Sony Pictures Entertainment suffered a destructive cyberattack that shut down internal systems, exposed large volumes of confidential data, and led to the online leak of unreleased films, executive emails, contracts, salary information, and employee medical and personal records. The attackers, calling themselves Guardians of Peace, reportedly stole roughly 11TB of data and used the breach to pressure Sony over The Interview, a comedy depicting a plot to kill Kim Jong Un. The fallout triggered lawsuits from former employees, public embarrassment for senior executives after private emails were published, and major operational disruption as staff reverted to phones, fax machines, and handwritten notes while the company worked with the FBI and other authorities.
The intrusion escalated from data theft to coercion when the hackers threatened cinemas with a "9/11"-style attack if The Interview was shown, prompting major theater chains to drop the film and Sony to cancel its wide Christmas release before later restoring it through independent theaters and online platforms including YouTube, Google Play, Xbox Video, and Sony's own service. U.S. officials and the FBI publicly attributed the attack to North Korea, later tying it to alleged operative Park Jin Hyok and broader Lazarus-linked activity, while North Korea denied responsibility and some private researchers argued insider involvement may also have played a role. The case became a landmark example of cyber-enabled extortion, censorship pressure, and destructive state-linked intrusion against a major media company.

See attribution, scope, and your downstream exposure.
19 events from the most recent confirmed update back to the earliest known activity.
The U.S. government moved to charge Park Jin Hyok, an alleged North Korean operative, in connection with the 2014 Sony Pictures hack. The case tied the Sony intrusion to broader North Korean cyber operations, including WannaCry and the Bangladesh Bank theft.
WikiLeaks released a searchable archive of Sony documents obtained from the breach. The publication extended the public exposure of internal Sony emails and files months after the attack.
At a cybersecurity conference in Manhattan, FBI Director James Comey said the Sony attackers made operational security mistakes that exposed internet connections used exclusively by North Korea. He presented the remarks as additional detail supporting the FBI's attribution.
North Korea reacted angrily after the United States imposed sanctions in response to the Sony attack. The sanctions represented a formal U.S. retaliatory step tied to the attribution of the hack to Pyongyang.
Private-sector cybersecurity researchers challenged the FBI's conclusion that North Korea alone was behind the Sony hack, arguing that insider involvement was likely. Reports cited suspected former employees and said some public indicators could have been decoys.
Sony made The Interview available online through YouTube Movies, Google Play, Xbox Video, Sony's platform, and a dedicated website one day before its theatrical debut. The digital release marked a further reversal of the earlier cancellation.
Sony reversed its cancellation and announced that The Interview would be released in more than 300 theaters on Christmas Day, largely through independent cinemas. The move followed criticism that canceling the film had rewarded coercion.
North Korea rejected the U.S. accusation and proposed a joint investigation into the Sony hack. Pyongyang decried the allegations while continuing to deny direct involvement.
President Barack Obama criticized Sony's decision to pull The Interview, saying the company 'did the wrong thing.' His remarks came as the U.S. government publicly blamed North Korea for the hack.
The FBI announced that North Korea was responsible for the Sony Pictures cyberattack. U.S. officials said the attack was linked to the intimidation campaign around The Interview.
Former employees filed lawsuits alleging Sony failed to protect highly sensitive personnel information exposed in the breach. The compromised data reportedly included records on about 47,000 current and former employees.
Sony canceled the planned December 25 theatrical release of The Interview after major theater chains refused to show it following hacker threats. The company also canceled the New York premiere amid the same intimidation campaign.
Top U.S. theater circuits decided not to screen The Interview after the threats tied to the Sony hack. Their withdrawal removed the film from most planned venues and increased pressure on Sony to change release plans.
The Guardians of Peace issued threats warning of a '9/11'-style attack against theaters showing The Interview. The threats escalated the incident from data theft and leaks into coercion aimed at stopping the film's release.
Sony executives Amy Pascal and Scott Rudin apologized after racially insensitive private emails leaked from the stolen Sony data prompted public backlash. Pascal said she was deeply embarrassed and criticized publication of the stolen material.
An email attributed to the Guardians of Peace blamed the attack on Sony's planned release of The Interview and demanded the company stop showing the film. The message also taunted Sony and the FBI as the breach investigation continued.
North Korea publicly denied responsibility for the Sony Pictures hack while criticism mounted over The Interview. A DPRK statement also suggested sympathizers could have carried out the attack.
About a week after the intrusion became public, high-quality copies of several unreleased or recently released Sony films were leaked online. Reports said the movies were likely part of roughly 11TB of data stolen from Sony.
Sony Pictures Entertainment suffered a major cyberattack in November 2014 that forced the company to shut down its computer network and begin working with law enforcement. Later reporting said the destructive phase of the attack became public on November 24, 2014.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
43 references tracked. Mallory keeps watching after this page renders.
bbc.co.uk
Open sourceweb.archive.org
Open sourcefbi.gov
Open sourcetheguardian.com
Open sourceweb.archive.org
Open sourcenpr.org
Open sourcecomputerweekly.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.