PlayStation Network Security Update

On Tuesday, April 26 we shared that some information that was compromised in connection with an illegal and unauthorized intrusion into our network. Once again, we’d like to apologize to the many users who were inconvenienced and worried about this situation.

We want to state this again given the increase in speculation about credit card information being used fraudulently. One report indicated that a group tried to sell millions of credit card numbers back to Sony. To my knowledge there is no truth to this report of a list, or that Sony was offered an opportunity to purchase the list.

One other point to clarify is from this weekend’s press conference. While the passwords that were stored were not “encrypted,” they were transformed using a cryptographic hash function. There is a difference between these two types of security measures which is why we said the passwords had not been encrypted. But I want to be very clear that the passwords were not stored in our database in cleartext form. For a description of the difference between encryption and hashing, follow this link.

To reiterate a few other security measures for your information: Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well. To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

We continue to work with law enforcement and forensic experts to identify the criminals behind the attack. Once again, we apologize for causing users concern over this matter.

Our objective is to increase security so our customers can safely and confidently play games and use our network and media services. We will continue to provide updates as we have them.

  • Man, this is way longer than I expected but then again I’d rather they do whatever necessary to not have this occur again.

  • offense – but would it have killed you guys to not have waited well over a week before figuring out the passwords were hashed?

    I mean, you do understand that it’s serious for us as consumers if we lose our private data (address, name) together with our credit card numbers. Just losing one of those on it’s own isn’t a terrible problem – but you can’t change your name and go into hiding “just to be safe”, see? Because if I get my identity stolen, and it’s used for something criminal – I’m [BUTTERFLIES AND FLOWERS]. Not just for a while, but for as long as my name stays the same.

    And on top of this, Kaz actually has the gall to state that Sony are committed to stopping credit card fraud against /their/ systems? You’ve screwed me over so many times now Sony I’ve lost count – what about at least trying to level with us here for once. Would it really hurt you as a company to do so? Inform us quickly about what sort of databases might have been breached, and what info had been linked.

  • Because what you’re doing now just gives off the impression that you’re not really concerned about our data at all. And that you’re either using the threat to users as an excuse – or that the real threat was actually only against Sony’s internal info, admin accounts, etc. If that’s the case, I’m sorry. But I don’t have time for “you maybe lost your identity and credit card to thieves, so be careful! Just in case!”.

    Not only is it useless for us, but it’s also very serious for us as users. If you actually had linked databases in a way that would actually allow sweeping datamining like this, Sony would also be in legal trouble in just about every country in the world. I hope you realize that.

    I’m not even being too dramatic about it – you already have half of the attorney generals in the States looking for ways to get more info out of you. And we still don’t know if the data lost actually stems from some “other” “implied” data-mining operation that Sony hasn’t told us about.

    But you just say: “we’re making things safer for you”. I don’t trust that. Why should I?

  • Thanks for the info but I’m still curious when we’ll start to see restoration and what sort of reimbursements we’ll get for subscription based games like free realms.

    Though I’m glad to see this is getting sorted out finally.

    See, we need specific information about what databases were linked, and what sort of data might have been breached and in what fashion. How were the credit card details stored. How does that differ between the regions, etc.

    P.S. Another thing – please don’t force a PS+ subscription on my account when the system comes back up. I don’t want to lose any games I buy this month when PS+ expires again. And my region doesn’t have any services tied to ps+, etc, so it’s not very interesting for me unless I want to just give you money for nothing in return. .. I’m guessing the system won’t ask me if I want the ps+ bonus or a regular purchase tied to my account “forever” (rather than just the 30 days).. if I’m already subscribed. So please sort that out.

  • Suprised my login still works :) but It looks like there will be no PSN update today then :(, hopefully there might come one later this week? :)

  • Clarifying that the passwords were hashed from the get-go probably would have saved Sony a lot of grief, and consumers a lot of stress. Regardless, this is obviously good news… hopefully, this will turn out to not be as big of a deal as it initially sounded it would be.

  • Well, that’s a bit of a relief. Still, I went ahead and changed any passwords I deemed insecure after this. Thanks, though.


    I wish someone would listen to THIS SAHREHOLDER!!!! I have 100 shares left to me by my recently deceased grand parents. I would like to ensure the integrity of those shares as I have lost money on them this past week. Now Call me Patrick Seybold, so that I can make sure that they are fine. I was only trying to help make sure MY INVESTMENT is fine. I might just have to sell em now. As your lack of Real communication and the distasteful treatment I have suffered at the hands of your FOSTER CITY HQ staff.


  • + Gerry_the_Veg on May 2nd, 2011 at 11:37 am said:

    I am guessing that you are relatively new to the internet and the PSN. Sony very rarely announces specific dates of release due to the fact that things can happen that may affect that particular release date. And then we would have the community in an uproar.

    People tend to complain if no date is stated, a given date is not met, or no date is specified. The best solution is keep the information open ended. I know that the PSN going back online is this week, thus I am happy.

    Oh well Im bored with this. I’ve been a Sony Fan since I first Received this Short-wave radio as a Gift. Used it to listen to radio stations the world over, it’s what initially started me on Your Company. Can you imagine in the 80’s being able to hear music from around the world all in the palm of your hand? TO hear news events as they happen, I even once heard a distress signal at night on it. Back then there was no internet. A typical short wave system at this time was Thousands of dollars yet Sony’s had it a small and compact form and an affordable price. I then went onto the walkman, then the discman which was very expensive at the time but a marvel to use(anti skip). Ps1, psone, ps2, then slim ps2, psp1000, psp 2000, psp3000, pspGo, ps3 phat 4 times (ket breaking). Sony phones, cameras, stereo equipment, tv’s, computers, heck I still have all that stuff. And the best thing was, with the older electronics, They All Still Work.

    I’lll just go get that radio now, might as well. Nothing else to really do this Evening.

    Also you said Two days initially, after two days I had all the info you needed…….

    Sold my shares………………….

  • Patience is a virtue for users who can get their entire thought into one post.

    In a day and age where things are far to often rushed unfinished to hit that magical “date” it’s good to see a major company understand that it’s perfectly fine to miss that date to give a higher quality product. Is it a coincidence that some of the best developers are also notorious for missing deadlines?

    If Sony is finding more ways to improve their system and to catch the person(s) responsible, then take your time. Rushing to appease the impatient is what results in things like this happening, as an extreme example. Or more common to an online gamer, day 1 patches to fix on disc glitches, bugs, or simply missing functionality.


    SCE/SCEA has the Network (PSN) that all internet partners (PS3 online games) use in order to bring their games and services us.

  • Still waiting for some kind of clarification about the usefulness of deleting our card info off the PSN prior to this breach. Seems like a very simple question to answer, yet I have asked 4 times (one in each new blog entry) and have yet to see an answer in any of these updates.

    Which makes me wonder, is there a law that says if we delete our info that it cannot be held on your system? Perhaps despite this law you guys still kept it on your servers and is why none of these ‘updates’ are commenting on it.

