fb-pixel Skip to main content

Sony studio is again target of hackers

The film and television studio was also the victim of a breach on Nov. 24 and the Internet pirating of five films. Fred Prouser/Reuters/File 2013

LOS ANGELES — Just as Sony Pictures Entertainment appeared to be recovering from a crippling online attack, the studio found itself confronting new perils Tuesday. The FBI warned US businesses of a similar threat, and additional Sony secrets were leaked online.

Sony, the studio behind “The Amazing Spider-Man” films and the “Breaking Bad” television series, restarted many of its computer systems Monday after a Nov. 24 breach by a group calling itself #GOP, for Guardians of Peace. Executives at the entertainment company said they were also making progress in fighting the apparently related Internet pirating of five completed films, including the unreleased “Annie.”

But Sony was newly rattled by the leak of internal documents, some of which were published late Monday on Fusion, an upstart cable network and news site, after first appearing on Pastebin, an anonymous Internet posting site. The documents contained the pre-bonus annual salaries of senior executives, 17 of whom are shown earning more than $1 million a year.

The breach exposed two things the secretive movie industry loathes the most — the piracy of films and details about executive compensation — and sent a ripple of dread across Hollywood.

On Pastebin, hackers released what they said were “tens of terabytes” of data worth of internal Sony data Monday night. The post— titled “Gift of G.O.P.” — included links to various data archives that appeared to contain Sony employees’ passwords, Social Security numbers, salaries, and performance reviews. (The password to open many of the files was “diespe123.”). The studio has offered to enroll employees in a fraud protection program.

The FBI issued a private bulletin late Monday to a wide range of companies about a malicious software threat that wipes data from computers beyond the point of recovery. An FBI spokesman declined to comment on the specifics of the bulletin, including whether it was linked to the Sony attack.

The agency did not name those affected, but the description mirrored findings at Sony. The FBI on Monday confirmed it was working with the company to investigate the attack.

Joshua Campbell, an FBI spokesman, said Tuesday the FBI’s “flash” warning, first reported by Reuters, was a routine advisory intended to “help systems administrators guard against the actions of persistent cybercriminals.”

Two people with knowledge of the advisory’s contents said the bulletin warned companies of malware that could destroy data on their hard drives and prevent computers from rebooting. The malware overwrites data in such a way that it can be nearly impossible to recover using standard means.

Security experts noted that unlike stealthy attacks from China and Russia, Sony’s hackers not only aimed to steal data but also to send a clear message.

“This was like a home invasion wherein after taking the family jewels the hackers set the house ablaze,” said Tom Kellermann, chief information security officer at Trend Micro, a private security firm.

And he predicts more of the same next year. “In 2015, hackers will destroy systems not just for activism but also for counter-incident response,” he said.

Some security experts warned that hackers could be leaking Sony’s content as “click bait” for a wider crime.

Sony declined to comment Tuesday beyond its previously released statements.