Chronology of the attack on Sony's PlayStation Network

Sony sent a letter to Congress today that describes the details of the hacker attack on its PlayStation Network and The Station online gaming services.

The information shows how Sony’s information technology team discovered and then responded to the attacks, which forced Sony to shut down the services and tell more than 100 million registered users that their personal data might have been stolen. It also says that 12.3 million account holders had credit card information on the system, including 5.6 million in the U.S.

Sony says it believes it knows how the attack occurred but is reluctant to make details available. It has not yet determined who is responsible for the attack, although it found some evidence pointing to hacktivist group Anonymous on its PC online service servers. Sony said that major credit card companies have not reported any increase in fraudulent credit card transactions.

Here’s the timeline:

January 11, 2011. Sony sues George “GeoHot” Hotz and others for jailbreaking, or circumventing the security system of the PlayStation 3.

January 27, 2011. Sony asks for a temporary restraining order stopping Hotz from further distributing the jailbreak tools to users, who can download them and break the security on their machines so they can run unauthorized software.

February 12, 2011. Hotz posts a rap video on his YouTube page explaining his side of the case. (It now has 1.8 million views).

February 19, 2011. Hotz starts a blog about the lawsuit.

March 6, 2011. Court approves Sony request to access all the internet protocol addresses of the people who visited GeoHot’s blog to download the jailbreaking tools.

March 23, 2011. Sony claims that Hotz has fled to South America and destroyed evidence. That turns out not to be true, according to Hotz’s attorney.

April 3, 2011. Hacktivist group Anonymous launches a cyber attack against various Sony web sites in an operation called #OpSony in retaliation for Sony’s pursuit of George “GEoHot” Hotz and Graf_Chokolo.

April 11, 2011. Sony settles the PS 3 jailbreaking case with Hotz. Anonymous says it will continue with boycott of Sony on April 16.

April 19, 2011, 4:15 pm Pacific time. Members of the Sony Computer Entertainment network team detect unauthorized activity in the PlayStation Network system in San Diego, Calif. Certain systems are rebooting when they are not scheduled to do so. The network service team starts reviewing the logs from the system to see what is wrong. It takes four servers offline.

April 20, 2011, early afternoon. Sony’s team discovers evidence that an unauthorized intrusion has occurred and that data of some kind has been transferred off the PSN servers without authorization. Six more servers are found to have been possibly compromised. Sony hires a forensic investigation team that afternoon. That team begins to “mirror” Sony’s systems, a meticulous process.

The team can’t determine what has been taken and so it shuts the network system down. At that point, the 77 million registered users of the network can’t play online games, access their accounts, or purchase movies and other entertainment on the network. Sony’s experts have to delve through 130 servers and 50 programs.

April 21, 2011. Sony hires a second computer security and forensic consulting firm to provide more manpower.

April 22, 2011. The forensics team completes the mirroring of nine of ten servers that are believed to be compromised. Sony Computer Entertainment’s general counsel provided the FBI with information about the intrusion. Sony’s forensics team has not reached any conclusions at this point.

April 23, 2011. Sony’s forensics teams confirm that very sophisticated and aggressive techniques were used to obtain access, hide their presence from system administrators, and steadily escalate their privileges inside the servers. The intruders deleted log files to hide their work. Sony now realizes it needs yet another forensic team to help.

April 25, 2011. The forensics teams determine the scope of the personal data that has been stolen from all PSN and Qriocity service accounts, but the team does not know if credit card numbers have been accessed.

April 26, 2011. Sony provides public notice about the intrusion. It also notifies regulatory authorities in a variety of states about the criminal intrusion.

April 28, 2011. Hotz denies any involvement in PSN attack.

April 29, 2011. House of Representatives subcommittee asks for more information on the attack as it considers legislation to require companies to notify consumers in case of data theft.

April 30, 2011. Sony’s No. 2 executive, Kazuo Hirai, apologizes to Sony’s customers and holds the first public press conference about the attack. He says the PSN should be up within a week and that Sony has beefed up its security.

May 1, 2011. Sony finds new evidence that hackers broke into the servers of Sony Online Entertainment, the PC online gaming division of the company which runs online games such as Free Realms and EverQuest. Sony discovers a file that says “Anonymous,” “We are legion.” That’s the slogan for the hacktivist group.

May 2, 2011. Sony says it will explain what happened to Congress but won’t testify yet.

May 4, 2011. Sony sends letter to Congress answering questions.

[photo credit: ant network]

  • Facebook_is_the_SPAMMER

    Pretty crazy. The Japanese messed with the Americans in WII bombing Pearl Harbor. The Japanese got bombed the fck out. The Japanese is messing with an American hacking his own PS3. Now look at what they get. A big nuke on their PSN. woo woo !!! The Japs never learn, do they?

  • http://pulse.yahoo.com/_SRSK6OYOH3XNUIR7BZ6ZT762OQ David

    STFU!

  • http://pulse.yahoo.com/_ZB5KRNS5KL7D3JRHGGOMPPMILM Andy

    you are truly a dumb, uneducated moron. this has nothing to do with the fact that Sony is a Japanese company.

  • http://profiles.google.com/sutiivusan Steve Talavera

    people like should disappear off this world!! people like you make this world go rotten!

  • l2troll

    I have to agree. Everyone knows Americans have the biggest sacks. You know what else has big balls? Bulls. And you fk with the bull you get the horns. How you like them horns Sony?

  • l2troll

    I have to agree. Everyone knows Americans have the biggest sacks. You know what else has big balls? Bulls. And you fk with the bull you get the horns. How you like them horns Sony?

  • http://pulse.yahoo.com/_2F4Z7B3UCFQA6DUE6CTENSBQQQ Dijon

    so when can i FUCKIN GO ONLINE AGAIN, shit is gonna make me resort to alcohol….again

  • http://pulse.yahoo.com/_RV6AUYF5XE4JW2ASJ3MWTW6MR4 Mister Inevitable

    The guy is clearly trolling, and you guys are the dumb ones for feeding him lol. Anyway, I just wanna know when the PSN will be back up and running. I haven't been able to game for 2 weeks, and I'm tired of coming home from work with no gaming after a long day.

  • zipperskyn

    Doesn't look like they'll get this up anytime this month. If Sony is waiting to testify, that might take a while

  • Edwin v/d Broek

    the japs are better then you SPAMMER. and if you dont no, japenees people made more stuff than you no (look arround stupid fuck. And you do not no that hackers like that stuff to hack so.But whete and you will see and i think that sony ps about 6 monds a pay network will have for to listen to the gamer and for better protecten and i hoop so. So SPAMMER no you

  • http://venturebeat.com/2011/06/13/imf-cyber-attacking/ Security experts: Government may be behind major IMF cyber attack | VentureBeat

    [...] The expert didn’t say which country is thought to be behind the attack, but their cryptic reveal falls in line with what other security professionals are saying about it. The attack follows a string of recent high-profile security intrusions, including a breach in defense contractor Lockheed Martin’s system weeks ago, a Chinese-based phishing attack on Gmail users, and April’s attack on Sony’s PlayStation Network. [...]

  • http://venturebeat.com/2011/06/24/sony-psn-lawsuit/ Sony slapped with lawsuit over PlayStation Network outage | VentureBeat

    [...] store, as well as 4,000 pieces of add-on content for games. VentureBeat previously published a timeline for the PlayStation Network outage and credit card information theft scandal. You can view the full video of Sony Chief Executive [...]

  • http://www.e-learningfree.com/sony-slapped-with-lawsuit-over-playstation-network-outage Sony slapped with lawsuit over PlayStation Network outage | E-learning, E-book, Tutorial Online

    [...] store, as well as 4,000 pieces of add-on content for games. VentureBeat previously published a timeline for the PlayStation Network outage. You can view the full video of Sony Chief Executive Kazuo Hirai (pictured above) detailing the [...]

  • http://venturebeat.com/2011/06/29/sony-rearranges-video-game-management-team-amid-persistent-hack-attacks/ Sony rearranges video game management team amid persistent hack attacks | VentureBeat

    [...] Sony on Wednesday said it planned to rearrange the senior management of its video game unit just months after hackers shut down the PlayStation Network for nearly a month. [...]

  • http://venturebeat.com/2011/07/05/psn-japan-online/ Sony finally brings PlayStation Network fully online in Japan | VentureBeat

    [...] store, as well as 4,000 pieces of add-on content for games. VentureBeat previously published a timeline for the PlayStation Network outage. You can view the full video of Sony Chief Executive Kazuo Hirai (pictured above) detailing the [...]

  • http://venturebeat.com/2011/07/05/psn-redesign-coming/ Sony planning redesign of PlayStation Network | VentureBeat

    [...] store, as well as 4,000 pieces of add-on content for games. VentureBeat previously published a timeline for the PlayStation Network outage. You can view the full video of Sony Chief Executive Kazuo Hirai (pictured above) detailing the [...]

  • http://dailytechnologynews.org/hackers-steal-info-from-1-3-million-washington-post-accounts/ Hackers Steal Info From 1.3 Million Washington Post Accounts

    [...] that hold users’ personal data. The biggest incident of this kind in recent months was the breach of Sony’s PlayStation Network in which hackers stole more than 100 million customers’ [...]

  • http://venturebeat.com/2011/07/12/psn-ps3-welcome-back-sales/ PlayStation Network welcome back package boosts PS3 sales | VentureBeat

    [...] store, as well as 4,000 pieces of add-on content for games. VentureBeat previously published a timeline for the PlayStation Network outage. You can view the full video of Sony Chief Executive Kazuo Hirai (pictured above) detailing the [...]

  • http://venturebeat.com/2011/09/06/in-wake-of-psn-hack-sony-recruits-ehomeland-security-official-as-security-boss/ In wake of PSN hack, Sony recruits eHomeland Security official as security boss | VentureBeat

    [...] the move is critical to regaining the credibility and respect it lost during the hacking attack. During the weeks-long outage of the PlayStation Network, Sony promised that it would hire a top executive to run security at the [...]

  • http://prosglobal.tv/blog/2011/09/in-wake-of-psn-hack-sony-recruits-homeland-security-official-as-security-boss/ In wake of PSN hack, Sony recruits Homeland Security official as security boss

    [...] move is critical for Sony to regain the credibility and respect it lost during the hacking attack. During the weeks-long outage of the PlayStation Network, Sony promised that it would hire a top executive to run security at the [...]

  • http://onlinemagazine.pcriot.com/?p=39628 OnlineMagazine » Blog Archive » In wake of PSN hack, Sony recruits Homeland Security official as security boss

    [...] move is critical for Sony to regain the credibility and respect it lost during the hacking attack. During the weeks-long outage of the PlayStation Network, Sony promised that it would hire a top executive to run security at the [...]

  • http://venturebeat.com/2011/09/16/sony-sue-psn-tos/ Updated PSN terms remove right to collectively sue Sony | VentureBeat

    [...] rallies a group of loosely connected hackers under moral or political banners. (You can see a timeline for the PlayStation Network outage here.) Lulz Security, another rogue hacking group, also broke into Sony Pictures and compromised more [...]

  • http://venturebeat.com/2011/09/22/security-lessons-from-the-playstation-network-breach/ Security lessons from the PlayStation Network breach | VentureBeat

    [...] April 19th, Sony’s PlayStation Network and Qriocity services were infiltrated, and hackers walked away with personally identifiable information from more than 77 million accounts. The attack was one of the largest security data breaches in history, and Sony’s response has [...]

  • http://www.socialnetworkbackgroundcheck.com/security-lessons-from-the-playstation-network-breach/ Security lessons from the PlayStation Network breach | Social Network Background Check

    [...] April 19th, Sony’s PlayStation Network and Qriocity services were infiltrated, and hackers walked away with personally identifiable information from more than 77 million accounts. The attack was one of the largest security data breaches in history, and Sony’s response has [...]

  • http://prosglobal.tv/blog/2011/09/security-lessons-from-the-playstation-network-breach/ Security lessons from the PlayStation Network breach

    [...] April 19th, Sony’s PlayStation Network and Qriocity services were infiltrated, and hackers walked away with personally identifiable information from more than 77 million accounts. The attack was one of the largest security data breaches in history, and Sony’s response has [...]

  • http://tony14518.wordpress.com/2011/09/22/60/ tony14518

    [...] Actually myself is a victim of a personal data theft.  PlayStation Network is Sony’s online service  which allows users to play gemes online and provide games and other digital products  to purchase. To use this online service users have to register first, this requires  personal information include names, birthdays and family addresses, if users want to buy things in its online store, they also have to provide their credit card numbers. All these information are stored in Sony’s server. On April 2011, the PSN server was attacked by some hackers and millions of users’ personal data got stolen including their credit card information. Unfortunately I was one of the victims. In order to prevent further losses I had to cancel my credit card and apply a new one. Here is a link to the details of this attack: http://venturebeat.com/2011/05/04/chronology-of-the-attack-on-sonys-playstation-network/ [...]

  • http://www.gamecentral.biz/security-lessons-from-the-playstation-network-breach/ Security lessons from the PlayStation Network breach | Playstation News | Game Central | Game, New and updates

    [...] Apr 19th, Sony’s PlayStation Network and Qriocity services were infiltrated, and hackers walked divided with privately identifiable information from some-more than 77 million accoun…. The conflict was one of the largest confidence information breaches in history, and Sony’s [...]

  • http://venturebeat.com/2011/12/30/the-deanbeat-from-the-supreme-court-to-anonymous-2011-was-a-transformational-year-for-games/ The DeanBeat: From the Supreme Court to Anonymous, 2011 was a transformational year for games | VentureBeat

    [...] million users from logging in to play online games. The network stayed down for more than six weeks, forcing the CEO of Sony and top PlayStation executives to apologize to consumers and offer them goodies to lure them back to the [...]

  • http://venturebeat.com/2012/01/06/sony-to-name-kazuo-hirai-president/ Nikkei: Sony to name Kazuo Hirai president, but Stringer remains CEO | VentureBeat

    [...] the notorious Sony PlayStation Network hack occurred in the middle of 2011, Hirai made the announcement that network was back online in the U.S. Hirai obviously did not get [...]

  • http://marketers-network.com/nikkei-sony-to-name-kazuo-hirai-president-but-stringer-remains-ceo/ Nikkei: Sony to name Kazuo Hirai president, but Stringer remains CEO : Marketers-Network

    [...] the notorious Sony PlayStation Network hack occurred in the middle of 2011, Hirai made the announcement that the network was back online in the U.S. Hirai obviously did not [...]

  • http://venturebeat.com/2012/01/16/zappo-hack/ Zappos user accounts get hacked — but your credit card info is safe | VentureBeat

    [...] a security breach is never good news, things certainly could have been much worse for Zappos. Sony’s PlayStation Network hack, for example, compromised 12.3 million users’ credit cards and led to downtime of almost a [...]

  • http://www.socialnetworkbackgroundcheck.com/zappos-user-accounts-get-hacked-%e2%80%94-but-your-credit-card-info-is-safe/ Zappos user accounts get hacked — but your credit card info is safe | Social Network Background Check

    [...] a security breach is never good news, things certainly could have been much worse for Zappos. Sony’s PlayStation Network hack, for example, compromised 12.3 million users’ credit cards and led to downtime of almost a [...]

  • http://www.gov-grants.co.uk/zappos-user-accounts-get-hacked-but-your-credit-card-info-is-safe Zappos user accounts get hacked — but your credit card info is safe | Gov Grants

    [...] a security breach is never good news, things certainly could have been much worse for Zappos. Sony’s PlayStation Network hack, for example, compromised 12.3 million users’ credit cards and led to downtime of almost a month. [...]

  • http://creditcardapprovalguide.info/2012/01/zappos-user-accounts-get-hacked-%e2%80%94-but-your-credit-card-info-is-safe/ Credit Card Approval Guide » Blog Archive » Zappos user accounts get hacked — but your credit card info is safe

    [...] a confidence crack is never good news, things positively could have been most worse for Zappos. Sony’s PlayStation Network hack, for example, compromised 12.3 million users’ credit cards and led to downtime of roughly a [...]

  • http://venturebeat.com/2012/02/01/playstation-network-to-be-down-for-maintenance-most-of-thursday/ PSN to be down for maintenance most of Thursday | VentureBeat

    [...] always makes Sony’s gamers a little nervous these days, particularly after last year’s six-week outage after the network’s security was breached by [...]

  • http://www.zimtelegraph.com/?p=21419 Zappos user accounts get hacked — but your credit card info is safe | Zimbabwe Telegraph

    [...] h&#1072&#957&#1077 b&#1077&#1077n much &#959f poorer quality f&#959r Zappos. Sony’s PlayStation Network hack, f&#959r example, compromised 12.3 million users’ credit cards &#1072n&#1281 led t&#959 downtime [...]

  • http://www.zimguardian.com/?p=29048 Zappos user accounts get hacked — but your credit card info is safe

    [...] h&#1072&#957&#1077 b&#1077&#1077n much &#959f poorer quality f&#959r Zappos. Sony’s PlayStation Network hack, f&#959r example, compromised 12.3 million users’ credit cards &#1072n&#1281 led t&#959 downtime [...]

  • http://venturebeat.com/2012/05/01/know-thine-enemy-hacker-george-geohot-hotz-met-with-sony-engineers/ Know thine enemy? Hacker George “Geohot” Hotz met with Sony engineers | VentureBeat

    [...] in dealing with the PlayStation 3 jailbreak, the subsequent dealings with the hacker involved, the hacking of the PlayStation Network, and the resulting six-week disruption of the network last [...]

  • http://www.simplyboundless.com/2012/05/know-thine-enemy-hacker-george-geohot-hotz-met-with-sony-engineers/ Know thine enemy? Hacker George “Geohot” Hotz met with Sony engineers | Simply Boundless Entertainment

    [...] in dealing with the PlayStation 3 jailbreak, the subsequent dealings with the hacker involved, the hacking of the PlayStation Network, and the resulting six-week disruption of the network last [...]

  • http://www.ktkt.tk/?p=2808 Know thine enemy? Hacker George “Geohot” Hotz met with Sony engineers | Share Blog

    [...] the way it handled the PlayStation 3 jailbreak, the subsequent dealings with the hacker involved, the hacking of the PlayStation Network, and the resulting six-week disruption of the network last [...]

  • http://www.ktkt.tk/?p=5158 Kickstarter bug exposed data from over 70,000 early projects | Share Blog

    [...] security lapse isn’t a big deal in the grand scheme of things. The attack on Sony’s PlayStation Network affected more than 100 million users, 12.3 million of which had credit card data stored within the [...]

blog comments powered by Disqus