[PSA for PSN users, from your pals at Joystiq: Before you start reading this informative news post, go change every internet password you've ever had. Done? Okay, read on!]
Nearly six days in, and Sony has finally sent out an email to the millions of affected PSN users explaining the prolonged downtime, and elaborating on the security implications of the "external intrusion" of the PlayStation Network. The most important new detail: Sony has determined that there has been "a compromise of personal information" as a result of the attack. The second most important new detail: "We have a clear path to have PlayStation Network and Qriocity systems back online, and expect to restore some services within a week."
So, what did the bad guys manage to steal? Uhh ... just about everything, it seems. Here's what's in the definitely jacked column: "name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID." Our takeaway: you'd better start changing passwords if you use the same one frequently. We'll leave the decision on whether or not to pack your bags and move away up to you.
In the possibly jacked column: "profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers." That leaves your credit card information, which ... well, we'll let Sony tell you itself: "If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained." Yikes.
Sony provides a bunch of links for consumers to keep an eye on their data. Most important is probably the free credit report services. It also cautions PSN users to change their password when the service is back online. Lastly, while they never directly say as much, we're going to suggest making PSN purchases through other retailers instead of directly on Sony's service. Well, when it works again. But after that, stock up on some PSN points cards from anywhere else.
Update 5:22pm: While we're working on a more thorough piece about what little old you can do in the face of such overwhelming barbarism, we did want to share some short tips. Our first tip comes to us from friend-of-the-site Robin Yang, who (re)tweets: "To see what card you used w/ PlayStation Network, check your emails from 'DoNotReply@ac.playstation.net.'" Once you've figured out what that card is, call your bank and tell them you think it may have been compromised. That's one part of the security equation.
Next up is your password, and it's a little trickier. Giant Bomb's Patrick Klepeck asked Sony if there was any way to learn what password was attached to a PSN account and was told "there is currently no way to determine what password you were/are using on PSN." That means you should probably be changing everything. Then again, if you followed our pre-post recommendation, you've already done that.
Update 2 6:02pm: Maybe you live in Europe and, thanks to the cultural and geographic gulf that separates you from North America, you thought your data was safe? Wrong. SCEE has issued a similar notice on the UK PlayStation blog.
This is somewhat of a larger logical leap, but if you managed – however briefly! – to pair your Steam account with your now-compromised PSN account last week, you need not worry! A Valve rep told Joystiq, "Nothing to be worried about. Steam has nothing to do with the PSN outage." So stop worrying ... about that one thing. You can continue worrying about the PSN data breach.
Sony says PSN 'intrusion' compromised personal info; hopes to have 'some services' back 'within a week'
366
Reader Comments (366)
Posted: Apr 26th 2011 4:29PM (Unverified) said
Wow...
One week to tell us that our personal details and possibly credit details (even if we took them down) have been compromised.
*Insert portal 2's slow clap joke*
Reply
One week to tell us that our personal details and possibly credit details (even if we took them down) have been compromised.
*Insert portal 2's slow clap joke*
Posted: Apr 26th 2011 4:33PM daytripper said
@(Unverified)
It probably took the that long to figure out exactly how severe the intrusion was.
Reply
It probably took the that long to figure out exactly how severe the intrusion was.
Posted: Apr 26th 2011 4:36PM Grubasaurus Rex said
@(Unverified) This is why I am a Gold subscriber. Sure Xbox Live has been down once or twice during my 5 year membership. However, that was for maintenance.
Anyways, I hope this situation gets solved fast!
Reply
Anyways, I hope this situation gets solved fast!
Posted: Apr 26th 2011 4:47PM (Unverified) said
@(Unverified)
Pretty sure all the ppl talking smack about sony were the ppl that were complaining that they wanted linux and for the ps3 to be hacked cus they payed for it.
Reply
Pretty sure all the ppl talking smack about sony were the ppl that were complaining that they wanted linux and for the ps3 to be hacked cus they payed for it.
Posted: Apr 26th 2011 4:48PM copa said
@eat it
"This type of thing can and does happen on many paid web services."
This happens on paid web services that don't give a shit about securing user data, and start investing in it AFTER they have been cracked.
Every time this happens on a site like Gawker, the postmortem shows that the company did something REALLY stupid and sloppy in terms of protecting user data. As another posted noted, there is a reason why this has never happened to companies like Amazon, Apple, Ebay, Microsoft, Google who know how to do internal security audits.
Sony should be offering us free ongoing credit monitoring for a year, just like any other reputable company does when they let this crap happen.
Reply
"This type of thing can and does happen on many paid web services."
This happens on paid web services that don't give a shit about securing user data, and start investing in it AFTER they have been cracked.
Every time this happens on a site like Gawker, the postmortem shows that the company did something REALLY stupid and sloppy in terms of protecting user data. As another posted noted, there is a reason why this has never happened to companies like Amazon, Apple, Ebay, Microsoft, Google who know how to do internal security audits.
Sony should be offering us free ongoing credit monitoring for a year, just like any other reputable company does when they let this crap happen.
Posted: Apr 26th 2011 4:48PM Protege420 said
@eat it
but the difference is that you paid to be on a secured service knowing you info is protected, if that company fails to do so you can litagate
Reply
but the difference is that you paid to be on a secured service knowing you info is protected, if that company fails to do so you can litagate
Posted: Apr 26th 2011 4:48PM eNriqeu said
@Grubasaurus Rex
http://www.zdnet.com/blog/security/xbox-live-hacked-accounts-stolen/131
And go search in google "xbox live hacked accounts credit card info".
This has nothing to do with being a paid service, don be an a**.
Reply
http://www.zdnet.com/blog/security/xbox-live-hacked-accounts-stolen/131
And go search in google "xbox live hacked accounts credit card info".
This has nothing to do with being a paid service, don be an a**.
Posted: Apr 26th 2011 6:35PM khaos100 said
@Grubasaurus Rex
I find it funny that you are saying a Microsoft service is secure. Nothing is secure the minute you involve people. We hear probably less than 5% of all the hacking into "secure" networks. It's only when they realize they have to cover their asses from being sued do we get the "we got hacked and you personal info may have been compromised" news.
Thinking paying for the Gold on line service makes you more secure only makes you a more likely victim.
Reply
I find it funny that you are saying a Microsoft service is secure. Nothing is secure the minute you involve people. We hear probably less than 5% of all the hacking into "secure" networks. It's only when they realize they have to cover their asses from being sued do we get the "we got hacked and you personal info may have been compromised" news.
Thinking paying for the Gold on line service makes you more secure only makes you a more likely victim.
Posted: Apr 26th 2011 4:50PM RobT said
@Grubasaurus Rex
that argument doesn't hold up, it doesn't matter what system, it can be compromised, paid or not. This sucks for sony as the gaming community is notoriously immature and childish and this will just amount to one more piece of ammo for anyone who wants to slag off anything with the PS brand. The gaming community as a whole should show some sympathy here, it doesn't matter what systems you play, we're all gamers in the end.
Reply
that argument doesn't hold up, it doesn't matter what system, it can be compromised, paid or not. This sucks for sony as the gaming community is notoriously immature and childish and this will just amount to one more piece of ammo for anyone who wants to slag off anything with the PS brand. The gaming community as a whole should show some sympathy here, it doesn't matter what systems you play, we're all gamers in the end.
Posted: Apr 26th 2011 4:51PM copa said
@(Unverified)
"Pretty sure all the ppl talking smack about sony were the ppl that were complaining that they wanted linux"
I'm pretty sure that some of us who are talking about Sony are a little pissed that criminals have our e-mail, password, birthdate, and credit card information.
Reply
"Pretty sure all the ppl talking smack about sony were the ppl that were complaining that they wanted linux"
I'm pretty sure that some of us who are talking about Sony are a little pissed that criminals have our e-mail, password, birthdate, and credit card information.
Posted: Apr 26th 2011 4:52PM A Sandwich said
@eat it
Are you still grabbing your ankles? This is the worst security breach in the history of video games and whether or not the possibility exists that it could happen on Live is irrelevant BECAUSE IT F*CKING HASN'T!
Reply
Are you still grabbing your ankles? This is the worst security breach in the history of video games and whether or not the possibility exists that it could happen on Live is irrelevant BECAUSE IT F*CKING HASN'T!
Posted: Apr 26th 2011 4:54PM beanbaggers said
@(Unverified) geohotz must be rolling his butt on the floor in mexico right now(yeaaah...)
Reply
Posted: Apr 26th 2011 5:02PM Ballistic H said
@sammo21
^This.
All of a sudden, there are lots of spoiled kids who want answers right away, blame the victim instead of the attackers, when the hell did the world turned upside down?
Reply
^This.
All of a sudden, there are lots of spoiled kids who want answers right away, blame the victim instead of the attackers, when the hell did the world turned upside down?
Posted: Apr 26th 2011 5:05PM PR0F3TA said
@RobT
"This sucks for sony as the gaming community is notoriously immature and childish"
YES!... you want an example
Childish gamer: WAAA WAAA SONY WONT LET ME JAILBREAK MY CONSOLE THAT I PAID FOR WITH MY MONEY. LET ME DO WHAT I WANT WITH MY CONSOLE INCLUDING RUNNING CUSTOM FW WAAA WAAA WAAA
*console info gets stolen thanks to jailbreak*
Childish gamer: WAAA WAAA SONY GOT MY INFO STOLEN, WHY DON'T YOU PROTECT YOUR SERVERS BETTER SONY WAA WAA I WANT FREE STUFF NOW WAAA WAAA THIS IS ALL YOUR FAULT SONY WAAA WAAA
i swear with all this childish self centeredness this generation of gamers have become i want to just rule out gaming forever. Its fcuking sick.
Reply
"This sucks for sony as the gaming community is notoriously immature and childish"
YES!... you want an example
Childish gamer: WAAA WAAA SONY WONT LET ME JAILBREAK MY CONSOLE THAT I PAID FOR WITH MY MONEY. LET ME DO WHAT I WANT WITH MY CONSOLE INCLUDING RUNNING CUSTOM FW WAAA WAAA WAAA
*console info gets stolen thanks to jailbreak*
Childish gamer: WAAA WAAA SONY GOT MY INFO STOLEN, WHY DON'T YOU PROTECT YOUR SERVERS BETTER SONY WAA WAA I WANT FREE STUFF NOW WAAA WAAA THIS IS ALL YOUR FAULT SONY WAAA WAAA
i swear with all this childish self centeredness this generation of gamers have become i want to just rule out gaming forever. Its fcuking sick.
Posted: Apr 26th 2011 5:15PM copa said
@PR0F3TA
"*console info gets stolen thanks to jailbreak*"
Are you mentally impaired? Customized firmware does not grant you access to Sony's entire payment services database. This is not someone running a warez mod on their PS3. These are criminals who directly compromised Sony's servers over the Internet.
Just take a one day break from crying and bitching about GeoHot, and focus on the grown-up problem. Our personal and financial information is being traded and resold all over the world right now.
Reply
"*console info gets stolen thanks to jailbreak*"
Are you mentally impaired? Customized firmware does not grant you access to Sony's entire payment services database. This is not someone running a warez mod on their PS3. These are criminals who directly compromised Sony's servers over the Internet.
Just take a one day break from crying and bitching about GeoHot, and focus on the grown-up problem. Our personal and financial information is being traded and resold all over the world right now.
Posted: Apr 26th 2011 6:02PM copa said
@PR0F3TA
"It has EVERYTHING to do with him and his problems with Sony."
I have no idea what in God's name you are talking about.
The criminals who cracked Sony's infrastructure were not using customized firmware, or any other technical means made possible by Geohot's firmware modifications. They used the same Internet server hacking techniques that all criminal gangs use when they are getting poorly protected user info from e-commerce sites.
These criminals did not break into the servers to show support for GeoHot, or Anonymous, or OtherOS. They broke into the servers because they are criminals and they want to take your goddamn money.
Reply
"It has EVERYTHING to do with him and his problems with Sony."
I have no idea what in God's name you are talking about.
The criminals who cracked Sony's infrastructure were not using customized firmware, or any other technical means made possible by Geohot's firmware modifications. They used the same Internet server hacking techniques that all criminal gangs use when they are getting poorly protected user info from e-commerce sites.
These criminals did not break into the servers to show support for GeoHot, or Anonymous, or OtherOS. They broke into the servers because they are criminals and they want to take your goddamn money.
Posted: Apr 26th 2011 6:07PM The Aquacharger said
@daytripper
wait why is he downvoted for fixing his spelling error?
Reply
wait why is he downvoted for fixing his spelling error?
Posted: Apr 26th 2011 7:11PM pibs said
@(Unverified) I found out about it yesterday through reddit, although he never mentioned the part about them nabbing our infos :(
http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/
Reply
http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/
Posted: Apr 26th 2011 7:16PM Biscuits said
@copa Umm from what i remember this has happened to Apple.
http://www.cbc.ca/news/technology/story/2011/01/07/hacked-itunes-accounts-sale-china.html
http://www.pcworld.com/article/216025/hacked_itunes_accounts_continue_to_sell_in_china.html
Reply
http://www.cbc.ca/news/technology/story/2011/01/07/hacked-itunes-accounts-sale-china.html
http://www.pcworld.com/article/216025/hacked_itunes_accounts_continue_to_sell_in_china.html
Posted: Apr 26th 2011 8:39PM mechafenris said
@A Sandwich
I'd like some assurances from Microsoft they're not doing the same asinine stuff with my information that Sony did. That's not too much to ask as a PAID subscriber? Show us Microsoft that you're a bigger man than Sony and TELL us we're not to worry about YOUR security practices...
Not too much to ask for, right? I asked Sony to keep my info safe and they did NOT... so I want Microsoft to double efforts and keep my info out of slimy hands...
Reply
I'd like some assurances from Microsoft they're not doing the same asinine stuff with my information that Sony did. That's not too much to ask as a PAID subscriber? Show us Microsoft that you're a bigger man than Sony and TELL us we're not to worry about YOUR security practices...
Not too much to ask for, right? I asked Sony to keep my info safe and they did NOT... so I want Microsoft to double efforts and keep my info out of slimy hands...
Posted: Apr 26th 2011 9:04PM PR0F3TA said
@copa
http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/
" no ones personal information was accessible via this hack. Not to say they couldn't get it, but no one is admitting to it being available."
THANK YOU THANK YOU THANK YOU
Copa?
Reply
http://www.reddit.com/r/gaming/comments/gx6o4/im_a_moderator_over_at_psxscenecom_the_real/
" no ones personal information was accessible via this hack. Not to say they couldn't get it, but no one is admitting to it being available."
THANK YOU THANK YOU THANK YOU
Copa?
Posted: Apr 26th 2011 11:28PM ShadowXIII said
@PR0F3TA
Its not just gaming......(shakes head in disappointment).....its not just gaming..... The world is in a sad state lately.
Reply
Its not just gaming......(shakes head in disappointment).....its not just gaming..... The world is in a sad state lately.
Posted: Apr 27th 2011 1:30AM Sentox said
@PR0F3TA
As in, not to say they couldn't get it via other means. The post clearly states "no ones personal information was accessible via this hack". And if you want to believe whatever you read on the internet, then here you go:
http://www.g4tv.com/thefeed/blog/post/712160/hackers-rebug-ps3-program-not-responsible-for-psn-security-failure/
I'm sorry, but you clearly have no understanding of what's going on here. Jailbreaking a PS3 has nothing to do with breaking into PSN. The specific hack you link to merely enables debug functionality on a console. That has nothing to do with customer records.
But for the sake of argument, let's say we live in an Alice-through-the-looking-glass dimension of pure nonsense, and the recent jailbreaking of the PS3 did magically facilitate this attack. All that would mean is that Sony's system architects and/or network engineers are the most incompetent people on the face of the planet.
Reply
As in, not to say they couldn't get it via other means. The post clearly states "no ones personal information was accessible via this hack". And if you want to believe whatever you read on the internet, then here you go:
http://www.g4tv.com/thefeed/blog/post/712160/hackers-rebug-ps3-program-not-responsible-for-psn-security-failure/
I'm sorry, but you clearly have no understanding of what's going on here. Jailbreaking a PS3 has nothing to do with breaking into PSN. The specific hack you link to merely enables debug functionality on a console. That has nothing to do with customer records.
But for the sake of argument, let's say we live in an Alice-through-the-looking-glass dimension of pure nonsense, and the recent jailbreaking of the PS3 did magically facilitate this attack. All that would mean is that Sony's system architects and/or network engineers are the most incompetent people on the face of the planet.
Posted: Apr 27th 2011 8:37AM eat it said
@A Sandwich
why do you have to be an asshole?
Everyone of my posts regarding this is filled with advice on how to remove yourself from any kind of threat! is that any reason to make a snarky comment? you dick
people here are saying this could never happen anywhere else blah blah blah. When in fact it does happen everywhere else. This happens to banks! BANKS!
For all of you guys that think Micorsoft is immune, how many times have we seen windows or IE compromised? Sure it's not exactly the same but microsoft defintely has it's security holes that affect plenty of people
you're naive if you think this can't happen to any company. sony, microsoft, and google included.
Reply
why do you have to be an asshole?
Everyone of my posts regarding this is filled with advice on how to remove yourself from any kind of threat! is that any reason to make a snarky comment? you dick
people here are saying this could never happen anywhere else blah blah blah. When in fact it does happen everywhere else. This happens to banks! BANKS!
For all of you guys that think Micorsoft is immune, how many times have we seen windows or IE compromised? Sure it's not exactly the same but microsoft defintely has it's security holes that affect plenty of people
you're naive if you think this can't happen to any company. sony, microsoft, and google included.
Posted: Apr 26th 2011 4:29PM DanielMeier said
This is turning out to be a real god damn mess. I know its not Sonys fault some morons jacked their crap, but come on! staying silent for so long, and now this crap!
Not cool Sony, not cool at all.
Now i need to cancle my Visa card and get a new one.
I know chumps are cheap labor for coding the backbone for your PSN service, but next time shell out some more cash and hire humans.
Reply
Not cool Sony, not cool at all.
Now i need to cancle my Visa card and get a new one.
I know chumps are cheap labor for coding the backbone for your PSN service, but next time shell out some more cash and hire humans.
Posted: Apr 26th 2011 4:31PM DanielMeier said
Sorry, should have spelled CHIMPS, and not chumps.
Reply
Posted: Apr 26th 2011 4:35PM daytripper said
@sweenish
Has anyone ever tried to break in those other networks?
Reply
Has anyone ever tried to break in those other networks?
Posted: Apr 26th 2011 4:40PM mrantimatter said
@Anticrawl
What, it's their fault some self-obsessed hackers released the encryption keys and made all this possible?
If only they woudl have just let the pirates do as they please, and not say, tried to defend the platform! Don't they know those hackers only have consumer rights and protections in mind?
Reply
What, it's their fault some self-obsessed hackers released the encryption keys and made all this possible?
If only they woudl have just let the pirates do as they please, and not say, tried to defend the platform! Don't they know those hackers only have consumer rights and protections in mind?
Posted: Apr 26th 2011 4:40PM DanielMeier said
@sweenish
Well ok its partially their fault, thinking their service was secure. But there is another party to blame here too, the damn low life hackers.
I won't stick up for Sony, cause this situation is just dumb as hell, and we all know Sony has done stupid decisions through out this console generation. but saying its only their fault is just stupid.
Reply
Well ok its partially their fault, thinking their service was secure. But there is another party to blame here too, the damn low life hackers.
I won't stick up for Sony, cause this situation is just dumb as hell, and we all know Sony has done stupid decisions through out this console generation. but saying its only their fault is just stupid.
Posted: Apr 26th 2011 4:41PM shinjix2 said
@Anticrawl
Correct me if I'm wrong but didn't GeoHotz open the gateway for all this crap to happen. I'm sure we would be fine right now if Mr. Dip$hit didn't decide to make a profit by selling everyone the console information....
Sony had every right to pick a fight with him! Too bad they can't go back after him for starting this mes!!!
Reply
Correct me if I'm wrong but didn't GeoHotz open the gateway for all this crap to happen. I'm sure we would be fine right now if Mr. Dip$hit didn't decide to make a profit by selling everyone the console information....
Sony had every right to pick a fight with him! Too bad they can't go back after him for starting this mes!!!
Posted: Apr 26th 2011 4:42PM BananaBoat said
@DanielMeier - You don't need to cancel your card. Sony DOES need to offer credit monitoring to every single last damn person this effects though, myself included, if credit card details were exposed.
This is a mess.
Reply
This is a mess.
Posted: Apr 26th 2011 4:44PM daytripper said
@Anticrawl
So they don't have a right to protect their IP? Let me know where you live so I can rob you. You wouldn't mind, right?
Reply
So they don't have a right to protect their IP? Let me know where you live so I can rob you. You wouldn't mind, right?
Posted: Apr 26th 2011 4:46PM Anticrawl said
@shinjix2
Nope it was Jack Tretton himself who said early in the console life, commenting on the 360's security being breached that their console's security was perfect and challenged anyone to run pirated or homebrewed games. So they used other OS to run homebrew and Sony got scared, they removed the feature to stop progress in the hacking community. Then they threatened legal action because the community was using 100% legal means to run homebrew through Other OS after removing the feature. Obviously they were pissed at this point, companies walking all over citizens because they are above the law and whatnot. So out of spite they doubled their efforts and found a much easier way to hack the console. That is when the Geohotz shit happened.
Regardless as I said this is an attack on the SERVERS. A couple security keys for the CONSOLE has nothing to do with breaching a server and stealing stored information.
Reply
Nope it was Jack Tretton himself who said early in the console life, commenting on the 360's security being breached that their console's security was perfect and challenged anyone to run pirated or homebrewed games. So they used other OS to run homebrew and Sony got scared, they removed the feature to stop progress in the hacking community. Then they threatened legal action because the community was using 100% legal means to run homebrew through Other OS after removing the feature. Obviously they were pissed at this point, companies walking all over citizens because they are above the law and whatnot. So out of spite they doubled their efforts and found a much easier way to hack the console. That is when the Geohotz shit happened.
Regardless as I said this is an attack on the SERVERS. A couple security keys for the CONSOLE has nothing to do with breaching a server and stealing stored information.
Posted: Apr 26th 2011 4:54PM Ballistic H said
@sweenish
Unless you guys don't watch news AT ALL, crap like that (personal infos, credit card numbers stolen) happens: Bank of America breach, CitiBank, etc.
Reply
Unless you guys don't watch news AT ALL, crap like that (personal infos, credit card numbers stolen) happens: Bank of America breach, CitiBank, etc.
Sorry, you must be logged in to leave a comment.
Featured Stories
Persona 3, Tactics Ogre, and other PSP RPGs that will live on my Vita
Posted on Feb 22nd 2012 5:45PM
The most popular posts
in the last 7 days
- Rumor: Japanese Vita devs jumping ship, Sony responds 124 comments
- Buy 2 get 1 free on select Vita games at GameStop starting today 114 comments
- Sony's Rohde: proprietary Vita cards 'completely necessary' to combat piracy 112 comments
- Sony: Call of Duty blasting onto Vita this fall 89 comments
- Asura's Wrath review: Wrecking the curve 84 comments










