Sony BMG distributed millions of music CDs containing the DRM products XCP and MediaMax, which installed software on Windows PCs with poor disclosure and serious security consequences. Researchers found that XCP used rootkit-like cloaking techniques, was difficult to remove, and exposed systems to compromise; Sony's own uninstaller introduced an additional vulnerability that attackers quickly began probing. MediaMax drew separate criticism because files could be installed even if users rejected the EULA, the software lacked a straightforward uninstall path, and later patches were also found to create new security flaws. Security firms, academics, and US-CERT warned that the software could degrade system stability, weaken defenses, and in some cases transmit listening-related data back to vendors.
The backlash led Sony BMG to halt use of the technology, recall affected titles, publish lists of impacted CDs, and offer exchanges and limited compensation to customers. Lawsuits and regulatory action followed, including challenges backed by the EFF and an FTC complaint alleging unfair and deceptive practices tied to undisclosed installation, inadequate consent, security vulnerabilities, and data collection. Sony BMG ultimately settled with the FTC, agreeing to improve disclosure, obtain authorization before installing software or collecting data, provide effective uninstall tools and patches, reimburse certain consumer losses, and stop using DRM on CDs sold in the United States.

See the reporting duties and controls this puts on the clock.
15 events from the most recent confirmed update back to the earliest known activity.
Sony BMG ultimately settled litigation over the XCP and MediaMax CDs, offering remedies and compensation to affected purchasers. The company also stopped placing DRM on CDs sold in the United States.
The U.S. Federal Trade Commission alleged that Sony BMG's XCP and MediaMax CDs used unfair and deceptive practices, including inadequate disclosure, difficult removal, security vulnerabilities, and unauthorized data collection. Sony BMG agreed to a settlement requiring clearer disclosures, consumer consent, uninstall tools and patches, CD exchanges, retailer support, and reimbursement of up to $150 for damage caused by removal attempts.
Ed Felten and Alex Halderman found that a Sony-provided patch for the MediaMax vulnerability created a separate security problem. The EFF subsequently advised users not to apply the patch.
On 6 December, Sony BMG and the Electronic Frontier Foundation issued a joint statement acknowledging the MediaMax vulnerability identified in SunnComm's software. The disclosure confirmed that another Sony BMG DRM technology posed security risks.
Researchers at iSEC Partners discovered that Sony BMG's MediaMax copy-protection software created security vulnerabilities on users' PCs, even when users did not install the software. The finding expanded the controversy beyond XCP to Sony's second DRM product line.
US-CERT advised users not to install software from unexpected sources such as audio CDs in response to the Sony BMG DRM controversy. The warning highlighted the broader security implications of software auto-installed from media.
Following the uninstaller controversy, independent researchers published tools to detect Sony BMG's DRM components and help close the resulting vulnerability. The releases provided users with alternatives to Sony's flawed removal approach.
Sony BMG's attempt to remove XCP introduced a separate vulnerability that could be exploited through proof-of-concept websites. Security firms warned that users who uninstalled XCP and then visited malicious sites could have their systems compromised.
Evidence cited by researcher Dan Kaminsky indicated that XCP had been installed across more than 500,000 networks. The estimate underscored the scale of exposure created by Sony BMG's DRM deployment.
The Electronic Frontier Foundation publicly challenged Sony BMG in November 2005, calling for recalls, refunds, repairs, and compensation for consumers affected by XCP and MediaMax. The group argued Sony's response was inadequate and that both DRM systems posed serious security and consumer-protection problems.
Sony BMG announced it would stop using the XCP technology, pull unsold affected CDs from retailers, and create an exchange program for consumers. The company later published a list of 52 impacted titles.
Sony BMG was sued over its copy-protected CDs as legal fallout from the XCP controversy began. The lawsuits alleged harm tied to the undisclosed installation and behavior of the DRM software.
Computer Associates announced that it would detect Sony BMG's DRM software as spyware, escalating industry criticism of the company's copy-protection technology. The move reflected growing concern that the software secretly altered systems and created security risks.
Security researcher Mark Russinovich publicly revealed that Sony BMG's XCP software behaved like a rootkit by hiding files and processes on users' systems. His disclosure triggered broad scrutiny of the software's security and consumer impact.
Sony BMG released millions of music CDs containing First4Internet's XCP and SunnComm's MediaMax copy-protection software in the United States and Canada. The software installed on Windows PCs, imposed playback and copying restrictions, and in some cases transmitted data or resisted removal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
10 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourceweb.archive.org
Open sourcenews.bbc.co.uk
Open sourceweb.archive.org
Open sourcenews.bbc.co.uk
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.