Feeds

New Sony hack exposes more consumer passwords

The 'sownage' continues

3 Big data security analytics techniques

Hackers who last week broke into the website of television network PBS have turned their attention to Sony's movie division, publishing what appeared to be the email addresses and passwords belonging to at least 50,000 consumers who registered for online promotions.

A group called LulzSec claimed responsibility for the attack and said it was achieved by exploiting a simple SQL injection vulnerability on the Sony Pictures website. The group claimed the single attack exposed information for more than 1 million people, but that the group lacked the resources to copy such a massive amount of data.

"What's worse is that every bit of data we took wasn't encrypted," the group wrote in a press release announcing the hack. "Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it."

A Sony spokesman said the company is looking into the claims, but provided no other comment.

LulzSec is the same group that took credit for breaching security at PBS.org last holiday weekend in retaliation for a documentary it claimed was unfair to whistle-blower website WikiLeaks. The pranksters published usernames and hashed passwords for website administrators and users, and they also posted a hoax news story claiming that dead rapper Tupac Shakur was alive and living in the same New Zealand town as nemesis Biggie Smalls.

The group has also hacked Sony’s Fox.com and stole hundreds of employee passwords along with the names, phone numbers and e-mail addresses of some 73,000 people who requested audition information for the upcoming talent show The X-Factor.

The compromise of Sony Pictures is the latest embarrassment for Sony, which has suffered a series of devastating hacks since being targeted for its scorched-earth legal campaign against people jailbreaking the PlayStation 3 game console. All told, the attacks have exposed personally identifiable information for more than 100 million Sony customers and cost Sony at least $171 million.

The personally identifiable information contained in Thursday's data dump appeared to belong to people who signed up for promotional campaigns involving AutoTrader.com, Sony's "Summer of Restless Beauty," and a “Seinfeld — We’re Going to Del Boca Vista!” giveaway. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.