Sony Pictures Entertainment was hit by a destructive cyber attack that took its network offline and led to the leak of films, emails, and employee personal data. A group calling itself the Guardians of Peace claimed responsibility, and the FBI later said the North Korean government was responsible.
What happened
- Attackers deployed malware that made thousands of Sony computers inoperable.
- Unreleased films, executives’ emails, salary details, and staff personal information were published online over the following weeks.
- The group issued threats against cinemas showing The Interview, a comedy about North Korea’s leader, and Sony initially cancelled its release.
- On 19 December 2014, the FBI said it had enough information to conclude that the North Korean government was responsible; North Korea denied involvement.
Why it mattered
It was one of the first times the US government publicly blamed a nation state for a destructive attack on a company, and it showed how cyber attacks could be used to coerce and embarrass organisations.
Lessons for organisations
Organisations should prepare for destructive attacks with tested offline backups and business continuity plans, and should limit the sensitive data kept in email. Incident response plans should cover communications and staff welfare, not just technical recovery.
Source: FBI
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.