PBS Hackers: We cracked Sony Pictures, compromised 1M accounts

Hacker group LulzSec, which claimed responsibility for breaking into PBS’ news website NewsHour, said it has broken into Sony’s movie site SonyPictures.com and compromised information about 1 million users.

The attacks could signal the emergence of another hacktivist group in LulzSec, one that takes up politically and other morally motivated attacks like hacker group Anonymous. The hacker group also posted a way to get into the Sony Pictures site — inviting readers to “plunder those 3.5 million music coupons while they can.” The group previously said it was targeting Sony in retaliation for how it handled the downtime and bringing the PSN back online. The group previously attacked PBS because of a feature called “WikiSecrets,” which shed an unfavorable light on WikiLeaks.

“We recently broke into SonyPictures.com and compromised over 1,000,000 users’ personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts,” the hacker group said in its official release. “Among other things, we also compromised all admin details of Sony Pictures (including passwords) along with 75,000 ‘music codes’ and 3.5 million ‘music coupons.’”

The hacker group said it was a simple SQL injection attack that allowed it to break into the network and steal information about the site’s users. It also said that the information it stole was not encrypted — another jab at Sony, which has faced criticism about its security after hackers were able break into the company’s online gaming network, the PlayStation Network (PSN). Purdue University security expert Dr. Gene Spafford told Congress that security experts knew Sony was running outdated versions of the Apache Web server software for the PSN that did not have a firewall installed.

Members of the LulzSec group were able to break into the PBS site several days ago and post a fake story that said rapper Tupac Shakur was still alive. It was the third high-profile hacking attack on a private network in a little more than a month. But now the group has apparently turned its eyes on Sony, which was forced to bring down the PSN and beef up security as a result of an earlier attack by an as-yet unidentified hacker group. A cyber attack on Sony’s PlayStation Network (PSN) led to hackers stealing sensitive information from potentially more than 100 million PSN and Station.com users.

The group has been quick to remind everyone that it is not a part of Anonymous — which regularly takes up political causes and sometimes commits hacks like this for amusement. Those within Anonymous — an amorphous and loosely associated group of hackers that are regulars on message boards like 4chan — typically use the term “lulz” to describe the amusement they get out of hacks like these.

  • http://venturebeat.com/2011/06/13/lulzsec-bethesda-hack/ LulzSec: “You’re welcome!” for hacking Bethesda, not stealing anything | VentureBeat

    [...] has claimed in the past month. The group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” The group said it was targeting Sony in retaliation for how it handled the downtime and bringing [...]

  • http://breachpool.wordpress.com/2011/06/13/lulzsec-%e2%80%9cyou%e2%80%99re-welcome%e2%80%9d-for-hacking-bethesda-not-stealing-anything/ LulzSec: “You’re welcome!” for hacking Bethesda, not stealing anything | The Breach Pool

    [...] has claimed in the past month. The group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” The group said it was targeting Sony in retaliation for how it handled the downtime and bringing [...]

  • http://www.e-learningfree.com/lulzsec-%e2%80%9cyou%e2%80%99re-welcome%e2%80%9d-for-hacking-bethesda-not-stealing-anything E-learning, E-book, Tutorial Online LulzSec: “You’re welcome!” for hacking Bethesda, not stealing anything

    [...] has claimed in the past month. The group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” The group said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://venturebeat.com/2011/06/14/lulzsec-ddos-party-attacks/ LulzSec hits U.S. Senate, throws a “DDoS Party” | VentureBeat

    [...] group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” The group said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://www.e-learningfree.com/lulzsec-hits-u-s-senate-website-throws-a-%e2%80%9cddos-party%e2%80%9d E-learning, E-book, Tutorial Online LulzSec hits U.S. Senate website, throws a “DDoS Party”

    [...] group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://venturebeat.com/2011/06/15/lulzsec-anonymous-civil-war/ Hit the deck: LulzSec and Anonymous start trading blows | VentureBeat

    [...] group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://venturebeat.com/2011/06/17/lulzsec-lulz-hack/ LulzSec’s real agenda? Who knows, but they love the Dreamcast | VentureBeat

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of [...]

  • http://venturebeat.com/2011/06/20/lulzsec-anonymous-bros/ Psyche! LulzSec and Anonymous are “bros,” hacker groups say | VentureBeat

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://www.goldfeed.in/Games/2011/psych-lulzsec-and-anonymous-are-%e2%80%9cbros%e2%80%9d-hacker-groups-say/ Psych! LulzSec and Anonymous are “bros,” hacker groups say | Mix Play News Games

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons &#1… It also said it was targeting Sony in retaliation for [...]

  • http://joeylakey.co.uk/blog/2011/06/psyche-lulzsec-and-anonymous-are-%e2%80%9cbros%e2%80%9d-hacker-groups-say/ Psyche! LulzSec and Anonymous are “bros,” hacker groups say « The Joe Lake Blog The Joe Lake Blog

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://venturebeat.com/2011/06/21/guardian-lulzsec-handles/ Security firm releases seven handles of suspected LulzSec members | VentureBeat

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://www.goldfeed.in/Games/2011/security-firm-releases-seven-handles-of-suspected-lulzsec-members/ Security firm releases seven handles of suspected LulzSec members | Mix Play News Games

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons &#1… It also said it was targeting Sony in retaliation for [...]

  • http://venturebeat.com/2011/06/21/lulzsec-snitch-payback/ Payback: LulzSec outs “snitches” that might have led to arrest of U.K. hacker | VentureBeat

    [...] previously broke into the Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” It also said it was targeting Sony in retaliation for how it handled the downtime of its [...]

  • http://venturebeat.com/2011/06/24/bioware-hacked-neverwinter-nights/ BioWare latest game company hit by hackers | VentureBeat

    [...] Hacker group Lulz Security, or “LulzSec,” said it recently broke into Bethesda Softworks’ secure network and could have compromised information regarding 200,000 of the company’s game players, but chose not to do so. The group previously broke into Sony’s Sony Pictures site and invited readers to “plunder those 3.5 million music coupons while they can.” [...]

  • http://venturebeat.com/2011/06/29/sony-rearranges-video-game-management-team-amid-persistent-hack-attacks/ Sony rearranges video game management team amid persistent hack attacks | VentureBeat

    [...] with lawsuit associated with the theft of personal data during the PSN attack, it also had its Sony Pictures website hacked with personal data stolen there [...]

  • http://venturebeat.com/2011/09/16/sony-sue-psn-tos/ Updated PSN terms remove right to collectively sue Sony | VentureBeat

    [...] timeline for the PlayStation Network outage here.) Lulz Security, another rogue hacking group, also broke into Sony Pictures and compromised more than 1 million [...]

blog comments powered by Disqus