Sony Interactive Entertainment (Sony) has notified current and former employees as well as their family members of a cybersecurity that led to a breach of personal data.

The company sent a notification to approximately 6,800 people, confirming that the leak occurred due to the exploitation of a zero-day vulnerability in the MOVEit Transfer platform.
The zero-day is CVE-2023-34362, a serious SQL injection flaw that leads to remote code execution. The Clop used this vulnerability in multiple attacks, affecting hundreds of organizations around the world.
The Clop group added Sony Group to its list of victims in June. However, the company has not provided a public statement until now.
According to the data breach notification, the initial attack occurred on May 28, three days before Sony was notified of the flaw by Progress Software (the MOVEit vendor). However, the incident was discovered in early June.
“On June 2, 2023, we discovered the unauthorized downloads, immediately took the platform offline, and remediated the vulnerability,” states .
“An investigation was subsequently launched with the assistance of external cybersecurity experts. We have also notified law enforcement,” Sony says in its data breach notification.
Sony says the incident was limited to that platform and did not affect any of its other systems .
However, sensitive information belonging to 6,791 people in the United States was leaked. The company has determined the details and has stated them in each individual letter.
Recipients of the notice can receive free credit monitoring and identity restoration services through Equifax, which they can access using their unique code until February 29, 2024.
Sony: And another data breach?
Late last month, there were claims on hacking forums that Sony had been hacked again and 3.14GB of data stolen. The company said at the time that it was investigating the claims.

In fact, two different hacking groups claimed responsibility for the attack. The first reports of the attack on Sony's systems came from a new ransomware group called RansomedVC. However, shortly after, another group, MajorNelson, emerged and denied RansomedVC's claims, saying that it was behind the cyberattack.
A Sony spokesperson told BleepingComputer:
“Sony is investigating recent public claims of a security. We are working with third-party experts and have identified activity on a single server located in Japan and used for internal testing for the Entertainment, Technology and Services (ET&S) business.
Sony has taken this server offline while the investigation is ongoing. At this time, there is no indication that data was stored on the affected server or that other Sony systems were affected. There has been no adverse impact on Sony operations.“.
However, even after the statement, we find that Sony has suffered at least two security breaches in recent months.
A data breach is a situation that no one wants to face, especially large companies like Sony. These incidents raise questions about the ability of organizations to protect users . Beyond the immediate consequences, such as the cost of recovery and repair, data breaches can cause deep and long-lasting damage to a company’s reputation. It is vital for businesses to strengthen their security measures by regularly reviewing and updating their cybersecurity practices and policies.
However, after the breach was discovered, Sony showed its determination to handle the issue properly. The company launched an internal investigation to fully understand what happened.
Source: www.bleepingcomputer.com
