Sony’s PlayStation unit hit by MOVEit hack

Share post:

The division of Sony Group behind the PlayStation video consoles and games is the latest American-based organization to publicly acknowledge being victimized by the zero-day vulnerability in Progress Software’s MOVEit file transfer platform.

Sony Interactive Entertainment (SIE) has begun notifying almost 6,800 former employees and family members of current or former staff that their personal data was stolen from the company’s MOVEit system by a hacker at the end of May.

A copy of the letter being sent to affected people and filed with the Maine attorney general’s office has blanked out what personal information was copied. However, the filing notice says the information includes peoples’ name or other personal identifier and their Social Security numbers.

On May 28, before Progress Software announced the vulnerability, a threat actor used the vulnerability to download some SIE files stored on its MOVEit platform, the letter to victims says. SIE discovered the hack on June 2, after which the division took down and remediated the server and notified police.

The Clop/Cl0p ransomware gang has taken credit for discovering and exploiting the vulnerability.

 

Sony Group is headquartered in Tokyo, but SIE is headquartered in California.

As of today, researchers at Emsisoft estimate that 2,342 organizations around the world have publicly said data on tens of millions of customers, employees, or former employees was directly or indirectly (through their data processors) stolen in MOVEit hacks. That includes over 4 million people whose data was kept by the Colorado Department of Health Care Policy and Financing and 3.4 million mothers and children in Ontario whose data was kept by a registry of newborns.

Experts say that if your organization uses MOVEit, the IT department should assume its server has been hacked.

In the past two years, vulnerabilities in file transfer applications from IBM, Accellion and Fortra have been targeted by Clop/Cl0p and other attackers. And Progress Software’s other file transfer application, WS_FTP, was recently added to the list.

The post Sony’s PlayStation unit hit by MOVEit hack first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Google Chrome update essential for Windows users

The latest Chrome update has just been rolled out, bringing the version up to 124.0.6367.78/.79. This update is...

Cyber Security Today, Week in Review for week ending Friday, April 26, 2024

This episode features a discussion on the latest in the Change Healthcare ransomware attack, a vulnerability in an abandoned Apache open source project, the next step in Canada's proposed critical infrastructure cybersecurity law and the future

Cyber Security Today, April 26, 2024 – Patch warnings for Cisco ASA gateways and a WordPress plugin

This episode reports on the malicious plugin worm that refuses to die

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways