Sony Hacked Yet Again

Collapse
X
Collapse
  •  

  • Sony Hacked Yet Again

    This is the second time in four months.
    Photo of the word SONY on the front of a building

    Coming just a week after a ransomware group called Ransomed.vc claims to have hacked into Sony, comes word that there was a second security breach. Sony themselves have admitted to there being another security breach that occurred back in May that involved the personal details of almost 6,800 former and current Sony employees.

    The initial reporting on this breach comes from Bleeping Computer. They say that Sony sent out a data breach notification to nearly 6,800 people after "an unauthorized party exploited a zero-day vulnerability in the MOVEit Transfer platform." The zero-day vulnerability in question is CVE-2023-34362, which is "a critical-severity SQL injection flaw that leads to remote code execution." This vulnerability has already been used several times by the Clop ransomware group to compromise "numerous organizations across the world." Clop added Sony Group to their list of victims back in June but Sony made no public mention of this until now.

    The breach happened on May 28, or three days before Sony was even made aware of the flaw from MOVEit vendor Progress Software. Sony apparently did not discover that they had been breached until early June.

    Sony claims that this specific breach was limited just to the MOVEit platform and had no impact on other systems. In total, 6,791 people in the U.S. were compromised as part of the breach. They have all been notified and are now being offered credit monitoring and identity restoration services through Equifax.

    As for the more recent breach by Ransomed.vc, some 3.14GB of data was allegedly stolen. Neither breach this year seems to include any customer details that we are aware of.
      Posting comments is disabled for guests. Login or sign up to leave a comment.

    Related Topics

    Collapse

    TGN on Threads TGN on BlueSky TGN on Facebook
    Working...