlayStation Knowledge Center | Support - PlayStation.com". us.playstation.com. 2011-01-10. Retrieved 2011-04-29.
- ^ Barrera, Rey. "Netflix-still-works-on-your-ps3-despite-the-outage". PSNation. Archived from the original on 27 April 2011. Retrieved 25 April 2011.
- ^ "PlayStation Network Outage Bad News for Netflix and Hulu: Online Video News". Gigaom.com. Archived from the original on 2011-04-29. Retrieved 2011-04-29.
- ^ "Update On PlayStation Network/Qriocity Services". United States: PlayStation Blog. 2011-04-22. Retrieved 2011-04-29.
- ^ "Latest Update for PSN/Qriocity Services – PlayStation Blog". Blog.us.playstation.com. 2011-04-23. Retrieved 2011-04-29.
- ^ "PSN Update – PlayStation Blog". Blog.us.playstation.com. 2011-04-25. Retrieved 2011-04-29.
- ^ "Update on PlayStation Network and Qriocity – PlayStation Blog". Blog.us.playstation.com. 2011-04-19. Retrieved 2011-04-29.
- ^ "Clarifying a Few PSN Points – PlayStation Blog". Blog.us.playstation.com. 2011-04-26. Retrieved 2011-05-07.
- ^ "Some PlayStation Network And Qriocity Services To Be Available This Week – PlayStation.Blog.Europe". Blog.eu.playstation.com. Retrieved 2011-05-01.
- ^ a b Yin-Poole, Wesley (2011-05-01). "PSN: Sony outlines "Welcome Back" gifts". PlayStation 3. United Kingdom: Eurogamer. Retrieved 2011-10-20.
- ^ a b "Service Under Maintenance". SOE. 2010-03-31. Archived from the original on 2013-02-02. Retrieved 2011-05-04.
- ^ "Sony Confirms Thousands Of Credit Cards Stolen During Hack - GameInformer News". gameinformer.com. 2011-05-02. Retrieved 2011-05-02.
- ^ "Sony's Response to the U.S. House of Representatives – PlayStation Blog". Blog.us.playstation.com. 2010-12-20. Retrieved 2011-05-07.
- ^ "Sony Offering Free 'AllClear ID Plus' Identity Theft Protection in the United States through Debix, Inc. – PlayStation Blog". Blog.us.playstation.com. Retrieved 2011-05-07.
- ^ a b "A Letter from Howard Stringer – PlayStation Blog". Blog.us.playstation.com. 2010-12-20. Retrieved 2011-05-07.
- ^ Watt, Peggy (30 April 2011). "Sony: PlayStation Network Resumes This Week". pcworld.com. Retrieved 2 May 2011.
- ^ Fletcher, JC (2011-05-01). "PSN 'welcome back program' includes a free download, 30 days free PlayStation Plus, Qriocity". joystiq.com. Archived from the original on 2012-07-15. Retrieved 2011-05-02.
- ^ "24.6 million SOE accounts potentially compromised". News. gamesindustry.biz. 2011-03-21. Retrieved 2011-05-04.
- ^ "Another team added to Sony's PSN investigation". VG247. 4 May 2011. Retrieved 2011-05-04.
- ^ Bartz, Diane (2011-04-26). "Sony blames Anonymous for stage-setting theft". Reuters. Retrieved 2011-05-04.
- ^ "Hackers deny involvement in PlayStation Network outage". 22 April 2011. Retrieved June 9, 2011.
- ^ "Important Step for Service Restoration – PlayStation.Blog.Europe". Blog.eu.playstation.com. 2011-05-06. Retrieved 2011-05-07.
- ^ JC Fletcher (2011-05-06). "PSN reactivation delayed for 'further testing,' likely not coming back this week". Joystiq. Archived from the original on 2011-05-08. Retrieved 2011-05-07.
- ^ "Twitter / @Sony Online Ent.: We wanted to let you know ..." twitter.com. 2011. Retrieved 16 May 2011.
- ^ Reynolds, Isabel (2011-05-06). "Sony CEO apologises for data theft; shares fall 2 pct". Reuters. Retrieved 2011-05-07.
- ^ Reynolds, Isabel (2011-05-06). "Sony removes data posted by hackers, delays PlayStation restart". Reuters. Retrieved 2013-10-10.
- ^ a b "Sony Global - News Releases - RESTORATION OF PLAYSTATIONNETWORK AND QRIOCITY SERVICES BEGINS". Sony. May 15, 2011. Retrieved May 15, 2011.
- PlayStation Blog. May 14, 2011. Retrieved May 15, 2011.
- ^ Mochizuki, Takashi (2010-04-07). "Japan Restart of Sony Online Games Services Not Yet Approved". FoxBusiness.com. Archived from the original on 2011-06-03. Retrieved 2011-06-02.
- ^ a b "Sony's PSN password page exploit". Eurogamer. May 18, 2011. Retrieved May 18, 2011.
- ^ "Report: Sony PlayStation Network Password Reset Page Exploited, Customer Accounts Potentially Compromised". Kotaku. May 18, 2011. Retrieved May 18, 2011.
- ^ "PlayStation Hack to Cost Sony $171M; Quake Costs Far Higher". PC Magazine. May 23, 2011.
- Telegraph. Archived from the originalon April 28, 2011. Retrieved April 29, 2011.
- ^ Brightman, James (2011-05-03). "Sony Breach 'Difficult to Excuse' Say Security Experts". IndustryGamers. Archived from the original on 2011-05-05. Retrieved 2011-05-05.
- ^ Chung, Emily (2011-05-03). "Sony data breach update reveals 'bad practices'". CBC News. Retrieved 2011-05-05.
- ^ Westervelt, Robert (2011-05-03). "Sony attack: Sony expands scope of its massive data security breach". SearchSecurity.com. Retrieved 2011-05-05.
- ^ Schwartz, Matthew J. (2011-05-03). "Sony Reports 24.5 Million More Accounts Hacked". InformationWeek. Archived from the original on 2011-05-05. Retrieved 2011-05-05.
- ^ "Blumenthal Demands Answers from Sony over Playstation Data Breach". Richard Blumenthal-US senator for Connecticut: Home. Archived from the original on May 5, 2011. Retrieved 2011-04-26.
- ^ "Blumenthal Calls for DOJ Investigation of Sony Playstation Data Breach". Richard Blumenthal-US senator for Connecticut: Home. Retrieved 2011-04-29.
- ^ "US lawmakers press Sony for info on data breach". Associated Press. 2011-04-29. Archived from the original on 2011-09-30. Retrieved 2011-04-30.
- ^ "Privacy Commissioner's office looking into Sony PlayStation hack". Canada.com. Retrieved 2011-04-29.[permanent dead link]
- ^ "Crap security lands Sony £250k fine for PlayStation Network hack". The Register.
- ^ Ogg, Erica (2011-03-24). "Sony sued for PlayStation Network data breach | Circuit Breaker - CNET News". News.cnet.com. Archived from the original on 2011-05-04. Retrieved 2011-04-29.
- ^ "Johns v. Sony Computer Entertainment America LLC et al". Justia. 2011-05-03. Retrieved 2011-05-03.
- ^ Schwartz, Mathew J. "Sony Sued Over PlayStation Network Hack". InformationWeek. Archived from the original on 2011-04-29. Retrieved 2011-04-29.
- Gamasutra. 2011-05-04. Retrieved 2011-05-04.
- ^ "Sony PlayStation Network Down: PSN Hit with $1.04B Class Action Suit". Gather. 2011-05-04. Archived from the original on 2011-05-07. Retrieved 2011-05-04.
- ^ "Sony PSN hacking lawsuit dismissed by judge".
- G4tv.com. Archived from the originalon 2012-10-17. Retrieved 2011-10-20.
- ^ PlayStation Blog. May 16, 2011. Retrieved May 17, 2011.
- ^ a b c d e f g h "Details Of The Welcome Back Programme For SCEE Users". PlayStation Blog. May 16, 2011. Retrieved May 17, 2011.
- ^ SCEJ. May 27, 2011. Retrieved 20 October 2011.
- ^ a b c d "Welcome Back Package for Hong Kong, Singapore, Malaysia, Thailand and Indonesia". PlayStation.com. May 27, 2011. Retrieved May 28, 2011.
- ^ a b "PlayStation users reporting credit card fraud". 30 April 2011. Retrieved April 30, 2011.
- ^ "Hackers run up debt for PlayStation user". ABC News. 27 April 2011. Retrieved April 30, 2011.
- ^ Arthur, Charles (2011-04-29). "Hackers claim to have 2.2 million card details". The Guardian. London. Retrieved April 30, 2011.
- ^ "Q&A #1 for PlayStation Network and Qriocity Services – PlayStation Blog". blog.us.playstation.com. 2011. Retrieved 16 May 2011.
- ^ "PS3 Firmware (v3.21) Update". PlayStation.Blog. 2010-03-28. Retrieved 2022-09-13.
- ^ a b c PSN Hack Attack Summary, IGN, retrieved 2022-09-13
- ^ "Geohot releases PS3 jailbreak for firmware 3.55, world ceases to have any meaning". Engadget. Retrieved 2022-09-13.
- ^ "Sony follows up, officially sues Geohot and fail0verflow over PS3 jailbreak". Engadget. Retrieved 2022-09-13.
- ^ "Sony and hacker GeoHot call a truce in bitter legal battle". NBC News. Retrieved 2022-09-13.