Case file · SONY PICTURES 2014

The Sony Pictures hack: wiped computers and a folder named Password

Published 2026-09-29 · 4 min read · Missing control: No plaintext password files on shares

When attackers dumped Sony Pictures' internal files online in 2014, one of the folders was simply named Password, and it held unprotected login details for the studio's social media accounts and more.[3] This case file covers how the attack shut the studio down, what leaked, who the FBI blamed, and the one habit that turned a break-in into a skeleton key.

What happened

On November 24, 2014, Sony Pictures Entertainment employees found their computers taken over by a group calling itself the Guardians of Peace.[1][4] The attackers had already copied huge amounts of data, and then they set off malware that erased hard drives. Thousands of the studio's computers stopped working, and Sony took its entire network offline.[1][5]

Over the following weeks the stolen files were posted online in batches. They included unreleased films, scripts, executives' emails and salaries, and personal data on staff, including about 47,000 Social Security numbers.[4] One spreadsheet alone listed the name, location, employee ID, network username, salary and date of birth of more than 6,800 people.[5] On December 4, reporters combing the dump found the folder named Password.[3]

The group also issued threats against theaters planning to show a comedy about the assassination of North Korea's leader. Sony canceled the wide release, then let about 300 independent theaters screen it on Christmas Day and released it online on December 24.[4] On December 19, the FBI said the North Korean government was responsible.[1]

How they got in

According to the Justice Department, the attackers got their first foothold with spear-phishing, emails tailored to fool specific people into opening something harmful. Once inside, they stole confidential data, threatened executives and staff, and damaged thousands of computers.[2]

The Password folder shows why stolen data was so damaging. It held documents with usernames and passwords for the official Facebook, Twitter, YouTube and MySpace accounts of major films, stored without encryption and labeled in plain words.[3] Anyone inside the network did not need to guess where the keys were kept. The file names told them. Much of the other sensitive data, from salary sheets to health savings records, sat in ordinary spreadsheets on shared systems.[5]

How it was caught

There was nothing quiet about this attack, which announced itself on every screen. The investigation focused on who did it. The FBI pointed to lines of code, encryption methods and deletion techniques that matched earlier malware it tied to North Korea, internet addresses built into the malware that overlapped with known North Korean infrastructure, and similarities to a 2013 attack on South Korean banks and media.[1] Some outside experts questioned the attribution at the time.[6]

In September 2018 the Justice Department charged a North Korean programmer who, prosecutors say, worked for a government front company tied to North Korean military intelligence. The charges covered the Sony attack along with the 2016 theft of $81 million from Bangladesh's central bank and the 2017 WannaCry ransomware outbreak.[2]

What it cost

Sony set aside $15 million in early 2015 to deal with the investigation and repairs.[4] That figure leaves out the harder costs: weeks of disruption across a global studio, private emails read around the world, and thousands of employees whose Social Security numbers, pay and medical details were public.[4][5] The FBI called the attack a reminder that cyber threats were among the most serious national security dangers facing the country.[1]

The missing control

The missing control: no plaintext password files on shared drives. Passwords belong in a password manager or vault that encrypts them and records who opens them, not in spreadsheets and documents anyone on the network can read.

This would not have stopped the phishing email or the wiper. It would have limited how far the intruders could reach and how much they could expose. A password manager keeps logins encrypted, so a copied file is useless without the key, and it logs access, so a sudden sweep through the vault stands out. Labeled folders of plain passwords do the opposite, turning one foothold into access to accounts across the business.

What to do in your business

Full episode

The Sony Pictures hack, start to finish: a wiped studio, a pulled film and a folder named Password: the long read behind the CL12 episode, chapter by chapter.

Watch the case
The Sony hack and the folder named PasswordDrops 2026-12-02
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. FBI: Update on Sony investigation
  2. U.S. Department of Justice: North Korean regime-backed programmer charged with conspiracy to conduct multiple cyber attacks and intrusions
  3. Gizmodo: Sony kept thousands of passwords in a document marked Password
  4. Wikipedia: 2014 Sony Pictures hack
  5. Krebs on Security: Sony breach may have exposed employee healthcare, salary data
  6. Krebs on Security: The case for N. Korea's role in Sony hack