2011
04.30

Sony has released an official FAQ concerning the PSN outage / hack, which we have reproduced, in full, below.  However, to ensure you know what to do next, we’ve summarised your best course of action, in order of priority;

1. If your password is the same for your PSN account as it is for the mailbox of your PSN email address then change your mailbox password(s) ASAP! (i.e. on Hotmail, GMail, Yahoo etc). (The same applies if your security question was the same, you should also change this).

2. Assume your login name / email address, password and security question for PSN are know to the hacking community. If the password  / security question you use(d) for PSN are the same or similar to any others you use you should change ALL other similar passwords / security questions on any/ all other games / sites / services ASAP. (We know this is a HUGE pain and will take a number of hours for many gamers, we feel your pain, we’re changing all our passwords as you read this!)

3. If you had payment card details added to your PSN account / profile then monitor this bank account VERY closely. If you notice ANY suspicious activity contact your bank IMMEDIATELY. They will be aware of this data breach and will be able to assist you further.

4. Be very wary of ANY contact, be that by phone, email or post, which requests any information from you. If in any doubt of the identity of the requesting party / company / individual then do not answer ANY question(s).

5. As soon as PSN is back online you MUST change your PSN password IMMEDIATELY.

Unfortunately, it is extremely likely that hackers are in possession of ALL data you had stored on PSN, including your full name, nickname, username, password, birth date, address, credit card details, etc. Act accordingly.

_________________________________________________________________

Sony’s Official FAQ

(http://faq.en.playstation.com/cgi-bin/scee_gb.cfg/php/enduser/std_adp.php?locale=en_GB&p_faqid=5593)

Q.1     When did you realise the system had been intruded?
We discovered between April 17 and April 19 there was an illegal and unauthorized intrusion into our network.

Q.2     How did you know that the system was intruded?
We watch for any issues that may be raised with respect to security and monitor for such issues both internally and externally.

Q.3     What is the main reason to this problem?  Which parts of the system were vulnerable to the intrusion?
We are currently conducting a thorough investigation of the situation.  Since this is an overall security related issue, we will not comment further on this case.

Q.4     What action did you take (are you taking)?  Is there any possibility of further unauthorized access?
As soon as we learned of this issue, 1) we temporarily turned off PlayStation Network and Qriocity services in order to conduct a thorough investigation and to verify the smooth and secure operation of our network services, 2) we have also engaged an outside, recognized security firm to conduct a full and complete investigation into what happened, and 3) quickly taken steps to enhance security and strengthen our network infrastructure by re-building our system to provide you with greater protection of your personal information.

Q.5     How many were affected?  How many per each region? What is the latest status of PlayStation Network registered account/ operating countries?
Our investigation indicates that all PlayStation Network/ Qriocity accounts may have been affected.

Q.6     Does that mean all users’ information was compromised?  Tell us more in details of what personal information leaked.
In terms of possibility, yes.  We believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password, login, password security answers, and handle/PSN online ID.  It is also possible that your profile data may have been obtained, including purchase history and billing address (city, state/province, zip or postal code).  If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. If you have provided your credit card data through PlayStation Network or Qriocity, it is possible that your credit card number (excluding security code) and expiration date may also have been obtained.

Q.7     Have you notified those users?
We are sending out e-mails directly to these users to their e-mail address registered on the PS Network accounts.  Also, we have posted web notices, and additional necessary procedures have been followed by each region.

Q.8     Have you received reports or claims that their PSN ID information/ credit card had been used improperly?
Not at this point in time.

Q.9     I want to know if my account has been affected.
To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit reports.  Additionally, if you use the same user name or password for your PlayStation Network or Qriocity service account for other unrelated services or accounts, we strongly recommend that you change them.  When the PlayStation Network and Qriocity services are back on line, we also strongly recommend that you log on to change your password.
For your security, we encourage you to be especially aware of email, telephone, postal mail or other scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking.

Q.10     What should I do to prevent any unauthorized use of my (credit card) personal information?
For your security, we encourage you to be especially aware of email, telephone, postal mail or other scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking.  Additionally, if you use the same user name or password for your PlayStation Network or Qriocity service account for other unrelated services or accounts, we strongly recommend that you change them.  When the PlayStation Network and Qriocity services are back on line, we also strongly recommend that you log on to change your password.
To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit reports.

Q.11     Since when have PSN/Qriocity become unavailable and in which region?
PSN/Qriocity services have not been available since April 20 (US time) in all regions.

Q.12     How come it is taking so much time to resume the service?
We are taking the investigation seriously.  We decided to keep the service down to allow us to conduct a thorough investigation and verify smooth operation of our network services.

Q.13     How serious is this?  Have the hackers broken the security on PSN/Qriocity?  Are you taking necessary measures to prevent such outage happening in the future?
Since this is an overall security related issue, we will not comment further on this case but we are working to restore and maintain the services, including countermeasures against future intrusions.

Q.14     When will the service resume?
We are taking the investigation seriously.  We will keep the service down to allow us to conduct a thorough investigation and verify smooth operation of our network services but are working hard to resume the services as soon as we can be reasonably assured security concerns are addressed.

Q.15     Seems like SOE service was also not available/ suffering outage.  Is this true?  Is this due to the same reason as the PSN/Qriocity outage?
SOE’s service is available although a service interruption due to an external attack did occur. A thorough investigation is ongoing.

Q.16     I want my money back (subscription fee, content) since the PSN/Qriocity was not available.
When the full services are restored and the length of the outage is known, we will assess the correct course of action.

Q.17     There seems to be some games that cannot be played even offline?
Depending on the game titles, but mainly PSN games, some may require access to PSN for trophy sync, security check, etc.

Contact Details
Country     Customer Support

Africa         [email protected]
Australia     1-300 365-911
Austria     0820 44 45 40
Belgium     011 516 406
Bulgaria     [email protected]
Croatia     [email protected]
Cyprus         22352282
Czech Republic     225 341 407
Denmark     90137013
Estonia     6543484
Finland     600411911
France         0820 31 32 33
Germany     01805 766 977
Greece         801 11 92000
Hungary     1 814 4800
Iceland     591- 5100
India         1800-103-7799
Ireland     0818 365065
Israel         09-9711700
Italy         199 116 266
Latvia         67046049
Lithuania     37338655
Luxembourg     0820 31 32 33
Malta         234 360 00
Middle East     [email protected]
Netherlands     0495 574 817
New Zealand     09 415 2447
Norway         82068322
Poland         0 801 230 000
Portugal     707 23 23 10
Romania     [email protected]
Russia         8-800-200-76-67
Slovakia     232 112 209
Slovenia     1 510 31 30
South Africa     0861 773783
Spain         902 102 102
Sweden         09002033075
Switzerland     0848 84 00 85
Turkey         [email protected]
Ukraine     0 800 307 669
UK        0844 736 0595

 

Share