Cybersecurity / Source date:

Sony PlayStation Network Breach: 77 Million Accounts

Sony's May 2011 statement forecast JPY 14 billion of costs for the fiscal year ending March 2012 across several service incidents, not a final PSN-only bill.

Illustration of customer-support update records beside a closed laptop, telephone and unbranded game controller.

Retrospective context. The original 30 May 2011 date is retained. Later June incidents and current commentary below were not facts known on that date.

On 20 April 2011, the PlayStation Network went dark. Sony initially described it as maintenance. Six days later the company confirmed what security researchers had already suspected: an intruder had been inside the network between 17 and 19 April, and personal information associated with approximately 77 million accounts, not a verified count of unique people, had been compromised — names, addresses, email addresses, dates of birth, usernames, hashed passwords and security-question information. Sony's 2 May 2011 update states PSN passwords were hashed; the later Sony Pictures plaintext-password episode below was a separate incident.[1][2] The service stayed down for weeks. Sony's 23 May 2011 statement forecast JPY 14 billion of associated costs for the fiscal year ending March 2012, covering PSN, Qriocity and Sony Online Entertainment matters. It was a forecast, not a subsequently reported actual USD 171 million PSN-only cost.

Why the Cost Was So Large Relative to the Data

The data itself was not exceptional. No payment card data was confirmed stolen from the main account database at the level initially feared, and the individual records were the sort of profile information held by thousands of companies. The expense came from everything around it. The outage. A consumer platform offline for weeks means lost transaction revenue, lost subscription value and customer goodwill that has to be purchased back. The primary forecast does not establish that outage cost was the largest component; estimate it separately rather than assert dominance. Notification and remediation. An account count is not a unique-person notification count; determine actual affected people and notification requirements. Identity protection offerings, credit monitoring, call centre capacity for the volume of enquiries that follows. Rebuilding the platform. Sony did not simply patch and restore. The environment was substantially rebuilt before it came back, which is what happens when an organization cannot establish precisely what an intruder touched. Regulatory and legal process. Multiple jurisdictions, multiple investigations, litigation, and appearances before legislators in several countries. The apology. Free content, extended subscriptions and welcome-back packages offered to reacquire customer trust. This case does not establish a general cost correlation. Model sensitivity, disruption, affected individuals, remediation and legal duties from the actual incident.

The Disclosure Problem

The reputational damage was driven less by the intrusion than by the week in between. Sony took the network offline on 20 April and provided limited explanation. Users experienced an unexplained outage of a paid service, then learned several days later that their personal data had been taken. The communications vacuum was filled by speculation, and by the time accurate information arrived, the narrative was already set. This is a genuinely hard problem and it is worth being fair about it. An organization in the first days of an incident does not know what happened. Disclosing early risks being wrong; disclosing late looks like concealment. But the asymmetry is clear in hindsight: being wrong in public while visibly investigating costs far less than being silent and then confirming the worst. The practical resolution most organizations arrived at is to communicate the process rather than the conclusions. Say what you know, say what you do not know, say when you will next update, and then meet that commitment. It is not satisfying to the recipient, and it is considerably better than nothing.

The Year the Attack Model Changed

The Sony incident sat in the middle of a year that reframed who gets attacked and why. In May 2011, six hackers formed LulzSec following the publicity around the HBGary compromise, and ran a fifty-day campaign against high-profile organizations.[4][5] They defaced the PBS website on 30 May and published a fabricated news story;[6] on 2 June they announced a breach of Sony Pictures Entertainment, releasing usernames, passwords, email addresses and phone numbers belonging to tens of thousands of people, many of whom had supplied their details for prize draws.[7] The detail that should have alarmed every security team was the plaintext passwords. Not weakly hashed — plaintext, in a marketing database, for a sweepstakes entry. That is not a sophisticated-attacker problem. That is a basic controls problem in a system nobody considered important. And the motive was not financial. These attacks targeted organizations for attention, embarrassment and ideology. Risk models built around "we do not hold data worth stealing" had no answer to an adversary whose objective was publicity.

Practical Guidance from the 2011 Breach Year

  • Model breach cost as disruption plus notification, not as record value. Quantify downtime, communication and rebuild alongside other costs; no universal component ranking is established. A breach of unremarkable data can still be a nine-figure event.
  • Inventory the systems nobody considers important. Marketing databases, competition entries, legacy applications, acquired platforms. This is consistently where plaintext credentials and forgotten personal data live.
  • Never store recoverable passwords, anywhere. Strong hashing with salting, no exceptions, including in systems built by agencies or inherited through acquisition. Audit for this specifically rather than assuming.
  • Write the communications plan before you need it. Holding statements, notification templates, call centre scaling, regulatory contacts and a defined update cadence. Drafting this during an incident produces the silence that causes the damage.
  • Rehearse the decision to take a service offline. Who has authority, what the revenue impact is per day, and what conditions must be met before restoration. This decision is made badly under pressure without prior thought.
  • Assume you will not know the scope for weeks. Build logging and segmentation now so that forensic investigation can produce answers. Organizations that rebuild from scratch do so because they cannot determine what was touched.
  • Extend the threat model beyond financially motivated attackers. Ideological, reputational and opportunistic adversaries pick targets on visibility, not asset value.
  • Test the backup and restore path for a full platform. Sony's weeks-long recovery was partly forensic and partly reconstruction. Most organizations have never attempted a restore at that scale.

The Insurance Consequence

One under-appreciated effect of the 2011 breach year was commercial. Cyber insurance had existed as a niche product since the late 1990s, usually attached to errors and omissions or general liability cover, with limited scope.[8] It was a specialist purchase that most boards had never discussed. A year of highly visible incidents with quantifiable costs changed that conversation. Standalone cyber products developed, and the market grew substantially over the following years — Marsh estimated US gross written premiums at around $1 billion by 2013.[9] Insurance mattered for a reason beyond risk transfer. Underwriting requires assessment, and assessment forced organizations to document controls they had never inventoried. For many companies the first honest security review they ever completed was an insurance application.

The Modern Echo

Every element of 2011 is recognisable now, at larger scale. Disruption can contribute to breach cost, but this incident does not establish a universal ranking against data sensitivity. Forgotten systems with poor controls remain the most common entry point. And the disclosure dilemma has been formalised into statutory notification deadlines that force a decision within days. The newest version of the forgotten-system problem is worth naming. Organizations now have AI tools connected to internal data stores, built quickly, frequently outside formal architecture review, with access provisioned generously to make them useful. They are the marketing database of this decade: important enough to hold real data, peripheral enough that nobody has audited them. The question Sony's year should prompt is not whether your crown jewels are protected. It is what else is connected, who built it, and what it can reach.

Common Questions

What happened in the 2011 PlayStation Network breach?

An intrusion between 17 and 19 April 2011 compromised personal information belonging to approximately 77 million accounts, including names, addresses, dates of birth, usernames, passwords and security question answers. The service was taken offline on 20 April and remained down for weeks.

How much did the PlayStation Network breach cost?

Sony forecast JPY 14 billion in its 23 May 2011 statement for the fiscal year ending March 2012 across the relevant PSN, Qriocity and SOE matters. It was not an actual PSN-only bill, and that source does not establish which cost component was largest.

Why was the disclosure handling criticised?

Because there was a gap of several days between taking the service offline and confirming that personal data had been taken. The communications vacuum was filled with speculation, and the delay read as concealment even though the organization was still investigating.

What did LulzSec change about the threat model?

It demonstrated that attackers motivated by publicity rather than money select targets on visibility, and that peripheral systems — such as a sweepstakes database storing plaintext passwords — are the practical entry point regardless of how well core systems are defended.


Breach Cost Assessment — Outpace models what an incident would actually cost your business in downtime, notification and rebuild, then finds the forgotten systems most likely to cause it.

Continue reading

Talk to OPS

Start with the operating problem.