Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

General: Station.com Taken Offline

135

Comments

  • KenzeKenze Member UncommonPosts: 1,217

    here is part of the press release which goes into a bit more detail..  http://www.soe.com/securityupdate/pressrelease.vm

     

    SONY ONLINE ENTERTAINMENT ANNOUNCES

    THEFT OF DATA FROM ITS SYSTEMS

    Breach Believed to Stem From Initial Criminal Hack of SOE

    Tokyo, May 3, 2011 - Sony Corporation and Sony Computer Entertainment announced today that their ongoing investigation of illegal intrusions into Sony Online Entertainment LLC (SOE, the company) systems revealed yesterday morning (May 2, Tokyo time) that hackers may have stolen SOE customer information on April 16th and 17th, 2011 (PDT).  SOE is based in San Diego, California, U.S.A.

    This information, which was discovered by engineers and security consultants reviewing SOE systems, showed that personal information from approximately 24.6 million SOE accounts may have been stolen, as well as certain information from an outdated database from 2007.  The information from the outdated database that may have been stolen includes approximately 12,700 non-U.S. credit or debit card numbers and expiration dates (but not credit card security codes), and about 10,700 direct debit records of certain customers in Austria, Germany, Netherlands and Spain.

    With the current outage of the PlayStation® Network and Qriocity™ services and the ongoing investigation into the recent attacks, SOE had also undertaken an intensive investigation into its system.  Upon discovery of this additional information, the company promptly shut down all servers related to SOE services while continuing to review and upgrade all of its online security systems in the face of these unprecedented cyber-attacks. 

    On May 1, Sony apologized to its customers for the inconvenience caused by its network services outages.  The company is working with the FBI and continuing its own full investigation while working to restore all services.



    Sony is making this disclosure as quickly as possible after the discovery of the theft, and the company has posted information on its website and will send e-mails to all consumers whose data may have been stolen.

    The personal information of the approximately 24.6 million SOE accounts that was illegally obtained, to the extent it had been provided to SOE, is as follows:


    • name

    • address

    • e-mail address

    • birthdate

    • gender

    • phone number

    • login name

    • hashed password. 

    In addition to the information above, the 10,700 direct debit records from accounts in Austria, Germany, Netherlands and Spain, include:


    • bank account number

    • customer name

    • account name

    • customer address.

    SOE will grant customers 30 days of additional time on their subscriptions, in addition to compensating them one day for each day the system is down.  It is also in the process of outlining a "make good" plan for its PlayStation®3 MMOs (DC Universe Online and Free Realms).  More information will be released this week.

     

    ----------------------------------------

    Credit card numbers from 2007 may have changed since then for those stolen outside the USA but bank account numbers?

    Watch your thoughts; they become words.
    Watch your words; they become actions.
    Watch your actions; they become habits.
    Watch your habits; they become character.
    Watch your character; it becomes your destiny.
    —Lao-Tze

  • MardyMardy Member Posts: 2,213

    Originally posted by Kenze

    Credit card numbers from 2007 may have changed since then for those stolen outside the USA but bank account numbers?

    lol this is why I don't like ot use debit cards.  Bank account #'s are always attached to your checkbook and during debit transactions, the records will have your bank account #'s.  But I gotta say, this does suck for foreign customers.

    EQ1-AC1-DAOC-FFXI-L2-EQ2-WoW-DDO-GW-LoTR-VG-WAR-GW2-ESO

  • SWGmodAlphaSWGmodAlpha Member Posts: 126

    http://www.soe.com/securityupdate/

    SOE is stupid for not having a full security audit / mitigation plan in place before they started to lay people off.

    I would bet money that someone they laid off commited the hack or provided information to execute the hack.

    Hacking is rarely exculsively electronic.

  • ReizlaReizla Member RarePosts: 4,092

    Originally posted by Mardy

    Originally posted by Kenze



    Credit card numbers from 2007 may have changed since then for those stolen outside the USA but bank account numbers?

    lol this is why I don't like ot use debit cards.  Bank account #'s are always attached to your checkbook and during debit transactions, the records will have your bank account #'s.  But I gotta say, this does suck for foreign customers.

    Yeah, bank accounts are most of the times long-term numbers. But I doubt that hackers will use direct debit to plunder bank accounts. They'd much rather use cc's because that's easier money to get and harder to trace back to a person / account / location. Not to mention, direect debit can be undone (at least here in The Netherlands) by simply calling your bank, and in most cases it's undone in 1 day when you explain the direct debit is fraude...

    [EDIT]

    ...one more reason to use timecards bought on the net (which are cheaper than the monthly subscription anyways)

  • MardyMardy Member Posts: 2,213

    I definiately wouldn't rule out that some secret security holes were exposed by those that got laidoff.  A lot of the security problems start from within.  Only good thing that can come from this is that sometimes it takes a big incident like this for a company to spend the money & resources into revamping their system.

    EQ1-AC1-DAOC-FFXI-L2-EQ2-WoW-DDO-GW-LoTR-VG-WAR-GW2-ESO

  • SWGmodAlphaSWGmodAlpha Member Posts: 126

    Originally posted by Mardy

    I definiately wouldn't rule out that some secret security holes were exposed by those that got laidoff.  A lot of the security problems start from within.  Only good thing that can come from this is that sometimes it takes a big incident like this for a company to spend the money & resources into revamping their system.


     

     QFE - SOE has been running on the cheap and was stupid beyond stupid for not perparing for this when laying off Techies.  I would not be suprised at all if this hack was perpatraded by a former eomployee or that a former employee sold information that enabled hackers.

    Hacking is seldomly exclusively electronic.

  • psyclumpsyclum Member Posts: 792

    hum...   did someone at SoE name their login server "the Gibson"?:D

  • MardyMardy Member Posts: 2,213

    Originally posted by psyclum

    hum...   did someone at SoE name their login server "the Gibson"?:D

    I told them to change their root password from "God"... them system administrators and male egos I swear image

     

    On another note, someone posted this on another forum from Zam.

     


    SOE downtime continues as they work to secure information.

    As we previously reported, all Sony Online Entertainment services, games, forums and web sites went offline this morning as a result of the recent Playstation Network intrusion. SOE issued an announcement which revealed that personal information had been compromised.  Players were, for the most part, relieved that credit card information was safe, but wanted to know when they could play their games.  The press release only said, "Our teams are working around the clock on this, and services will be restored as soon as possible."

    We shot off a quick e-mail to John "Smed" Smedley, president of Sony Online Entertainment, asking if the servers would be back up tonight.  He quickly replied with, "They won't be up tonight unfortunately." 

    SOE is granting customers 30 days of additional time on their subscriptions, in addition to compensating them one day for each day the system is down.

    EQ1-AC1-DAOC-FFXI-L2-EQ2-WoW-DDO-GW-LoTR-VG-WAR-GW2-ESO

  • rewonerewone Member Posts: 7

    i hate hackers 

  • SuperXero89SuperXero89 Member UncommonPosts: 2,551

    Originally posted by rewone

    i hate hackers 

     

    They seem to me like a bunch of highly gifted whiny attention whores, but they did expose some gaping holes in Sony's security system.  Hopefully Sony learns from this, protects their network, and goes about tracking down the hackers the right way.

  • werewoodwerewood Member Posts: 76

    Don't say the Station. 

    Say the Crack ('d) Station.

    NO SOE FOR ME!

  • SorrowSorrow Member Posts: 1,195

    Latest news feed is saying 25 million more accounts got hacked today, and SOE hopes credit cards were not compromised along with the accounts.

    image

  • KedoremosKedoremos Member UncommonPosts: 432

    Originally posted by SuperXero89

    Originally posted by rewone

    i hate hackers 

     

    They seem to me like a bunch of highly gifted whiny attention whores, but they did expose some gaping holes in Sony's security system.  Hopefully Sony learns from this, protects their network, and goes about tracking down the hackers the right way.

    Nothing gifted about a bunch of script kiddies. It's not like they discovered the vulnerabilities themselves. They ran scripts against servers and got a report that said such and such port is open or such and such vulnerability is available. They then exploited it. The only real thing crackers (the correct term, fyi) have is the will to do wrong.

    image
    Life of an MMORPG "addict"
    For 7 years, proving that if you quote "fuck" you won't get banned.

  • SpectralHunterSpectralHunter Member UncommonPosts: 455

    So SOE was hacked two weeks ago and they just discovered it now? 

    Wow, that's just pathetic...

  • psyclumpsyclum Member Posts: 792

    Originally posted by SpectralHunt



    So SOE was hacked two weeks ago and they just discovered it now? 



    Wow, that's just pathetic...


     

    I guess you havent been a customer of SoE very long:D   you see, how SoE works is that, unless they admit something happened, then it didnt happen:D   just like bugs in their software, unless they ADMIT there is a bug, then there is NO bugs in their software....   ever :D

    any/all EQ1 player can agree on that fact:D  what they will do is next week they will roll out the new expansion to the hack and charge everyone another $35 to log into their new hacked login server "expansion" with bigger and nastier hacks so you will forget about the hacks from this week.  and you will need to anticipate a few weeks of emergency nerfs for them to fix the hacks so that EVERYBODY can take a few more days off from online addiction compliments of SoE:D

  • whilanwhilan Member UncommonPosts: 3,472

    See now this right here is the kind of stuff that will make me write off a company all together. bad games no, bad CS no, getting my info taken from a company that was suppose to keep it safe, yeah thats big enough to do it.

    I'm still unsure if i was hit by this or not. I will err on the side that i was and take the proper precuations. But this is the one thing that will stop me from dealing with a company. Pity to. I liked EQ and SWG. Now they are out.

    The only way i will be willing to go back is if they can ensure that they have taken every precuations needed to increase secruity and even at that i'm going to be extremely cautious and unlikely to sub. Usernames and passwords i can change. CC info, and personal info i never should have to worry about.

    /emote shakes head at sony.

    Help me Bioware, you're my only hope.

    Is ToR going to be good? Dude it's Bioware making a freaking star wars game, all signs point to awesome. -G4tv MMo report.

    image

  • MardyMardy Member Posts: 2,213

    Originally posted by whilan

    See now this right here is the kind of stuff that will make me write off a company all together. bad games no, bad CS no, getting my info taken from a company that was suppose to keep it safe, yeah thats big enough to do it.

    I'm still unsure if i was hit by this or not. I will err on the side that i was and take the proper precuations. But this is the one thing that will stop me from dealing with a company. Pity to. I liked EQ and SWG. Now they are out.

    The only way i will be willing to go back is if they can ensure that they have taken every precuations needed to increase secruity and even at that i'm going to be extremely cautious and unlikely to sub. Usernames and passwords i can change. CC info, and personal info i never should have to worry about.

    /emote shakes head at sony.

    Not making excuses for SOE at all or see this situation lightly, but you'll be surprised how many big companies get hacked on a regular basis.  Every year you hear a credit card company gets hacked,  Ever year you hear a health insurance company lost their data tape which just happen to contain all their patient data, which just happen to include social security #'s and everything.  Every other month you see hackers taking down government websites, penetrating specific databases, stealing customer information from online merchant stores, etc..

     

    This is just a sample of some recent hack incidents

     

    So again, not to excuse SOE at all, but I think you have to expect this to happen more and more as more and more things go online.  When you have a server that's online taking data, then chances are if hackers want to get in bad enough they can get in.  And as mentioned before, sometimes hacks start from within.  Disgruntled employee or someone who wants to get paid more than their salary would sell vulnerability information just to make extra bucks.  It happens more than you think.  The good that can come from it is that usually when something big like this happens, this is when the company spends a lot of money and resources to get it "right".

    EQ1-AC1-DAOC-FFXI-L2-EQ2-WoW-DDO-GW-LoTR-VG-WAR-GW2-ESO

  • ElikalElikal Member UncommonPosts: 7,912

    I don't know heck how secure the Sony systems were. But I find it remarkable that almost everyone is just angry at Sony and none against the criminals who did this. I'd suppose there is no system that is 100% safe. Just saying.

    People don't ask questions to get answers - they ask questions to show how smart they are. - Dogbert

  • JeroKaneJeroKane Member EpicPosts: 7,098



    Originally posted by Elikal

    I don't know heck how secure the Sony systems were. But I find it remarkable that almost everyone is just angry at Sony and none against the criminals who did this. I'd suppose there is no system that is 100% safe. Just saying.






     

     We are angry at Sony and SOE, because they stored our Account and Personal information UNSECURED in databases!

    Not to mention they kept an UNSECURED database ONLINE with people's account, personal and credit information!! Outdated or not!

    There is absolutely no excuse for this! A company that receives millions of dollars a month alone via subscription fees and Cash Shop purchases!

    People underestimate the danger of their Login name (station account name) being stolen! Especially since many many people use this same Login name / account name for many online services. Passwords can be changed, but login names / account names cannot!

    This will have severe concequences and is going to cause a lot of misery for people affected!

     

    I sincerely hope John Smedly will finally be booted from the company! He has been laying off many people these past years due to his incompetence to run the company.

    It is now his time to take responsibility for this FIASCO and leave the company! Any CEO would have been fired long ago already. That he is still at the helm is a down right insult!  This is really the last straw!

    The trust in this company is just gone! And it will take new leadership and clean ship to even attempt a regain in trust towards their customers!

  • ElikalElikal Member UncommonPosts: 7,912

    Originally posted by JeroKane



    Originally posted by Elikal



    I don't know heck how secure the Sony systems were. But I find it remarkable that almost everyone is just angry at Sony and none against the criminals who did this. I'd suppose there is no system that is 100% safe. Just saying.






     

     We are angry at Sony and SOE, because they stored our Account and Personal information UNSECURED in databases!

    Not to mention they kept an UNSECURED database ONLINE with people's account, personal and credit information!! Outdated or not!

    There is absolutely no excuse for this! A company that receives millions of dollars a month alone via subscription fees and Cash Shop purchases!

    People underestimate the danger of their Login name (station account name) being stolen! Especially since many many people use this same Login name / account name for many online services. Passwords can be changed, but login names / account names cannot!

    This will have severe concequences and is going to cause a lot of misery for people affected!

     

    I sincerely hope John Smedly will finally be booted from the company! He has been laying off many people these past years due to his incompetence to run the company.

    It is now his time to take responsibility for this FIASCO and leave the company! Any CEO would have been fired long ago already. That he is still at the helm is a down right insult!  This is really the last straw!

    How do you know they were unsecured? I assume they were secured, but security was broken?

    People don't ask questions to get answers - they ask questions to show how smart they are. - Dogbert

  • JeroKaneJeroKane Member EpicPosts: 7,098

    Originally posted by Elikal

    Originally posted by JeroKane



    Originally posted by Elikal

    I don't know heck how secure the Sony systems were. But I find it remarkable that almost everyone is just angry at Sony and none against the criminals who did this. I'd suppose there is no system that is 100% safe. Just saying.






     

     We are angry at Sony and SOE, because they stored our Account and Personal information UNSECURED in databases!

    Not to mention they kept an UNSECURED database ONLINE with people's account, personal and credit information!! Outdated or not!

    There is absolutely no excuse for this! A company that receives millions of dollars a month alone via subscription fees and Cash Shop purchases!

    People underestimate the danger of their Login name (station account name) being stolen! Especially since many many people use this same Login name / account name for many online services. Passwords can be changed, but login names / account names cannot!

    This will have severe concequences and is going to cause a lot of misery for people affected!

     

    I sincerely hope John Smedly will finally be booted from the company! He has been laying off many people these past years due to his incompetence to run the company.

    It is now his time to take responsibility for this FIASCO and leave the company! Any CEO would have been fired long ago already. That he is still at the helm is a down right insult!  This is really the last straw!

    How do you know they were unsecured? I assume they were secured, but security was broken?

     Unencrypted! I should have worded it better. I am just pissed off all our personal information, account information and possible credit card information (latter being outdated or not) is lying open on the street!

    Especially since it happened a week ago and it them first saying last week everything is fine and peachy... and now a whole week later suddenly saying it is not!

    And who says their so called secured seperate recent financial / credit card database environment hasn't been hacked and stolen either?

    No one is going to believe SOE now!  Not when they first said last week that nothing was stolen! So who says they are telling us everything right now?

    They pretty much lost all their credibility right now as a company!

  • ReizlaReizla Member RarePosts: 4,092

    For those interested... I've just dropped 2 inquiries to politicians for inquiries and action.

    First one is to the Dutch Socialist Party (SP), to ask both the Dutch privacy protection agency our minister of Justice & Security what they're about to do after a breach of personal security.

    Second one is to the EU department of Internet & security, our own Dutch (and probably most powerful woman in the world): Neelie Kroes asking to look into the way SONY has stored the private data of so many persons without using any form of encryption. I also added to the eMail to her that the iinformation that's stolen can lead to identity theft. Knowing Neelie, she'll pick this up and start asking some tough questions to SONY ;-)

  • YasouYasou Member Posts: 86

    Call you credit card company, and have your card replaced with a new code. They do it free of charge if your card is linked to Sony. I just did it this morning.

  • JeroKaneJeroKane Member EpicPosts: 7,098

    Originally posted by Reizla

    For those interested... I've just dropped 2 inquiries to politicians for inquiries and action.

    First one is to the Dutch Socialist Party (SP), to ask both the Dutch privacy protection agency our minister of Justice & Security what they're about to do after a breach of personal security.

    Second one is to the EU department of Internet & security, our own Dutch (and probably most powerful woman in the world): Neelie Kroes asking to look into the way SONY has stored the private data of so many persons without using any form of encryption. I also added to the eMail to her that the iinformation that's stolen can lead to identity theft. Knowing Neelie, she'll pick this up and start asking some tough questions to SONY ;-)

     I think everyone needs to do this, so enough attention is generated with those politians.

    And yes Neelie Kroes is one tough lady that made Microsoft fall to their knees a couple years ago heh.

  • JeroKaneJeroKane Member EpicPosts: 7,098

    Originally posted by Yasou

    Call you credit card company, and have your card replaced with a new code. They do it free of charge if your card is linked to Sony. I just did it this morning.

     My girlfriend and me are going to do it too. We are not going to take any chances with this.

    I don't believe anything come out from SOE anymore about what has really been stolen or not. Not after how this has been handled. And pretty much how Sony has handled this whole affair themselves.

Sign In or Register to comment.