Share

Hack attack

Boston - The hacking of Sony's PlayStation Network has earned a place in the annals of internet crime.

That's partly because of the massive size of the data breach - information from about 77 million customer accounts was stolen. It is also because Sony bothered to disclose the attack at all.

The bulk of attacks on corporate and governmental computer networks go unreported because victims want to avoid the embarrassment and public scrutiny that come with acknowledging that their systems have been hacked.

Companies fear that their stock price might take a hit or that their brand might be damaged after news of an intrusion, said Jerry Dixon, a former government official who was instrumental in setting up the US government's crime-fighting Computer Emergency Readiness Team.

"Everybody's network is getting hammered all the time," said Dixon, director of analysis at Team Cymru, a non-profit security research group.

Sony shut down the network on April 19 after discovering the breach, one of the biggest online data infiltrations ever. But it was not until Tuesday that the company said the system had been hacked and that users' data could have been stolen.

In the United States, several members of Congress seized on the breach, in which hackers stole names, addresses and possibly credit card details. One US law firm filed a lawsuit in California on behalf of consumers.

Democratic Senator Richard Blumenthal of Connecticut called on the Justice Department to investigate the matter.

The FBI launched an inquiry and urged anybody with information about the attack to contact an agency hotline.

Code of Silence

Experts say that many companies only disclose break-ins when they are required to do so by government regulations that say they must tell customers whose data was compromised.

In many cases companies seek to keep the matter quiet by telling individual customers of the problem without issuing a public statement like the one from Sony this week.

The publicity over the break-in has exposed Sony to global legal scrutiny, with officials from Hong Kong to London and Washington looking into the breach.

Sony's PlayStation Network, a service that produces an estimated $500m in annual revenues, provides access to online games, movies and TV shows. Nine out of 10 of PlayStation's users are based in the United States or Europe.

Security experts say that companies that are attacked remain silent most of the time.

For example, 85% of some 200 companies in electricity-producing industries said that their networks had been hacked, according to a survey released this month by security software maker McAfee Inc and the non-profit Center for Strategic and International Studies. Yet utilities rarely disclose such attacks.

One in four of those companies in the McAfee/CSIS study reported that they had been victims of extortion campaigns from hackers who had broken into their networks.

In many cases, intrusions go undetected by the victim company, leaving the firm and its customers completely unaware that criminals have access to their sensitive data.

"Everybody's data is at risk. We've all got to worry about our personal information, wherever it may be," said Josh Shaul, chief technology officer for Application Security Inc.

Spear "phishing"

Sony said it had encrypted all credit card numbers, which would make it extremely difficult for hackers to access that data. But criminals might use other personal information that was not encrypted to launch scams.

With birthdates, email addresses and home addresses, hackers can launch spear "phishing" attacks that are targeted at those individuals.

Spear phishing refers to attacks that are customised to each individual target. Hackers draft emails that contain enough personal information to persuade the victim to let down their defenses, which can be enough to get them to click on a link that downloads malicious software onto their personal computer.
We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.15
-0.7%
Rand - Pound
23.82
-0.6%
Rand - Euro
20.39
-0.5%
Rand - Aus dollar
12.30
-0.5%
Rand - Yen
0.12
-0.6%
Platinum
950.40
-0.3%
Palladium
1,028.50
-0.6%
Gold
2,378.37
+0.7%
Silver
28.25
+0.1%
Brent Crude
87.29
-3.1%
Top 40
67,190
+0.4%
All Share
73,271
+0.4%
Resource 10
63,297
-0.1%
Industrial 25
98,419
+0.6%
Financial 15
15,480
+0.6%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders