Information Age: News, analysis & insight for IT & business leaders

Hackers claim theft of 1m passwords from Sony

3 June 2011  

Stealing unencrypted, plain text password file was "just a matter of taking it", says hacker group LulzSec

In yet another embarassing data breach for Sony, a group of hackers has claimed that it stole over 1 million user passwords from the Japanese company's TV and film division.

"We recently broke into SonyPictures.com and compromised over 1,000,000 users' personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts," Lulz Security  said in a statement.

"Among other things, we also compromised all admin details of Sony Pictures (including passwords) along with 75,000 "music codes" and 3.5 million 'music coupons'," it said.

The group said their latest hack was carried out using a simple technique called SQL injection, the same method was used in similar attacks on Sony last month.

"Every bit of data we took wasn't encrypted. Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it." the group said. "From a single injection, we accessed EVERYTHING. Why do you put such faith in a company that allows itself to become open to these simple attacks?"

Sony is reported to be investigation the group's claims.

Lulz Security, which calls itself a "cyber community" and does not affiliate itself with any country or politics, say it is behind a string of recent cyber attacks, including those on Sony Music, PBS and Fox.com.

On their website, the group says, "we have now taken it upon ourselves to spread fun, fun, fun, throughout the entire calendar year."

The website lists all the hacks recently carried out, including those of eight Sony databases all listed on the the 2nd of June.

Sony said is is investigating the attacks, but gave no further response. No group has claimed responsibility for the April attacks, in which over 100 million customers' details were stolen.


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">