Site navigation

Sony Contacts Nearly 6,800 Employees Following Security Breach

Michael Edgar

,

MOVEit
Sony warns 6,791 current and former employees’ data may have been exposed in a cyber-attack. 

Sony, a multinational technology company, has issued warnings to current and former employees which were exposed in a data breach that took place in May of this year. According to a letter originally obtained by Bleeping Computer, the breach occurred via the transfer application MOVEit. 

The exploited zero-day is CVE-2023-34362, which was leveraged by the Cl0p ransomware group in large scale attacks across a number of organisations. 

“I don’t think we have seen the end of MOVEit disclosures yet at all, nor will we any time soon,” said Martin Kraemer, security awareness advocate at KnowBe4.

“This will be a gift that keeps on giving, as attackers – like the Clop gang – seized the opportunity to smash and grab as much as possible, as quickly as possible. They will keep sifting through their plunder and keep releasing information on the dark web as suits their goals.”

The specifics of what stolen personal data was redacted by Sony, however the company did disclose that the hackers were able to access personally identifiable information pertaining to US-based employees. 

According to Sony, after it was alerted on the issue by MOVEit’s vendor on the 31st of May, Sony took the platform offline on the 2nd of June after discovering unauthorised downloads. The company also engaged with an external cybersecurity investigation on the breach, and notified enforcement agencies. 


Recommended reading


“As cyber teams continue to address the fallout from MOVEit, the news of another breach should serve as a wakeup call to every organisation that this serious zero-day vulnerability must be remediated immediately,” said Darren Guccione, CEO and co-founder at Keeper Security.

“All organisations should take a proactive approach to regularly update software and immediately patch vulnerabilities that are being actively exploited in the wild. Organisations must ensure they have a patch deployment process defined and written down, with emergency levers for critical vulnerabilities. When organisations have a clear plan, their teams can execute it accordingly.”

This is the second security breach reported by the company in two weeks. Last week, it was reported that hackers had infiltrated Sony servers in Japan, which were used for internal testing. The hackers pilfered almost 3.5GB of data, however, Sony has assured that the breach had no negative impact on its operations. 

Michael Edgar

Staff Writer, DIGIT

Latest News

Cybersecurity Editor's Picks

OpenAI Flags Potential ‘Critical’ Cyber Risk From Astra

Business Featured Funding

VC Access Expanded For Early-stage Companies in UK

Business Editor's Picks Technology

Comment | Managing Risk in Multi-Supplier SaaS Procurements

AI Recruitment Skills

Young Scots Seek Jobs That AI Can’t Replace