Destructive cyberattack and data leak at Sony Pictures Entertainment
Sony Pictures Entertainment suffered a destructive cyberattack that disrupted business operations and resulted in the theft and public release of internal data. The FBI publicly stated it concluded North Korea was responsible for the attack. Later U.S. Department of Justice statements about related cyber conspiracies also referenced the Sony Pictures incident.
First reported December 19, 2014Espionagemed overall confidence
Sony Pictures employees and business partners whose data was exposed
Initial access
unknown
Impact
data_theft
service_disruption
extortion
financial_loss
Attribution
North Koreahigh confidence
The FBI publicly concluded North Korea was responsible in its 2014 statement; later DOJ materials reference the incident in the context of DPRK-linked activity.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Implement robust privileged access management and limit lateral movement pathsReduces the ability of intruders to access sensitive file shares and administrative tooling used to disrupt operations.
Soon
Enhance data loss prevention and secure storage for sensitive internal documentsLimits the scope of data exposure if attackers access internal repositories.
Later
Practice incident response for destructive and leak/extortion scenariosImproves containment, communications, and business continuity for high-impact attacks.
Detection ideas
Detect suspicious privilege escalation and lateral movement across file servers
Alert on new admin group membership, remote admin share access, and authentication to many servers from a single workstation.
Data sources: Windows Security Event Logs, EDR telemetry, SMB logs
Monitor for large-scale data staging and exfiltration
Identify unusual compression/archiving followed by outbound transfers to rare external destinations.
Data sources: Proxy logs, NetFlow/flow logs, EDR telemetry