Sony Interactive Entertainment notified about 6,800 people of MOVEit breach

Organization
Sony Interactive Entertainment
Exploit
Hacking
Industry
Video Games

Sony Interactive Entertainment began notifying about 6,800 current and former employees, and in some cases their family members, in early October 2023 that their personal information had been taken through the mass exploitation of the MOVEit Transfer file sharing product.

The notification, filed with the Maine Attorney General's office and reported publicly on October 4, said an unauthorized actor used the MOVEit zero-day tracked as CVE-2023-34362 to download files stored on Sony's own MOVEit platform on May 28, 2023. Progress Software did not disclose the vulnerability until May 31.

Sony said it identified the intrusion on June 2, immediately took the platform offline and remediated the flaw, launched an investigation with outside cyber security experts and notified law enforcement. Affected individuals were offered complimentary credit monitoring and identity restoration services through Equifax.

The Clop ransomware group, which ran the wider MOVEit extortion campaign, added Sony to its leak site in late June 2023. Sony did not detail publicly which data elements were involved, and the sample notice published by Maine's regulator had those fields redacted. The incident was distinct from a separate claim made in September 2023 by a group calling itself RansomedVC, which Sony investigated at the time.

Sources