What happened
On 24 November 2014 Sony Pictures employees found workstations wiped and a ransom-style message on screen; terabytes of internal email, films and personnel data were later leaked. Researchers from Cylance presenting at RSA Conference 2015 said they found a phishing campaign in the months beforehand in which Sony staff, including senior executives, received fake Apple ID verification emails designed to harvest passwords. The FBI publicly attributed the attack to North Korea.
How the deception worked
In September and October 2014 messages purporting to come from Apple warned recipients of unauthorised activity on their Apple ID and pointed to a lookalike verification page. Because many staff reused passwords between personal Apple accounts and Sony systems, harvested credentials could be replayed against corporate services. The intruders spent weeks inside the network collecting mail archives, unreleased films, salary and personnel files, then executed wiper malware that overwrote master boot records and disk volumes, disabling thousands of machines while the stolen data was published in stages.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Blocking password reuse between personal and corporate accounts, plus MFA on remote access, removes the value of a harvested consumer credential.
Sources (3)
- Sony hackers targeted employees with fake Apple ID emailsComputerworld·computerworld.comOpen ↗
- Sony Hackers Used Apple ID Phishing Scheme, Researchers Claim at RSAeWeek·eweek.comOpen ↗
- Sony Hackers Used Phishing Emails to Breach Company NetworksTripwire State of Security·tripwire.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.