The Sony Pictures hack, start to finish: a wiped studio, a pulled film and a folder named Password
In about an hour on the morning of November 24, 2014, malware erased roughly half of the personal computers and servers at Sony Pictures, and a studio with 7,000 employees went back to fax machines and paper paychecks.[1] This long read follows the attack from a comedy about North Korea to the leaks, the threat that pulled a film from theaters, the FBI's attribution, the bill, and the one control that would have made the thieves' job much harder.
The movie, the warning email and the wiper
In 2014 Sony Pictures was preparing a comedy called The Interview, in which 2 American journalists are recruited to kill North Korea's leader. It cost about $44 million to make, with a marketing budget of about $32 million, and the studio hoped for $100 million or more at the box office.[1]
On November 21, 2014, several top Sony executives received an email from a group that demanded money and warned that the studio would suffer if it did not pay. Nobody acted on it; the message only became public later, when it turned up among leaked emails.[5]
At about 7 a.m. Pacific time on Monday, November 24, an image of a red skeleton and a message signed by a group calling itself Guardians of Peace appeared on Sony screens. Behind it was a wiper, malware built to destroy rather than to steal or ransom. It overwrote data using a method that made recovery impractical. When it was done, 3,262 of the studio's 6,797 personal computers and 837 of its 1,555 servers had been erased.[1] Staff communicated by fax and posted notes, and the company paid its 7,000 employees with paper checks.[1]
A wiper that reaches thousands of machines in an hour does not start at the front door on the day it runs. The FBI later said the attackers had stolen large amounts of personal and business data before the destruction began, and that the attack left thousands of Sony computers inoperable and forced the whole network offline.[2] In other words, the intruders had been inside long enough to map the place, collect what they wanted and copy it out before anyone saw the skull.
What leaked: films, salaries and a folder named Password
Starting in late November and continuing for weeks, the stolen files were posted to public file-sharing sites in 9 batches.[1] The first to appear were films: 5 Sony titles, 4 of them not yet released in theaters.[1] Then came spreadsheets of executive salaries, internal emails in which executives discussed stars and projects, and personnel records.[1]
The personal data hit hardest. Analysts who went through the leaked files found more than 47,000 unique Social Security numbers, belonging to current and former employees and to some actors and freelancers, many of them stored in ordinary spreadsheets.[7] Sony later told a court that about 437,000 people had been affected in some way.[4]
One directory drew particular attention from security professionals. It was named, simply, Password, and it held documents and spreadsheets listing login details for company systems and social media accounts, stored as plain text with file names that described what they contained.[6] Nobody outside the investigation can say exactly how much that folder helped the attackers move around. But it showed how the studio handled its keys: written down, labeled and left where anyone already inside could read them.
The threat that pulled The Interview from theaters
On December 16, 2014, a new message tied to the hackers warned people to stay away from theaters showing The Interview and referred to the September 11 attacks.[8] The Department of Homeland Security said it had no credible intelligence of an active plot, but the country's biggest theater chains quickly said they would not show the film.[9] On December 17, Sony cancelled the planned Christmas Day release.[9]
On December 19, the FBI announced that it had enough information to conclude that North Korea's government was responsible. It pointed to 3 things: code and methods in the wiper that matched malware previously tied to North Korean actors, internet addresses built into the malware that had communicated with known North Korean infrastructure, and similarities to a March 2013 attack on South Korean banks and media companies.[2] The same day, the President told reporters that Sony had made a mistake by pulling the film.[10]
Sony reversed course. On December 24 it released The Interview online, and on Christmas Day it opened in a few hundred independent theaters.[11] Digital sales brought in up to about $40 million in the weeks that followed, making it the studio's most successful online release at the time.[11] That was still far below what a wide theatrical release had been expected to earn.[1]
What the Sony Pictures hack cost
In February 2015, Sony said it expected to spend about $15 million on investigating and repairing the damage in its fiscal year.[12] That figure covered the immediate response, not lost business, delayed projects or the time spent rebuilding systems. The same month, the studio's co-chairman, whose emails had been among the most quoted, stepped down to become a producer with the company.[13]
Current and former employees sued, arguing that Sony had failed to protect their personal information. In April 2016 a federal judge in Los Angeles gave final approval to a settlement. Sony committed $7 million to a notification and reimbursement fund, paid for up to 3 years of credit monitoring, and covered lawyers' fees, bringing the total to as much as about $8 million.[4][3] Employees could claim reimbursement for identity theft losses and for steps they took to protect themselves.[3]
On September 6, 2018, the Justice Department charged a North Korean computer programmer who, prosecutors say, worked for a government front company and was part of a team behind the Sony attack, the $81 million theft from Bangladesh Bank and the WannaCry ransomware.[14] According to the charges, the Sony intrusion began with malicious messages sent to employees that gave the attackers a foothold in the network.[14] The defendant has not been brought to a U.S. court.
Why one intrusion reached half the studio
Put the pieces together and the attack looks less exotic than its headlines. The attackers got in through employees, stayed long enough to gather what they wanted, and copied terabytes of data out through the studio's own internet connection without triggering an alarm anyone acted on.[2][14]
Researchers who examined the wiper reported that its authors had detailed knowledge of Sony's internal IT setup, the kind of map an intruder builds only after time inside.[15] Malware that can use a trusted account spreads with that account's reach instead of breaking into each machine separately. When one set of logins works almost everywhere, and those logins are stored in labeled spreadsheets on shared drives, an intruder does not need to be clever. The network was flat enough that a single foothold reached about half of all company computers in an hour.[1]
It took the studio weeks to restore basic systems, and it rebuilt much of its network from scratch. The case became the reference point that security teams at other companies used for years to argue for bigger budgets.
Timeline
| Date | What happened |
|---|---|
| Nov 21, 2014 | Sony executives receive an email demanding money.[5] |
| Nov 24, 2014 | Wiper erases 3,262 PCs and 837 servers in about an hour.[1] |
| Early Dec 2014 | Leaks reveal more than 47,000 Social Security numbers.[7] |
| Dec 16, 2014 | Hackers threaten theaters showing The Interview.[8] |
| Dec 17, 2014 | Sony cancels the Christmas Day theatrical release.[9] |
| Dec 19, 2014 | FBI attributes the attack to North Korea's government.[2] |
| Dec 24, 2014 | Sony releases the film online.[11] |
| Feb 2015 | Sony puts response costs at about $15 million; co-chairman steps down.[12][13] |
| Apr 6, 2016 | Judge approves the employee class action settlement.[4] |
| Sep 6, 2018 | Justice Department charges a North Korean programmer.[14] |
The missing control
The missing control: keep passwords out of plain-text files, limit what any one administrator login can reach, and raise an alarm when large amounts of data leave the network. With those in place, a single foothold would not have unlocked half the studio or let terabytes walk out unnoticed.[2][6]
- Move every shared password into a password manager. Search shared drives and email for files with names like passwords or logins, move the contents into a proper vault, then delete the files.
- Separate everyday and admin accounts. Give staff who manage systems a separate login for admin work, protect it with two-factor sign-in, and never reuse one admin password across every machine.
- Divide the network. Keep finance, HR and file servers on their own segments so a compromised laptop cannot reach everything at once.
- Watch outbound data. Ask your IT provider to alert on unusually large uploads or transfers to unfamiliar destinations, and name the person who responds.
- Treat threats and odd emails as incidents. When anyone receives an extortion demand or strange warning, report it to whoever handles security that day instead of filing it away.
What it means now
The Sony attack is remembered for the film, the leaked emails and a foreign government. The reusable lesson is smaller and closer to home: the attackers found the keys where the studio kept them and walked out with the data through a door nobody was watching.
Most small businesses already have a file somewhere with passwords in it. Finding it and replacing it with a password manager takes an afternoon, and it removes one of the easiest wins an intruder can get.
The Sony Pictures hack: wiped computers and a folder named Password: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Fortune: Sony Pictures, Inside the Hack of the Century, Part 1
- FBI: Update on Sony investigation
- Data Privacy + Security Insider: Sony settles employees' class action suit for up to $8M
- News 5 Cleveland (AP): Judge approves settlement in class action suit regarding Sony Pictures hack
- Computerworld: Hackers contacted top Sony executives before attack
- Computerworld: A lesson from Sony's massive hack: don't store your passwords in Word docs and Excel sheets
- SecurityWeek: Sony hackers dump personal data of 47,000 people, celebs included
- CNN Money: Sony hackers threaten theaters
- NPR: Major theater chains won't screen The Interview amid threats
- Christian Science Monitor: Obama says Sony made a mistake in pulling The Interview
- CBS News: The Interview digital sales rake in up to $40 million
- Fortune: Sony is spending $15 million to deal with the big hack
- KSL (AP): Amy Pascal steps down as Sony Pictures chief
- U.S. Department of Justice: North Korean regime-backed programmer charged with conspiracy to conduct multiple cyber attacks
- Dark Reading: Sony hackers knew details of Sony's entire IT infrastructure