Additional Information


Content

Sony to appeal £250,000 fine for hack into PlayStation Network

Sony Computer Entertainment has been fined £250,000 for a hack on its PlayStation Network that compromised the personal details of millions of its users.

Sony PlaySation: Sony fined £250,000 for hack into the network

Sony PlaySation: Sony fined £250,000 for hack into the network

Share this article

The decision is being disputed by Sony, which is planning an appeal after "strongly disagreeing" with the ruling by the Information Commissioner’s Office (ICO).

Sony is objecting to the fine, citing that the ICO admitted the hack in 2011 was a determined criminal attack, that there was "no evidence that encrypted payment card details were accessed" and "personal data is unlikely to have been used for fraudulent purposes".

A Sony spokesman said: "Criminal attacks on electronic networks are a real and growing aspect of 21st century life and Sony continually works to strengthen our systems, building in multiple layers of defence and working to make our networks safe, secure and resilient."

The ICO imposed the fine after ruling that Sony breached the Data Protection Act by not putting sufficient safeguards in place to protect users of the Sony PlayStation Network.

Sony was victim to Distributed Denial of Service (DDoS) attacks in April of 2011 that also compromised information including the passwords, names, addresses, email addresses, and dates of birth of PlayStation Network users.

Although there was no evidence encrypted payment card details were accessed, Sony was reprimanded because details including passwords will have been used by people to control other online accounts and services.

The investigation found the attack could have been prevented if Sony had updated its software, while the electronics firm was also guilty of not anticipating an attack on systems, despite being subject to server DDoS attacks before the April 2011 incident.

David Smith, deputy commissioner and director of data protection at ICO, said: "If you are responsible for so many payment card details and log-in details, then keeping that personal data secure has to be your priority. 

"In this case, that just didn't happen, and when the database was targeted – albeit in a determined criminal attack – the security measures in place were simply not good enough.

"There's no disguising that this is a business that should have known better. It is a company that trades on its technical expertise, and there's no doubt in my mind that they had access to both the technical knowledge and the resources to keep this information safe."

This article was first published on marketingmagazine.co.uk

Before commenting please read our rules for commenting on articles.

If you see a comment you find offensive, you can flag it as inappropriate. In the top right-hand corner of an individual comment, you will see 'flag as inappropriate'. Clicking this prompts us to review the comment. For further information see our rules for commenting on articles.

comments powered by Disqus

Additional Information

Latest jobs Jobs web feed

FROM THE BLOGS

The Wall blogs

Infographic: The rise of the feed External website

by Chris Quigley, 28/08/2014

 

Household probiotics External website

by Greg Taylor, 27/08/2014

 

The blurred lines of native ads External website

by Brian Brady, 27/08/2014

 

Back to top ^