Share

Hackers hit PlayStation users

Los Angeles - Sony said on Tuesday that the credit card data of PlayStation users around the world may have been stolen in a hack that forced it to shut down its PlayStation Network for the past week, disconnecting 77 million user accounts.

Some players brushed off the breach as a common hazard of operating in a connected world, and Sony said some services would be restored in a week. But industry experts said the scale of the breach was staggering and could cost the company billions of dollars.

"Simply put, one of the worst breaches we've seen in several years," said Josh Shaul, chief technology officer for Application Security Inc, a New York-based company that is one of the country's largest database security software makers.

Sony said it has no direct evidence credit card information was taken, but said: "We cannot rule out the possibility."

It said the intrusion was "malicious" and that the company had hired an outside security firm to investigate. It has taken steps to rebuild its system to provide greater protection for personal information, and warned users to contact credit agencies and set up fraud alerts.

"Our teams are working around the clock on this, and services will be restored as soon as possible," it said in a blog post on Tuesday.

The company shut down the network last Wednesday after it said account information - including names, birthdates, email addresses and log-in information - had been compromised for certain players.

Sony says people in 59 nations use the PlayStation network. Of the 77 million user accounts, about 36 million are in the US and elsewhere in the Americas, 32 million in Europe and 9 million in Asia, mostly in Japan.

Purchase history and credit card billing address information may also have been stolen but the intruder did not obtain the three-digit security code on the back of cards, Sony said. Spokesperson Satoshi Fukuoka said the company has not received any reports yet of credit card fraud or abuse resulting from the breach.

Shaul said that not having direct proof of credit card information theft should not instill a sense of security, and could mean Sony just didn't know what files were touched.

"They indicated that they're worried about it, which is probably a very strong indication that everything was stolen," he said.

If the intruder successfully stole credit card data, the heist would rank among the biggest known thefts of financial data.

Recent major hacks included some 130 million card numbers stolen from payment processor Heartland Payment Systems. As many as 100 million accounts were lifted in a break-in at TJX Cos., the chain that owns discount retailers TJ Maxx and Marshalls, and some 4.2 million card numbers were stolen from East Coast grocery chain Hannaford Bros. Those attacks allegedly involved a single person: Albert Gonzalez, a Miami hacker who was sentenced last year to 20 years in prison for the attacks.

The Ponemon Institute, a data-security research firm, estimated that the cost of a data breach involving a malicious or criminal act averaged $318 per compromised record in 2010, up 48% from the year earlier.

That could pin the potential cost of the PlayStation breach at more than $24bn.

Spectacular target

Alan Paller, director of research for the SANS Institute, a security training organisation, said that even if credit numbers weren't stolen, knowing someone's name, email address and which games he or she likes can lead to expertly crafted scam emails. Knowing billing histories can be even more harmful, since they can identify big spenders.

"If you know someone's spent a lot on gaming, they could be a spectacular target," he said.

The PlayStation break-in serves as a reminder of the danger of large-scale breaches, even as hackers gravitate towards smaller attacks that target specific, valuable data and are harder to detect.

The theft of credit card numbers has taken on a routine feel, even though instances of mega-breaches has been declining.

Verizon's latest annual security report, one of the industry's most authoritative analyses, found that the number of compromised records in cases examined by it and the US Secret Service dropped from a record-breaking 361 million in 2008 to under 4 million last year.

The decline was the result of more targeted attacks, as well as the lack of major breaches to inflate the numbers.
We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
18.82
+1.1%
Rand - Pound
23.52
+1.2%
Rand - Euro
20.13
+1.4%
Rand - Aus dollar
12.29
+0.9%
Rand - Yen
0.12
+2.5%
Platinum
922.80
-0.3%
Palladium
961.00
-3.0%
Gold
2,339.29
+0.3%
Silver
27.20
-0.9%
Brent Crude
89.01
+1.1%
Top 40
69,358
+1.3%
All Share
75,371
+1.4%
Resource 10
62,363
+0.4%
Industrial 25
103,903
+1.3%
Financial 15
16,161
+2.2%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders