Sony Reels From Multiple Hacker Attacks Essay

PAGES
6
WORDS
2089
Cite

Sony Reels From Multiple Hacker Attacks In the past, many organizations - from Sony to NASA to the New York Times - have fallen victim to hacking incidents. In addition to costing organizations money, data breaches have also taken a significant toll on the trust customers have on affected businesses. It is therefore important to note that as entities continue to accumulate more PII of clients, the relevance of having in place adequate security measures cannot be overstated. This text reviews the 2011 Sony PSN hacking debacle. In so doing, it amongst other things discusses some of the measures that organizations ought to take to protect the private information of users. The text also speculates on why organizations are slow to report or acknowledge instances of data breach.

Sony Reels from Multiple Hacker Attacks

Overview

In the month of April, 2011, Sony experienced a massive external intrusion on its PlayStation Network. During the said intrusion, the account information of scores of the media conglomerate's PSN customers was accessed by the hackers. The damages Sony Suffered as a consequence of this particular outage are immense; this is particularly the case should one take into consideration the resulting compensation to users, the outcome of the various legal suits brought against the company, the costs associated with the release of security patches and other fixes, fines, loss of revenues during the outage period, loss of goodwill, etc.

To begin with, as part of the company's "Welcome Back" program, the existing members of PS (plus) service were granted a 30 additional days on their subscription (Yin-Poole, 2011). The program according to Yin-Poole was "designed to reward customers affected by the outage." Some of the security measures the company implemented, and for which it also had to incur some costs, include but they are not limited to, establishment of additional firewalls, enhancement of data encryption and protection, etc. In the UK, Sony according to Halliday (2013) was fined a total of 250,000 pounds for its failure to take appropriate measures to protect the information of users that had been compromised as a result of the hack. This according to Halliday (2013) is the largest fine ICO has imposed in recent times.

The total cost of the hacking incident has been estimated by various analysts to run into many millions of dollars. It would be difficult to in this case come up with the exact cost of the debacle. While Sony itself claims a total loss of $105 million, analysis such as Michael Pachter as Dutton (2012) observes are convinced that the company lost tens of millions. As Dutton further points out, one research manager at the International Data Corporation - IDC puts the total cost of breach at $250 million.

Most gamers, as the president of DFC Intelligence observes, do not "really hold a grudge against Sony" for this unfortunate intrusion incident (Dutton, 2012). As the author further points out, reputation wise, the company seems to have emerged from the debacle unscathed. This could be attributed to Sony's excellent handling of the entire incident. In that regard therefore, it would be safe to state that the incident cost Sony very few of its customers. As a matter of fact, Sony could have, in the final analysis, gained additional customers. According to the company, in addition to triggering the re-activation of approximately three million accounts that had been dormant, the breach led to activation of new accounts as more gamers joined the system (Dutton, 2012). As strange as this may sound, it is a claim collaborated by Jesse Divnich, the Vice President of EEDAR. In his opinion, the company's welcome back initiative could have exited customers -- both new and existing (Dutton, 2012). In other instances, such an incident could have led to a massive customer walkout.

One year after the hacking debacle, i.e. As of April, 2012, there were "no verifiable reports of any account holders having actual hard cash stolen or IDs hijacked" (Dutton, 2012). So far, i.e. As of December 2013, there has been no credit card fraud report that has been directly attributed to the data breach. Although no hack has in the recent past been successful or as massive as the one this text concerns itself with, Sony has had its PSN attacked at least one more time. For instance, in October 2011, intruders staged an unsuccessful attack on the company's PSN in an attempt to gain access to the various accounts of users (Hosaka, 2011).

2. Protecting the Private Information of Customers

Virtual services on the Internet routinely store PII and credit card information...

...

This effectively puts such information at risk of exposure should a hacking attempt succeed. In that regard, therefore, the need to have in place effective and adequate protection measures to protect the private information of clients cannot be overstated. According to Stewart (2013), there are two distinct security areas that companies processing credit card transactions and selling products over the internet must address. These according to the author include Transaction security and network security. When it comes to network security, Stewart (2013) points out that equipments attached to the Internet either directly or indirectly should be protected. On this front, the author notes that "firewalls serve an important role…" (Stewart, 2013, p. 377). With regard to transactional security, Stewart observes that to ensure that private transactions between web servers and other entities are securely completed, there is need to encrypt the said transactions. Hypertext Transfer Protocol Secure (HTTPS) is critical on this front (Stewart, 2013). The other measures an organization could adopt to protect customer interests and information include but they are not limited to setting "rules regarding access to the data, how the data is received, stored and transmitted, what information can be sent within the organization and what can be passed along to third parties" (Brooks, 2012). It is however important to note that even with adequate security measures in place, an attacker can still gain access to an organization's systems by exploiting a single vulnerability. In that regard therefore, no entity can boast of having in place virtually impenetrable protection measures.
3. Rehabilitating Hackers

If law enforcement agencies succeed in tracking down and arresting an extremely intelligent hacker, I believe there is every reason to "turn" such an individual into what some refer to as an ethical hacker. This would be more beneficial than sending such an individual to jail.

Converted intelligent hackers could become computer security analysts, consultants, or researchers. In such positions, they can greatly help reduce chances of attack on networked information systems. Further, in addition to helping flag system vulnerabilities, convert hackers can also come in handy in the development of security patches to help seal exploits and loopholes before they are utilized by individuals with ulterior motives. Some of the hackers from the past who have since converted and are now regarded digital world gems include but they are not limited to Kevin Mitnick and Sven Juschan. While Mitnick was, according to Warman (2009), at some point regarded America's most wanted hacker for his hacking exploits, Juschan earned his place in the hackers' 'hall of fame' while still a teenager for his role in the development of two worms that were at the time "found to be responsible for 70 per cent of all the malware seen spreading over the internet" (Warman, 2009). Today Mitnick according to Warman (2009) runs a successful computer security consultancy firm. Juschan on the other hand was according to Warman (2009) later on hired by Securepoint -- a respected firewall firm. In the final analysis therefore, it is not difficult to see why it would be better to rehabilitate an intelligent attacker, instead of sending them to jail.

4. Reluctance of Businesses to Announce Data Breaches

More often than not, businesses grossly understate the extent of data breaches. Additionally, many businesses appear reluctant to even acknowledge instances of such breaches. For instance, during the Sony hack debacle, the company was at first quick to downplay the extent of the external intrusion. When it first learnt of the attack, i.e. On April 20th 2011, the company according to Williams (2011) did not make an announcement. However, some hours later - after making the said discovery, the company issued a vague statement -- explaining that it was aware some of the PSN's functions were down. Users who attempted to sign in during the first two or so days were welcomed by a message stating that some maintenance work was on course across the network. On April 22nd 2011, the company requested its customers for more time -- "a full day or two" -- to investigate the extent of the outage and hence get the service running again (Williams 2011). The "full day or two" turned out to be 23 days. This is just but a classical case of the typical reaction of companies to downplay not only the extent but also the seriousness of data breaches. Other companies that have found themselves in the same situation as Sony include but they are not limited to…

Sources Used in Documents:

References

Brooks, C. (2012, Nov 12). Personally Identifiable Information: What it is and How to Protect it. Tech News Daily. Retrieved from http://www.technewsdaily.com/15421-personally-identifiable-information-definition.html

Dutton, F. (2012, April 30). The PSN Hack: One Year On. Eurogamer. Retrieved from: http://www.eurogamer.net/articles/2012-04-27-the-psn-hack-one-year-on

Halliday, J. (2013, January 24). Data Watchdog Fines Sony £250,000 Over PlayStation ID Hack. The Guardian. Retrieved from http://www.theguardian.com/technology/2013/jan/24/sony-fined-over-playstation-hack

Hosaka, T.A. (2011, October 12). Sony Hack October 2011: Thousands of PlayStation Network Accounts Targeted by Massive Attack. Huffington Post. Retrieved from http://www.huffingtonpost.com/2011/10/12/sony-hack-october-2011-playstation-network_n_1006661.html?
Warman, M. (2009, Nov 27). Top 10 Most Famous Hackers: We Present 10 Most Famous Hackers. The Telegraph. Retrieved from http://www.telegraph.co.uk/technology/6670127/Top-10-most-famous-hackers.html
Williams, M. (2011, April 27). PlayStation Network Hack Timeline. PCWorld. Retrieved from http://www.pcworld.com/article/226393/sony_playstation_network_breach_timeline.html
Yin-Poole, W. (2011, May 1). PSN: Sony Outlines "Welcome Back" Gifts. Eurogamer. Retrieved from http://www.eurogamer.net/articles/2011-05-01-psn-sony-outlines-welcome-back-gifts


Cite this Document:

"Sony Reels From Multiple Hacker Attacks" (2014, January 03) Retrieved April 23, 2024, from
https://www.paperdue.com/essay/sony-reels-from-multiple-hacker-attacks-180519

"Sony Reels From Multiple Hacker Attacks" 03 January 2014. Web.23 April. 2024. <
https://www.paperdue.com/essay/sony-reels-from-multiple-hacker-attacks-180519>

"Sony Reels From Multiple Hacker Attacks", 03 January 2014, Accessed.23 April. 2024,
https://www.paperdue.com/essay/sony-reels-from-multiple-hacker-attacks-180519

Related Documents

Anonymous is one of the groups that can be seen as participating in this form of hacktivism, as is Wikileaks. Wikileaks is probably the best know hactivist site to the general public because of the sheer volume of political information that it has made public and because of the unapologetic nature of the owner of the site. This is unfortunate in many ways because it has given individuals a false

They would sometimes be using the school curriculum as an excuse to hack pertinent information that are government or privately owned. At some point, these students would be challenging themselves if they will be able to create and send unnecessary information (such as computer viruses) to other computer systems. This will provide extreme joy and satisfaction for these students. However, the issue here lies on how can this be

Hacktivism Securing the Electronic Frontier Consider how cybercrime is defined and how it relates to the issue Internet vulnerabilities. Cybercrime is any illegal or illicit activity which is mediated by internet usage and which is aimed at accessing, stealing or destroying online data. This may include hacking of government websites, phishing scams, disruption of commercial service sites or penetration of privately held databases containing personal information about private citizens. The presentation given by

Such people may not generally take shelter under the canopy of hackers but as a result of the more serious attributes of their motivation. (Hacker Motivation) Most of the people are anxious about the probability of being an objective for exploitation by a hacker. It is quite normal that if a computer has been installed for home use and only connected to the Internet for two hours once a

Hacker Hacking, Web Usage and the Internet Hierarchy Computer hacking is perceived as a crime and is frequently motivated by economic interests such as the stealing of personal and credit information, or by ideological interests such as the disruption of a company's service or the acquisition of classified information from government or corporate sites. However, hacking is also quite frequently used as an instrument for the expression of political, philosophical and practical frustrations.

Hacker Culture and Mitigation in the International Systems The explosion of the internet technology in the contemporary business and IT environments has assisted more than 300 million computer users to be connected through a maze of internet networks. Moreover, the network connectivity has facilitated the speed of communication among businesses and individuals. (Hampton, 2012). Despite the benefits associated with the internet and network technologies, the new technologies have opened the chance