Sony Says Hacker Stole 2,000 Records From Canadian Site
By Robert McMillan
The problems keep coming for Sony. On Tuesday the company confirmed that someone had hacked into its website and stolen about 2,000 customer names and e-mail addresses.
Close to 1,000 of the records have already been posted online by a hacker calling himself Idahc, who says he’s a “Lebanese grey-hat hacker.” Idahc found a common Web programming error, called an SQL injection flaw, that allowed him to dig up the records on the Canadian version of the Official Sony Ericsson eShop, an online store for mobile phones and accessories.
The hacker got access to records for about 2,000 customers, including their names and e-mail addresses and a hashed version of users’ passwords, said Ivette Lopez Sisniega, a Sony Ericsson Mobile Communications spokeswoman. “Sony Ericsson has disabled this e-commerce website,” she said in an e-mail message. “We can confirm that this is a standalone website and it is not connected to Sony Ericsson servers.”
Other than the names and e-mail addresses, no personal or banking information was compromised, she said.
Sony Ericsson is a mobile-phone company run jointly by Sony and Ericsson.
Earlier this year Sony raised the hackles of hackers by suing George Hotz, a well-respected hacking enthusiast, who’d found a way to break Sony’s controls and install Linux on his PlayStation 3. Sony eventually settled with Hotz, but to many it came off as a bully in the affair.
Now, increasingly, Sony looks like a company where security was merely an afterthought.
Sony’s continued problems reflect a cavalier attitude toward computer security, said Scott Borg, CEO of the U.S. Cyber Consequences Unit, a Washington-based think tank that studies cyber-attacks. “It’s a pretty obvious conclusion that they weren’t managing their security well,” he said.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert’s e-mail address is firstname.lastname@example.org
Note: When you purchase something after clicking links in our articles, we may earn a small commission. Read ouraffiliate link policyfor more details.