Hackers say they’ve exposed more holes in Sony’s security

LONDON — Another massive data breach at Sony has left hackers exulting, customers steaming and security experts questioning why basic fixes haven’t been made to the company’s stricken cybersecurity program.

Hackers say they managed to steal a massive trove of personal information from Sony P

ictures’ website using a basic technique which they claim shows how poorly the company guards its users’ secrets. Security experts agreed Friday, saying that the company’s security was bypassed by a well-known attack method by which rogue commands are used to extract sensitive data from poorly-constructed websites.

“Any website worth its salt these days should be built to withstand such attacks,” said Graham Cluley, of Web security firm Sophos. Coming on the heels of a massive security breach that compromised more than 100 million user accounts associated with Sony’s PlayStation and online entertainment networks, Cluley said the latest attack suggested that hackers were lining up to give the company a kicking.

“They are becoming the whipping boy of the computer underground,” he said.

Culver City, California-based Sony Pictures has so far declined to comment beyond saying that it is looking into the reported attack — which saw many users’ names, home addresses, phone numbers, emails, and passwords posted on the Web.

It wasn’t clear how many people were affected. The hackers, who call themselves Lulz Security — a reference to the Internetspeak for “laugh out loud”– boasted of compromising more than 1 million users’ personal information — although it said that a lack of resources meant it could only leak a selection on the Web. Their claim could not be independently verified, but several people whose details were posted online confirmed their identities to The Associated Press.

The group ridiculed Sony for the ease with which it stole the data, saying that the company stored peoples’ passwords in a simple text file — something it called “disgraceful and insecure.”

Several emails sent to accounts associated with the hackers as well as messages posted to the microblogging site Twitter were not returned, but in one of its tweets Lulz Security expressed no remorse.

“Hey innocent people whose data we leaked: blame Sony,” it said.

Sony’s customers — many of whom had given the company their information for sweepstakes draws — appeared to agree.

Tim Rillahan, a 39-year-old computer instructor in Ohio, said he was extremely upset to find email address and password posted online for “the whole world to see.”

“I have since been changing my passwords on every site that uses a login,” he said in an email Friday. “Sony stored our passwords in plain text instead of encrypting the information. It shows little respect to us, their customers.”

He and others complained that they had yet to hear from the company about the breach, news of which is nearly a day old.

John Bumgarner, the chief technology officer for the U.S. Cyber Consequences Unit — a research group devoted to monitoring Internet threats — was emphatic when asked whether users’ passwords could be left unencrypted.

“Never, never, never,” he said. “Passwords should always be hashed. Some kind of encryption should be used.”

Bumgarner, who’s been critical of Sony’s security in the past, said the company needed to take a hard look at how it safeguards its data.

“It’s time for Sony to press reset button on their cybersecurity program before another incident occurs,” he said.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Logo for news use featuring Snohomish County, Washington. 220118
Health officials: Three confirmed measles cases in SnoCo over holidays

The visitors, all in the same family from South Carolina, went to multiple locations in Everett, Marysville and Mukilteo from Dec. 27-30.

Dog abandoned in Everett dumpster has new home and new name

Binny, now named Maisey, has a social media account where people can follow along with her adventures.

People try to navigate their cars along a flooded road near US 2 on Wednesday, Dec. 10, 2025, in Sultan, Washington. (Olivia Vanni / The Herald)
Temporary flood assistance center to open in Sultan

Residents affected by December’s historic flooding can access multiple agencies and resources.

Logo for news use featuring the Tulalip Indian Reservation in Snohomish County, Washington. 220118
Teens accused of brutal attack on Tulalip man Monday

The man’s family says they are in disbelief after two teenagers allegedly assaulted the 63-year-old while he was starting work.

A sign notifying people of the new buffer zone around 41st Street in Everett on Wednesday, Jan. 7. (Will Geschke / The Herald)
Everett adds fifth ‘no sit, no lie’ buffer zone at 41st Street

The city implemented the zone in mid-December, soon after the city council extended a law allowing it to create the zones.

A view of the Eastview development looking south along 79th Avenue where mud and water runoff flowed due to rain on Oct. 16, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
Eastview Village critics seek appeal to overturn county’s decision

Petitioners, including two former county employees, are concerned the 144-acre project will cause unexamined consequences for unincorporated Snohomish County.

Snohomish County commuters: Get ready for more I-5 construction

Lanes will be reduced along northbound I-5 in Seattle throughout most of 2026 as WSDOT continues work on needed repairs to an aging bridge.

Logo for news use featuring the municipality of Snohomish in Snohomish County, Washington. 220118
Snohomish man held on bail for email threat against Gov. Ferguson, AG Brown

A district court pro tem judge, Kim McClay, set bail at $200,000 Monday after finding “substantial danger” that the suspect would act violently if released.

Kathy Johnson walks through vegetation growing along a CERCLA road in the Mt. Baker-Snoqualmie National Forest on Thursday, July 10, 2025 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Activism groups to host forest defense meeting in Bothell

The League of Women Voters of Snohomish County and the Pacific Northwest Forest Climate Alliance will discuss efforts to protect public lands in Washington.

Debris shows the highest level the Snohomish River has reached on a flood level marker located along the base of the Todo Mexico building on First Street on Friday, Dec. 12, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
SnoCo offers programs to assist in flood mitigation and recovery

Property owners in Snohomish County living in places affected by… Continue reading

Two of the Helix newspaper founders, Tom Robbins and Paul Dorpat, at The Sky River Rock Festival on Aug. 31, 1968 in Sultan, WA. (Courtesy of Paul Dorpat)
‘A story worth telling’: Snohomish County did it before Woodstock

Local author J.D. Howard reminds readers of The Sky River Rock Festival, a forgotten music milestone.

The Naval Station Everett Base on Wednesday, Oct. 23, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Rebooted committee will advocate for Naval Station Everett

The committee comes after the cancellation of Navy frigates that were to be based in Everett.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.