01Summary
The incident began in early April 2011 when Anonymous launched coordinated DDoS attacks against Sony's network infrastructure in protest of Sony's legal action against PlayStation 3 jailbreaker George 'GeoHot' Hotz. The attacks targeted Sony's Japanese and American websites. On April 20, Sony discovered that unknown attackers had also exfiltrated massive amounts of user data. The breach exposed names, addresses, email addresses, birthdates, usernames, passwords, and potentially credit card information for approximately 77 million PlayStation Network accounts. Sony shut down the entire PSN service on April 20, and it remained offline until May 14 — a total of 23 days. The incident became the largest data breach in gaming history at the time and cost Sony an estimated $171 million.
02Background
Anonymous viewed Sony's lawsuit against George Hotz as an attack on consumer rights and the open internet. Hotz had published a jailbreak for the PS3, allowing users to run custom software. Sony responded aggressively, obtaining a court order forcing Hotz to hand over his computer equipment and IP addresses. This legal overreach, as perceived by Anonymous, triggered the retaliation.
03Key revelations
- 01Sony's customer database was vulnerable to basic SQL injection attacks.
- 0277 million user accounts had their PII exposed in the largest gaming breach in history.
- 03The incident highlighted the risks of corporate legal actions against the hacker community triggering retaliatory cyberattacks.
04Technical analysis
The attack had two phases. First, Anonymous conducted DDoS attacks against Sony's web infrastructure, causing service degradation. Second, unknown actors (potentially separate from the Anonymous DDoS) exploited vulnerabilities in Sony's application server software to gain access to the customer database. The breach utilized SQL injection techniques against Sony's Apache Struts framework. The data was exfiltrated and posted on underground forums.
- Attack vector
- DDoS attacks followed by exploitation of web application vulnerabilities (SQL injection)
- Attack method
- Distributed Denial of Service (DDoS) and Data Exfiltration
- Initial access
- Web application exploitation
- Lateral movement
- Internal network traversal following initial access
- Exfiltration
- Bulk database extraction
- Tool / malware
- SQL injection tools, DDoS botnets (LOIC)
- Malware type
- Data Exfiltration Tool
Vulnerabilities exploited
- Apache Struts vulnerability
- SQL injection vulnerabilities
MITRE ATT&CK techniques
- T1499
- T1190
05Threat actor
Anonymous is a decentralized, global hacktivist collective. The Sony campaign demonstrated its ability to disrupt major corporate infrastructure and trigger cascading security incidents. Attribution for the actual data theft portion remains debated, with some security analysts suggesting a separate group piggybacked on the Anonymous DDoS chaos.
Aliases
- Anonymous Collective
MITRE groups
- T1499
Attribution sources
- Media Reports
- Sony Corporate Statements
- Security Analysis
06Victims and impact
Additional victims
- PlayStation Network Users (77 million accounts)
Countries affected
- United States
- Japan
- Global
07Data exposed
Data types
- PII
- Names
- Email Addresses
- Passwords (hashed)
- Credit Card Data (encrypted)
- Birthdates
- Addresses
Notable documents
- Anonymous press releases about OpSony
- Sony security notifications to users
08Financial damage
Sony estimated costs of $171M including legal, security upgrades, customer protection, and lost revenue.
09Timeline
- 2011-04-04Anonymous launches DDoS attacks against Sony websites in response to GeoHot lawsuit.
- 2011-04-20Sony discovers data breach of 77M PSN accounts; shuts down PSN.
- 2011-04-26Sony confirms credit card data may have been exposed.
- 2011-05-14PSN service restored after 23-day outage.
10Key figures
- George Hotz (GeoHot)PS3 Jailbreaker / Target of Sony LawsuitAmericanSony lawsuit triggered the Anonymous campaign.
11On the record
We do not forgive. We do not forget. Expect us.
12Reaction and fallout
Public reaction
Massive public outrage directed at Sony for poor security practices and at Anonymous for disrupting gaming services. The incident triggered multiple class-action lawsuits against Sony and Congressional inquiries into data security.
Political impact
The breach prompted US Congressional hearings on data breach notification laws and corporate cybersecurity obligations. Several state attorneys general launched investigations.
13Legal
Sony faced multiple class-action lawsuits and regulatory fines. The company spent $171M on remediation. Anonymous perpetrators were not definitively identified.
Civil lawsuits
- Multiple class-action lawsuits against Sony for inadequate data protection
14Aftermath
Policy changes
- Strengthened data breach notification requirements in several US states.
- Increased regulatory scrutiny of video game industry cybersecurity.
Regulatory changes
- FTC review of Sony's data security practices.
Security improvements
- Sony overhauled its network security architecture.
- Implementation of mandatory multi-factor authentication for PSN accounts.
- Enhanced encryption and monitoring systems deployed.
15Significance and legacy
Significance
One of the largest data breaches of its era (77M records) and the longest gaming network outage in history (23 days). The incident demonstrated how hacktivist retaliation against corporate legal actions could escalate into catastrophic data breaches affecting millions of innocent consumers.
Legacy
The Sony PSN hack set a benchmark for gaming industry security standards and became a cautionary tale about the unintended consequences of aggressive corporate litigation against the hacker community. It remains a landmark case study in hacktivism escalation.
16Disclosure and media
- Authentication
- Sony corporate disclosure and media reporting
Media partners
- BBC News
- The Guardian
- Wired
- Kotaku
Publishing organisations
- Anonymous
17Field notes
- 01The PSN outage lasted 23 days, making it the longest gaming network outage in history at the time.
- 02Anonymous denied responsibility for the actual data breach, claiming the DDoS attacks were separate from the data theft.
- 03George Hotz later went on to become the first person to unlock the iPhone and later worked at Google and Meta on AI.
18Resolution
PSN service restored on May 14, 2011. Sony implemented comprehensive security upgrades and offered identity theft protection and free games to affected users.
19Sources
Official documents
- Sony Security Breach Notification Letters
References
- [1]Sony corporate statements (2011)
- [2]Congressional testimony
- [3]Media reports (BBC, Wired, Kotaku)









