Don’t do SECURITY. Do business SECURELY.

Sony says PlayStation Network breach exposed 77 million accounts

Sony revealed that an intrusion behind a week-long PlayStation Network outage had exposed personal data from around 77 million accounts.

Sony revealed that an intrusion into its PlayStation Network and Qriocity services had exposed personal information from around 77 million accounts. The disclosure came about a week after Sony took the network offline.

What happened

  • Sony shut down PlayStation Network on 20 April 2011 after detecting the intrusion.
  • Exposed data included names, addresses, email addresses, birth dates, and login credentials.
  • Sony said it could not rule out that credit card data had been taken, although it said there was no evidence that it had been.
  • The network stayed offline for weeks, and Sony faced criticism over the delay in informing customers.

Why it mattered

It was one of the largest consumer data breaches of its time and became a case study in breach notification and service outage costs. The UK ICO later fined Sony £250,000 over the incident.

Lessons for organisations

Notify affected customers promptly and be clear about what is and is not known. Segment systems, encrypt sensitive data, and rehearse incident response so that containment does not require taking whole services offline for weeks. Card data should be tokenised or held to PCI DSS standards.

Sources: Forbes, TechCrunch

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights