05 May 2011
Sony has said that the hacking group Anonymous is indirectly to blame for the data losses that have affected its customers, and may have taken a more direct role in the theft from the company's databases.
Kazuo Hirai, chairman of Sony Computer Entertainment America, said in a letter to the US Congress that the data hacking attack succeeded in penetrating Sony's security systems in part because the company was distracted by a distributed denial-of-service (DDoS) attack against the company by Anonymous.
Hirai explained that, as the DDoS attack was going on, a team of hackers using advanced techniques exploited a software flaw in Sony's systems and got access to its network.
The attackers then escalated the privileges they had on the system, while deleting log files to mask their actions.
Anonymous has denied any involvement in the theft of data, but Hirai said that the attackers had deliberately left a file on its servers named 'Anonymous' containing the group's catchphrase: 'We are legion.'
"Whether those who participated in the DDoS attacks were conspirators or whether they were simply duped into providing cover for a very clever thief, we may never know," Sony's letter said.
Hirai sent the letter rather than testifying in person at the US House Energy and Commerce Subcommittee on Commerce, Manufacturing and Trade Hearings, which is investigating the breach.
Sony also faces legal action from angry users over the affair.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
The Role: As a Field Service Engineer working from...
The Role: Make the most of your IT knowledge in one...
Head of IT / Infrastructure Manager (Marketing Services...
A Multi-national data analytic's and cloud computing...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
quote.. "Anonymous is indirectly to blame"
I think you'll find that under that definition.. Sony is also "indirectly to blame". The public are not that stupid Mr Sony.
Posted by: anonymous.. Ironically enough 06 May 2011
Absurd
What an absolutely absurd thing to say, Its Anonymous fault for possibly engaging in a DDoS attack? Really, so if i crash my car because i was looking at an advert on a bus shelter window would the advertiser be to blame for my accident? of course not! Sony has been very poor in addressing this security breach quickly and informing its customers of the problems and is now trying to push blame onto someone else. Get a grip Sony this a PR nightmare for you.
Posted by: Carl Dean 05 May 2011
How convenient for Sony
Public Relations 101: 1. Identify external organization with high public animosity ratings, i.e., "Anonymous." 2. Engage in nebulous shifting of blame to external organization. 3. Refuse to appear in public and answer questions under oath as to what really happened.
Posted by: ConcernedUser 05 May 2011