We want to let you know that we have detected attempts on Sony Entertainment Network, PlayStation Network and Sony Online Entertainment (“Networks”) services to test a massive set of sign-in IDs and passwords against our network database. These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites or other sources. In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks. We have taken steps to mitigate the activity.
Less than one tenth of one percent (0.1%) of our PSN, SEN and SOE audience may have been affected. There were approximately 93,000 accounts globally (PSN/SEN: approximately 60,000 accounts; SOE: approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts. Only a small fraction of these 93,000 accounts showed additional activity prior to being locked. We are currently reviewing those accounts for unauthorized access, and will provide more updates as we have them. Please note, if you have a credit card associated with your account, your credit card number is not at risk. We will work with any users whom we confirm have had unauthorized purchases made to restore amounts in the PSN/SEN or SOE wallet.
As a preventative measure, we are requiring secure password resets for those PSN/SEN accounts that had both a sign-in ID and password match through this attempt. If you are in the small group of PSN/SEN users who may have been affected, you will receive an email from us at the address associated with your account that will prompt you to reset your password.
Similarly, the SOE accounts that were matched have been temporarily turned off. If you are among the small group of affected SOE customers, you will receive an email from us at the address associated with your account that will advise you on next steps in order to validate your account credentials and have your account turned back on.
We want to take this opportunity to remind our consumers about the increasingly common threat of fraudulent activity online, as well as the importance of having a strong password and having a username/password combination that is not associated with other online services or sites. We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account.
Posted on 12 October by Philip Reitinger – VP & Chief Information Security Officer, Sony Group












« Previous 1 2 3 Next »
107 CommentsAdd Yours
51
Posted on 12 October, 2011 at 11:00 am by Catkiller1
Off Topic:
Please can we have a “Heads Up” update at a decent time today?
Also will we receive Arc The Lad in English this month? If not please could we have a different title to make up for it?
Fingers crossed that Mortal Kombat Arcade Kollection is released today & Sideway: New York!
Any chance of PLUS discounts on Rochard & Eufloria like the US got?
Kind Regards
52
Posted on 12 October, 2011 at 11:06 am by trutenprower
Hahaha dumb idiots. Well done Sony you have done a really good job informing us and stopping these losers from getting into people’s accounts. Good job.
@ Catkiller1
We don’t have a date yet for the English version of Arc the Lad yet. They will announce it when it is ready. It wasn’t Sony’s fault, the publisher sent them the wrong version.
53
Posted on 12 October, 2011 at 11:16 am by Bovrillor
This is why you use different Passwords for every account you have – usually these things occur when you use your e-mail password for other stuff.
I have a different password for every account I have (various stores mostly) – and a little black book in my desk with them all written down. Better safe than sorry.
54
Posted on 12 October, 2011 at 11:33 am by Huono_peleis
Better safe than Sony.
55
Posted on 12 October, 2011 at 11:45 am by Romansiii
Highly suspicious this attack right when Sony release’s 2 new exclusives and the Uncharted 3 multiplayer is happening. Perhaps Microsoft fan boys are disliking Sony’s new success.
56
Posted on 12 October, 2011 at 11:46 am by Catkiller1
@ trutenprower
Thanks I guess??!!
I already knew that, as it has been stated within the “Set Your Import Sights On Arcade Hits: Shienryu” post
I asked, as SONY are working on it & it would be good if they could hint at this month! I’m aware of the problems as I check the Blog on a regular basis.
Thanks for being kind enough to reply, but you shouldn’t have bothered i’m afraid
57
Posted on 12 October, 2011 at 11:48 am by Carnivius_Prime
Cheers for the heads up. Just occurs to me I can’t even remember what my password is since I changed it after the big ol’ hack attack earlier in the year.
58
Posted on 12 October, 2011 at 12:03 pm by starboy18x_x
thanks for the update i keep getting request from people saying hi this is there name and where there from its weird how i keep getting people i dont know keep on saying it could you please check into it and my account was banned on the 8th dan_gray for 7 days but it says the 17th going to be unbanned that is 9days could you rechange it or send me another email explainning the solution thanks
59
Posted on 12 October, 2011 at 12:17 pm by Izorpo
it’s a shame some peoples accounts have been compromised again – but if people are going to continue to use the same password – at least pick variants of it
here are some examples
iamstupid
14ms7up1d
I1mstup84
this way you can remember it is really stupid to use the same password for everything or if you don’t want to be constantly reminded of such inadequacies – buy a little book to write all the different logins in and never allow your browser to save passwords for you
60
Posted on 12 October, 2011 at 12:23 pm by Krisp1989
It’s great to see you reacting so quickly and informing the users right away. Good job Sony! Seems like you have learned a lot from the hackers in April.
61
Posted on 12 October, 2011 at 12:26 pm by Pamperdamps
Appreciate the heads up. What might be useful is naming the places that these “lists” of PSN accounts was gathered from. That way we can stop new registrations on these suspect sites/services.
Also hope this doesn’t affect PSN, enjoying Uncharted 3 MP to much.
62
Posted on 12 October, 2011 at 12:32 pm by PenguinGlen
Well I must admit I did have panic a bit at first as I assumed the PSN was offlien again. Thankfully it’s not.
I do greatly appreciate you informnig us about this Sony and hope you continue these excellent customer relations in the future. Kudos!
63
Posted on 12 October, 2011 at 12:36 pm by Skookie30
I like the new way of telling us a early heads up it means you are on the ball sony. i wouldn’t know what to look for as my download is nearly 900 items & done by me & me only.
64
Posted on 12 October, 2011 at 12:50 pm by Izorpo
@63
didn’t realise anyone would actually admit to being that lazy and stupid especially stating on a public blog that they actually save their passwords in their browser
so I wonder who the other 92,999 are then?
65
Posted on 12 October, 2011 at 12:58 pm by Catkiller1
@ POST NUMBER 63
WOW, JUST SIMPLY WOW!!!!!
66
Posted on 12 October, 2011 at 12:58 pm by jakster123x
Oh.
67
Posted on 12 October, 2011 at 1:02 pm by UIUoOoUIU
PlayStation Store Update ?
68
Posted on 12 October, 2011 at 1:06 pm by born2destroy
HAHA failed much attempt? Thanks for the update sony and thanks for increasing your defenses they worked better this time
69
Posted on 12 October, 2011 at 1:09 pm by born2destroy
***Also i forgot to add that considering the person who attacked it last time was caught what makes this person think they will get away. Some people are really stupid
70
Posted on 12 October, 2011 at 1:13 pm by Demonized
I’m going to go ahead here and say a very big well done to Sony.
Although the PSN hack should never have happened it did and taught Sony a very valuable lesson.
A major criticism back then was Sony’s communication to consumers over the whole affair and it obviously caused a huge breach of trust among customers.
I think that this goes a fair way to restoring some of that trust because Sony have basically said here is “Oh hey guys we’ve been attacked again but we’ve caught it, we’ve blocked accounts so that the ones that were compromised have no losses and we’ll get it up and running when you use the link we email you to reset your password, oh and by the way wise up and stop using the same username/password for everything in your life”.
This has also been done in a very timely fashion and imo has been very well communicated and the numers of effected accounts etc. broken down well too.
Thanks for letting us know Sony and again, well done. Even though it should always have been this way things happen, I can forgive people their mistakes so long as they learn from them and I believe that you have done.
71
Posted on 12 October, 2011 at 1:14 pm by Nightmare966
I’d like to note a few things: No one’s hacked anyone. There have been attempts to log into accounts, which translates as: I got this e-mails/passwords from a forum and I’ll try to use them as PSN log in details, surely someone’s using the same!
Anyways good job at SCEE/SOE for the quick report and action taken
72
Posted on 12 October, 2011 at 1:14 pm by Michelasso
I wonder how the hackers could successfully sign in if we were all forced to change password using one that was different from the previous one.
73
Posted on 12 October, 2011 at 1:50 pm by Carnivius_Prime
@61 I hear ya. Loving Uncharted 3 Multiplayer. Can’t wait for the full game. My most wanted purchase of the year by light years…
74
Posted on 12 October, 2011 at 2:52 pm by OttoT
Just last week I put my cc information on the PSS. Guess what I´m doing right now…
75
Posted on 12 October, 2011 at 3:11 pm by corncannon
just my two cents.from my experience with this..I got an e-mail to reset my account.
Here are some differences from what I am seeing.
I bought my ps3 in sept. So last time I Didn’t have an account.
This is the first time I’ve ever logged into anything with the id/pass other than the psn.
Never checked my trophies/nor do I have an android.
I have never purchased anything from psn nor is my CC info there.
The only thing I use ps3 for is the gaming,no facebook etc…
again just my two cents,maybe this can help narrow things down a bit.
76
Posted on 12 October, 2011 at 3:40 pm by fcpavao
Good to know you guys have it under control.
77
Posted on 12 October, 2011 at 4:07 pm by CMJE96
what do you do if the hackers uses your account. I recently toped up £10 in my wallet. What do I do if they have spent it. I was saving for Deus ex HR dlc!
78
Posted on 12 October, 2011 at 4:29 pm by Motor12345
Here’s why: http://www.winehq.org/pipermail/wine-users/2011-October/097753.html
79
Posted on 12 October, 2011 at 5:01 pm by DAYDANNY666
Skookie30 you TWONK what you on about?
80
Posted on 12 October, 2011 at 5:09 pm by Suhail3728
Not Again. But not all are affected by this. So it may not be as big as the last one. But what about the strong Security that they adopted after the last crash?
81
Posted on 12 October, 2011 at 5:43 pm by Marv78UK
Thanks for keeping us in the loop this time guys…
82
Posted on 12 October, 2011 at 5:49 pm by nfcribeiro
I just cancelled my credit card as I had an email from Amazon informing that an account with the same credit card details as my own, was created today. This was roughly at the same time these news started pouring out everywhere.
I fully checked and confirmed that the email is genuine, no question.
So regarding credit card details being safe… That’s just bs Sony, sorry.
83
Posted on 12 October, 2011 at 5:50 pm by mrsbunty
thank you for leting us know so quick this time sony
84
Posted on 12 October, 2011 at 5:54 pm by nfcribeiro
Sony if you are reading this, I am fully available to provide all the details related to the situation describe a couple of posts above and the be of all the help I can be.
85
Posted on 12 October, 2011 at 5:54 pm by monoliet
i only use one pasword on ps3
one one facebook both i change a lot
end one for gamessites
fast reply en fast action = good work !!!!
86
Posted on 12 October, 2011 at 5:57 pm by monoliet
82@ = noting to do from sony site = them very correct now
only pers. using same pas on every internet site
also on ps3 – facebook ext.
facebook = not very trustful .
87
Posted on 12 October, 2011 at 6:02 pm by Skookie30
before you call 1 a TWONK you should read my post again.
i like a quick response, that‘s a early heads up.
he said always look for unusual activity, & i said how when i have nearly 900 items in my download list all buy & downloaded by me get it NOW.
got demo & betas to make up that number. :/
88
Posted on 12 October, 2011 at 6:38 pm by IR_God
please dont shut down the network again you guys (Sony) move like old laddies at a nursing home and i will go crazy if it takes more then a month to fix again
89
Posted on 12 October, 2011 at 7:20 pm by liquidharker
well i was affected :/ password has been changed yet i didn’t receive an email. i usually get an email about everything psn does so Im baffled. had to ring up to be told ill be sorted within 48 hours and if there were any problems the network team would get in touch. seems a long time to simply reset my password and security questions. id have happily scanned my drivers licence or passport as proof ;(
oh and for some reason my birthday has changed which i didn’t think was possible.
90
Posted on 12 October, 2011 at 10:03 pm by manutreble
This hacking this really getting to annoyed me NOW Hackers get a Life……… good job Sony for posting this info
91
Posted on 12 October, 2011 at 11:20 pm by KILLO31
Please let it just blow away unlike the last time !
92
Posted on 13 October, 2011 at 12:57 am by Ivan_Krazy
My PS3 HDD is corrupted and cannot be fixed…… so a complete restore for me. The crap I am getting from Sony and hearing is just going beyond me. Thank you and adios!
93
Posted on 13 October, 2011 at 1:41 am by stargateheaven
your “change password” for PSN page has been down for months now.
FIX IT.
94
Posted on 13 October, 2011 at 4:20 am by fishier
o NOOOO not again these hackers have no lifes
95
Posted on 13 October, 2011 at 6:22 am by jacko_gfreak
If the psn gets hacked and shuts down when MW3 comes out i will die
96
Posted on 13 October, 2011 at 7:04 am by r3dx_iii
<3 Yay for open communication!
97
Posted on 13 October, 2011 at 8:42 am by assimtb
Hello everyone . I’ve got a ” little ” problem. I had to sign in to this account ( my american account) because my main account got hacked and i still didn’t recieve an email from sony , is it normal ? =/
98
Posted on 13 October, 2011 at 9:51 am by illage2
Ah, thanks for keeping us informed this time around Sony. Please do not take PSN offline for months again. At least this time you acted quickly before any real damage was done, and hopefully you’ll keep your customers in the loop in the future.
99
Posted on 13 October, 2011 at 3:36 pm by mrsbunty
why is it that i can’t aways sign into playstation blog?
100
Posted on 13 October, 2011 at 6:54 pm by scottsymons1985
@73 michelasso
because after the ‘Big Outage’ some people didn’t renew their accounts and change their passwords. They simply traded their PS3 and bought an XBOX 3[DELETED].
You cant please everyone.
p.s. Great work Sony! you have our FULL support.
« Previous 1 2 3 Next »
We close the comments for posts after 30 days. If you would still like to comment on this post, please use our contact form.