{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:44.210Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Sony Pictures destructive hack preceded by fake Apple ID phishing emails","date":"2014-11-24","date_precision":"day","victim_org":"Sony Pictures Entertainment","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Service Disruption","Extortion","Espionage"],"loss_usd":null,"loss_note":"Sony disclosed investigation and remediation costs in the tens of millions of dollars; a settlement of up to about $8 million with former employees was also reported. No single authoritative total is asserted here.","records_affected":null,"threat_actor":"Guardians of Peace; attributed by the FBI to North Korea (Lazarus Group)","summary":"On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.","how_it_worked":"In September and October 2014 messages purporting to come from Apple warned recipients of unauthorised activity on their Apple ID and pointed to a lookalike verification page. Because many staff reused passwords between personal Apple accounts and Sony systems, harvested credentials could be replayed against corporate services. The intruders spent weeks inside the network collecting mail archives, unreleased films, salary and personnel files, then executed wiper malware that overwrote master boot records and disk volumes, disabling thousands of machines while the stolen data was published in stages.","lessons":"Blocking password reuse between personal and corporate accounts, plus MFA on remote access, removes the value of a harvested consumer credential.","confidence":"Reported","sources":[{"title":"Sony hackers targeted employees with fake Apple ID emails","url":"https://www.computerworld.com/article/1364510/sony-hackers-targeted-employees-with-fake-apple-id-emails.html","publisher":"Computerworld"},{"title":"Sony Hackers Used Apple ID Phishing Scheme, Researchers Claim at RSA","url":"https://www.eweek.com/security/sony-hackers-used-apple-id-phishing-scheme-researchers-claim-at-rsa/","publisher":"eWeek"},{"title":"Sony Hackers Used Phishing Emails to Breach Company Networks","url":"https://www.tripwire.com/state-of-security/sony-hackers-used-phishing-emails-to-breach-company-networks","publisher":"Tripwire State of Security"}],"entry_type":"incident","slug":"2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails","year":2014,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-sony-pictures-destructive-hack-preceded-by-fake-apple-id-phishing-emails"}]}