Sony disclosed that attackers breached the PlayStation Network and Qriocity platforms, exposing data tied to about 77 million users and forcing a shutdown that lasted roughly five weeks. The company said it detected the intrusion on 19 April and took days to confirm that personal information had been stolen, including names, addresses, email addresses, dates of birth, usernames, passwords, security answers, purchase history, and potentially payment-card data. Reports soon emerged of fraudulent card activity and claims that millions of card records were being offered for sale, while Sony said card data was encrypted and that it had no confirmed evidence of card theft or identity fraud at the time. Sony also publicly suggested possible links to Anonymous, though the group denied carrying out the intrusion while acknowledging separate denial-of-service activity against Sony sites.
The breach drew regulatory and political scrutiny, including inquiries from U.S. lawmakers and assistance from the Department of Homeland Security, and ultimately cost Sony an estimated $171 million in response expenses, legal exposure, customer support, and identity-protection measures. UK regulators later fined Sony Computer Entertainment Europe £250,000, concluding the incident was preventable because the company had failed to apply up-to-date patches and had not followed password-security best practices such as hashing and salting. In the aftermath, Sony rebuilt PSN security, restored services in stages, issued repeated apologies, and later updated PlayStation Network terms to require binding arbitration and limit users’ ability to join future class-action lawsuits over disputes including security incidents.

See attribution, scope, and your downstream exposure.
16 events from the most recent confirmed update back to the earliest known activity.
The UK Information Commissioner's Office fined Sony Computer Entertainment Europe £250,000, concluding the breach was preventable because Sony had failed to maintain up-to-date software and proper password protections. Regulators said millions of UK users' personal information had been put at risk in the 2011 attack.
Sony updated PlayStation Network terms to require binding individual arbitration and waive class-action participation for future disputes unless users opted out by mail within 30 days. The move came after a series of hacks affecting more than 100 million subscriber accounts.
On 2011-06-06, security researcher Troy Hunt published an analysis criticizing Sony's password security practices in the wake of its 2011 breaches. The post added technical detail to public understanding of Sony's security failures by focusing specifically on password handling and storage weaknesses.
Sony told investors the PlayStation Network breach was expected to cost about 14 billion yen, or $171 million. The estimate included customer support, identity theft protection, legal expenses, and lost business tied to the incident.
Reports said Sony's PlayStation Network password reset page could be abused to change an account password using only an email address and date of birth, creating account-takeover risk because that data may have been exposed in the earlier breach. Sony took the password reset system and related web services offline, then said the URL exploit had been fixed.
Sony announced that phased restoration of PlayStation Network and Qriocity services had begun in some regions after the April breach and prolonged outage. The move marked the transition from recovery planning to actual service resumption for affected users.
In early May, Sony indicated that Anonymous might have been involved in the PlayStation Network intrusion. The suggestion represented a notable attribution claim, though Anonymous had already denied responsibility.
Public reporting on Sony's breach response said the company had failed to keep key systems up to date and exposed broader security weaknesses in how PlayStation Network data was protected. The revelations added technical detail to the incident and intensified criticism of Sony's security practices.
Sony Online Entertainment said it had shut down its network after discovering a separate intrusion that compromised nearly 25 million customer accounts. Reporting also said older SOE credit and debit card data had apparently not been encrypted, adding a major escalation beyond the earlier PSN breach.
Sony announced that portions of PlayStation Network and Qriocity were expected to come back online during the following week. The statement was part of the company's early recovery plan after the prolonged outage.
The House Committee on Energy and Commerce sought answers from Sony about the breach, and reports said the Department of Homeland Security was assisting the investigation. This marked a significant escalation from a corporate incident to a matter of government scrutiny.
Reports emerged that attackers were claiming to hold 2.2 million stolen credit card numbers tied to the PlayStation Network breach. The claim intensified concerns over whether payment card data had been compromised despite Sony's public uncertainty.
By late April, some PlayStation Network users reported unauthorized credit card activity following the breach. At the same time, Sony said it had no evidence that card data had been stolen and maintained that stored card information was encrypted.
As speculation mounted over responsibility for the attack, Anonymous denied carrying out the PlayStation Network breach while acknowledging separate denial-of-service actions against Sony websites. The denial became an early attribution development in the incident.
After several days of forensic analysis, Sony publicly disclosed that personal data from roughly 77 million PlayStation Network and Qriocity accounts may have been stolen. Exposed data potentially included usernames, passwords, addresses, birth dates, security answers, purchase history, and possibly credit card details.
Sony said it detected an unauthorized intrusion into the PlayStation Network and Qriocity services on 2011-04-19 and took the services offline. The outage marked the start of a breach that ultimately affected about 77 million accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
20 references tracked. Mallory keeps watching after this page renders.
pcmag.com
Open sourceweb.archive.org
Open sourcetheguardian.com
Open sourcetheregister.co.uk
Open sourcerferl.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.