Sony PlayStation Network and Qriocity intrusion and prolonged outage
Sony disclosed that an external intrusion affected the PlayStation Network and Qriocity services, leading to a multi-week service outage and exposure of user account data. Sony announced it was investigating the compromise and took systems offline while rebuilding security controls. Public reporting cited Sony’s estimate of roughly 14 billion yen (about $171 million at the time) in costs tied to response and customer remediation.
First reported April 26, 2011Breachmed overall confidence
Public disclosures in cited sources describe an external intrusion but do not provide definitive public attribution to a specific actor.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Encrypt sensitive customer data at rest and minimize retained payment dataReduces impact of database compromise by limiting exposure of high-value data.
Soon
Implement strong access controls and segmentation for customer data storesLimits attacker movement from perimeter services into user databases and payment-related systems.
Later
Improve breach detection and notification playbooks (including user communications)Reduces time-to-detect and ensures rapid, consistent public and customer notifications when incidents occur.
Detection ideas
Alert on anomalous access to user data stores and bulk exports
Detect spikes in SELECT/EXPORT activity, unusual admin sessions, and large outbound transfers from database subnets.
Data sources: Database audit logs, Application logs, Network flow logs