SONY Corp says the credit card data of PlayStation users around the world may have been stolen in a hack that forced it to shut down its PlayStation network for the past week, disconnecting 77 million user accounts.
Some players brushed off the breach as a common hazard of operating in a connected world, and Sony said some services would be restored in a week.
But industry experts said the scale of the breach was staggering and could cost the company billions of dollars.
“Simply put, one of the worst breaches we’ve seen in several years,” said Josh Shaul, chief technology officer for Application Security Inc, a New York- based company which is one of the country’s largest database security software makers.
Sony said it hads no direct evidence credit card information was taken, but said “we cannot rule out the possibility”.
It said the intrusion was “malicious” and the company had hired an outside security firm to investigate. It hads taken steps to rebuild its system to provide greater protection for personal information and warned users to contact credit agencies and set up fraud alerts.
“Our teams are working around the clock on this, and services will be restored as soon as possible,” it said in a blog post on Tuesday. The company shut down the network last Wednesday after it said account information, including names, birth dates, e-mail addresses and log-in information was compromised for certain players in the days prior.
Sony says people in 59 nations use the PlayStation network. Of the 77 million user accounts, about 36 million are in the US and elsewhere in the Americas, 32 million in Europe and nine million in Asia, mostly in Japan. Purchase history and credit card billing address information may also have been stolen but the intruder did not obtain the threedigit security code on the back of cards, Sony said.
Spokesperson Satoshi Fukuoka said the company had not received any reports yet of credit card fraud or abuse resulting from the breach.
Shaul said not having direct proof of credit card information theft should not instill a sense of security, and could mean Sony just did not know what files were touched. “They indicated they’re worried about it, which is probably a very strong indication that everything was stolen,” he said.
If the intruder successfully stole credit card data, the heist would rank among the biggest known thefts of financial data.
Recent major hacks included about 130 million card numbers stolen from payment processor Heartland Payment Systems. As many as 100 million accounts were lifted in a break-in at TJX Cos, owner of a chain of US discount retailers.
Albert Gonzalez, a Miami hacker, was sentenced last year to 20 years in prison for the attacks.
The Ponemon Institute, a data-security research firm, estimated the cost of a data breach involving a malicious or criminal act averaged $318 (R2114) per compromised record last year, up 48% from the year earlier.
That could pin the potential cost of the PlayStation breach at more than $24-billion (R159.6-billion). Sapa-AP, Reuters