First reportedDecember 19, 2014
ActivityNovember 24, 2014
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Sony Pictures Entertainment
  • Sony Pictures employees and business partners whose data was exposed

Initial access

  • unknown

Impact

  • data_theft
  • service_disruption
  • extortion
  • financial_loss

Attribution

North Korea high confidence

The FBI publicly concluded North Korea was responsible in its 2014 statement; later DOJ materials reference the incident in the context of DPRK-linked activity.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Implement robust privileged access management and limit lateral movement pathsReduces the ability of intruders to access sensitive file shares and administrative tooling used to disrupt operations.

Soon

  • Enhance data loss prevention and secure storage for sensitive internal documentsLimits the scope of data exposure if attackers access internal repositories.

Later

  • Practice incident response for destructive and leak/extortion scenariosImproves containment, communications, and business continuity for high-impact attacks.

Detection ideas

Detect suspicious privilege escalation and lateral movement across file servers

Alert on new admin group membership, remote admin share access, and authentication to many servers from a single workstation.

Data sources: Windows Security Event Logs, EDR telemetry, SMB logs

Monitor for large-scale data staging and exfiltration

Identify unusual compression/archiving followed by outbound transfers to rare external destinations.

Data sources: Proxy logs, NetFlow/flow logs, EDR telemetry

Sources