The Sony Pictures hack: wiped computers and a folder named Password
When attackers dumped Sony Pictures' internal files online in 2014, one of the folders was simply named Password, and it held unprotected login details for the studio's social media accounts and more.[3] This case file covers how the attack shut the studio down, what leaked, who the FBI blamed, and the one habit that turned a break-in into a skeleton key.
What happened
On November 24, 2014, Sony Pictures Entertainment employees found their computers taken over by a group calling itself the Guardians of Peace.[1][4] The attackers had already copied huge amounts of data, and then they set off malware that erased hard drives. Thousands of the studio's computers stopped working, and Sony took its entire network offline.[1][5]
Over the following weeks the stolen files were posted online in batches. They included unreleased films, scripts, executives' emails and salaries, and personal data on staff, including about 47,000 Social Security numbers.[4] One spreadsheet alone listed the name, location, employee ID, network username, salary and date of birth of more than 6,800 people.[5] On December 4, reporters combing the dump found the folder named Password.[3]
The group also issued threats against theaters planning to show a comedy about the assassination of North Korea's leader. Sony canceled the wide release, then let about 300 independent theaters screen it on Christmas Day and released it online on December 24.[4] On December 19, the FBI said the North Korean government was responsible.[1]
How they got in
According to the Justice Department, the attackers got their first foothold with spear-phishing, emails tailored to fool specific people into opening something harmful. Once inside, they stole confidential data, threatened executives and staff, and damaged thousands of computers.[2]
The Password folder shows why stolen data was so damaging. It held documents with usernames and passwords for the official Facebook, Twitter, YouTube and MySpace accounts of major films, stored without encryption and labeled in plain words.[3] Anyone inside the network did not need to guess where the keys were kept. The file names told them. Much of the other sensitive data, from salary sheets to health savings records, sat in ordinary spreadsheets on shared systems.[5]
How it was caught
There was nothing quiet about this attack, which announced itself on every screen. The investigation focused on who did it. The FBI pointed to lines of code, encryption methods and deletion techniques that matched earlier malware it tied to North Korea, internet addresses built into the malware that overlapped with known North Korean infrastructure, and similarities to a 2013 attack on South Korean banks and media.[1] Some outside experts questioned the attribution at the time.[6]
In September 2018 the Justice Department charged a North Korean programmer who, prosecutors say, worked for a government front company tied to North Korean military intelligence. The charges covered the Sony attack along with the 2016 theft of $81 million from Bangladesh's central bank and the 2017 WannaCry ransomware outbreak.[2]
What it cost
Sony set aside $15 million in early 2015 to deal with the investigation and repairs.[4] That figure leaves out the harder costs: weeks of disruption across a global studio, private emails read around the world, and thousands of employees whose Social Security numbers, pay and medical details were public.[4][5] The FBI called the attack a reminder that cyber threats were among the most serious national security dangers facing the country.[1]
The missing control
The missing control: no plaintext password files on shared drives. Passwords belong in a password manager or vault that encrypts them and records who opens them, not in spreadsheets and documents anyone on the network can read.
This would not have stopped the phishing email or the wiper. It would have limited how far the intruders could reach and how much they could expose. A password manager keeps logins encrypted, so a copied file is useless without the key, and it logs access, so a sudden sweep through the vault stands out. Labeled folders of plain passwords do the opposite, turning one foothold into access to accounts across the business.
What to do in your business
- Search for password files today. Look through shared drives, cloud folders and email for files with names like passwords, logins or accounts, and for spreadsheets with a password column.
- Move logins into a password manager. Use a business password manager with shared vaults for team accounts, then delete the old documents and change every password that was in them.
- Turn on two-step login for shared accounts. Social media, email and banking accounts should all need a second factor, so a leaked password alone is not enough.
- Lock down sensitive spreadsheets. Keep payroll, Social Security numbers and health data in the systems built for them, or at least in folders only the people who need them can open.
- Keep offline backups. Wiper attacks destroy data rather than hold it hostage. A recent backup that the network cannot reach is what gets the business running again.
The Sony Pictures hack, start to finish: a wiped studio, a pulled film and a folder named Password: the long read behind the CL12 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- FBI: Update on Sony investigation
- U.S. Department of Justice: North Korean regime-backed programmer charged with conspiracy to conduct multiple cyber attacks and intrusions
- Gizmodo: Sony kept thousands of passwords in a document marked Password
- Wikipedia: 2014 Sony Pictures hack
- Krebs on Security: Sony breach may have exposed employee healthcare, salary data
- Krebs on Security: The case for N. Korea's role in Sony hack