Email Address/Passwords Hacked - Sony Pictures

bigdaddytim

New member
Just a heads up....

If you've entered a sweepstakes from Sony Pictures, your account info may have been hacked. I was alerted this morning (not by Sony though) and googled my email address. Sure enough, there it was on a few websites along with my password. Looks like a thousand or so others info is out there too.

I would highly suggest googling your email address just to make sure!
 
Original URL: http://www.theregister.co.uk/2011/06/03/sony_pictures_hacked/

New Sony hack exposes more consumer passwords
The 'sownage' continues

By Dan Goodin in San Francisco

Posted in ID, 3rd June 2011 03:15 GMT

Get a free report and consultation with an Agile expert

Hackers who last week broke into the website of television network PBS have turned their attention to Sony's movie division, publishing what appeared to be the email addresses and passwords belonging to at least 50,000 consumers who registered for online promotions.

A group called LulzSec claimed responsibility for the attack [1] and said it was achieved by exploiting a simple SQL injection vulnerability on the Sony Pictures website [2]. The group claimed the single attack exposed information for more than 1 million people, but that the group lacked the resources to copy such a massive amount of data.

"What's worse is that every bit of data we took wasn't encrypted," the group wrote in a press release announcing the hack. "Sony stored over 1,000,000 passwords of its customers in plaintext, which means it's just a matter of taking it. This is disgraceful and insecure: they were asking for it."

A Sony spokesman said the company is looking into the claims, but provided no other comment.

LulzSec is the same group that took credit for breaching security at PBS.org [3] last holiday weekend in retaliation for a documentary it claimed was unfair to whistle-blower website WikiLeaks. The pranksters published usernames and hashed passwords for website administrators and users, and they also posted a hoax news story claiming that dead rapper Tupac Shakur was alive and living in the same New Zealand town as nemesis Biggie Smalls.

The group has also hacked Sony’s Fox.com and stole hundreds of employee passwords along with the names, phone numbers and e-mail addresses of some 73,000 people who requested audition information for the upcoming talent show The X-Factor.

The compromise of Sony Pictures is the latest embarrassment for Sony, which has suffered a series of devastating hacks since being targeted for its scorched-earth legal campaign [4] against people jailbreaking the PlayStation 3 game console. All told, the attacks have exposed personally identifiable information for more than 100 million Sony customers [5] and cost Sony at least $171 million [6].

The personally identifiable information contained in Thursday's data dump appeared to belong to people who signed up for promotional campaigns involving AutoTrader.com, Sony's "Summer of Restless Beauty," and a “Seinfeld — We’re Going to Del Boca Vista!” giveaway.
 
I had a reporter from the Associated Press contact me earlier and he ended up including me in a story about the hacking.:

http://www.usatoday.com/tech/news/2011-06-02-sony-data-breach_n.htm?csp=34tech

Tim Rillahan, a 39-year-old computer instructor in Ohio, said he was extremely upset to find email address and password posted online for "the whole world to see."

"I have since been changing my passwords on every site that uses a login," he said in an email Friday. "Sony stored our passwords in plain text instead of encrypting the information. It shows little respect to us, their customers."

He and others complained that they had yet to hear from the company about the breach, news of which is nearly a day old.

It's been 15 hours since Sony Pictures said they were looking into the problem (via Facebook page). No response since. Not a good way to treat your customers.
 
I googled my email address, didn't show anything than some bingo site i belonged to awhile ago.

But, i did however get an email yesterday from Amazon. letting me know that they saw my name and email address on a "list" and that i should change my password. the email was addressed to me personally. there was no link to click on. I actually had to go to amazon and change my password from there.

I don't know what list they were referring to? I'm going to send them an email to ask them what list they saw my name and email address on.
 
Me too, they published my sweepstakes password online. It took me about 15 minutes to find some lists online from Lulz with this information from sweepstakes entries. I haven't received any phone calls yet. With the publicity surrounding this, I feel more vulnerable to international scam attacks.
 
When I Googled my email address I did not find anything, but when I did an advanced search with "lulz" plus my email address, I found it, along with my sweeps password, on the giant list. :cry: :cry:

So, are people going to each sweeps site, or changing passwords on each site as they enter? Does anyone have any good advice? Thanks.
 
When I Googled my email address I did not find anything, but when I did an advanced search with "lulz" plus my email address, I found it, along with my sweeps password, on the giant list. :cry: :cry:

So, are people going to each sweeps site, or changing passwords on each site as they enter? Does anyone have any good advice? Thanks.

I didn't find minewhen I first googled either, but when I did it with lulz it did come up! Funny thing is the password they are showing is not the password I use on Sony. Strange.
 
Hmm, that is strange. Did you use different passwords for each of the SONY sweeps?


I mostly use one password, for sweeps only, so I hope there won't be a lot of trouble. Even though the passwords have already been exposed, can't the luzsec site be taken down so they won't continue to be available? I don't get it. It's like theft, but the stolen information should not remain visible where there could potentially be additional damage from anyone who sees it...compounding the problem.
 
I had to change Facebook, Twitter, Amazon, and my ISP :cussing:

As to sweeps logins? If someone wants to enter/win for me, cool with me! I can't see where they'd benefit :scratch: :crazytongue: :whistle:
 
Sorry you had to change so many things! Those are important though, especially things like Amazon.

About sweeps logins - I was thinking and trying to figure out, with the tons of emails and passwords disclosed, if anyone would actually go through the process and get as far as a sweeps where you used that password... then what could they do if they logged in? Maybe they could find other personal information from your profile...but then I think a lot of information is already available on line, whether we chose to have it there or not (such as personal info on whitepages.com). I can't recall having to provide answers to security questions for sweeps, so mostly profiles would include name, address, phone, date of birth.

I started changing my sweeps password where I could, but now I'm getting all mixed up! :crazytongue:
 
How are you finding your information. I also googled and didn't find my name but don't know how to find the lulz list.

Can you let me know how to find it?

Thank you,
 
I went to Google Search, Advanced Search (Find webpages that have...all these words). I typed in "lulz [email protected]" and a page came up with so many email addresses and passwords. (I then found mine on that page by using Find.)

[Of course, I typed my actual email address]
 
How are you finding your information. I also googled and didn't find my name but don't know how to find the lulz list.

Can you let me know how to find it?

Thank you,

Venice, I just sent you a pm.
 
Arrtup3 - Thank you, the information worked perfectly. Fortunately I was not on that list. However, I read that out of the 1,000,000 only 38,000 were released so I will need to keep checking.

Good luck everyone - this is one time we don't want to find our names listed.
 
You're welcome, and I'm glad to hear you were not on the list.

You're absolutely right, this is one time we don't want to find our names!
 
I'm so upset (I'll be nice) with Sony...they know they were hacked, and yet they are just ignoring it for the most part. Put out a lame press release but are no contacting individuals. I don't know about anyone else, but I'm getting more and more spam since the breach.
 
I'm not quite sure what should I do now... Both mine and my husband's email addresses are on the list. It is impossible to go back to all the sweepstakes I have ever enetered with this email and password and change it. I have been bombared with spam for the past few weeks.
It all makes me so mad! :cussing:
 
Back
Top