HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)PIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SONY INTERACTIVE ENTERTAINMENT LLC
bd_5964ebb36d9098bb · schema v1 · pii pii-v1
Full breach record for SONY INTERACTIVE ENTERTAINMENT LLC →Sony Interactive Entertainment (SIE) notified New Hampshire residents of a cybersecurity event involving its IT vendor, Progress Software. An unauthorized actor exploited a vulnerability in Progress Software's MOVEit Transfer platform on May 28, 2023, to download SIE files. SIE discovered the unauthorized access on June 2, 2023, took the platform offline, and remediated the vulnerability. The incident involved personal information of former SIE employees and their family members. SIE offered complimentary credit monitoring and identity restoration services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_9166ebc934535cb1Maine State AGfiled 2023-10-03Candidate
- bd_9cc5b58ee8582363Vermont State AGfiled 2023-10-03Verified
- bd_ac2e1e883f28b084California State AGfiled 2023-10-03Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sony-interactive-entertainment-20231003.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2023
- Raw hash
- 2472086acd14de28d3b78c80ea2706715857a4b3e3dc4149704ace22f8ba0cf5
Reporting entity
- Name
- SONY INTERACTIVE ENTERTAINMENT LLCnorm: sony interactive entertainment
- Domain
- sonyinteractive.com
Victim entity
- Name
- SONY INTERACTIVE ENTERTAINMENT LLCnorm: sony interactive entertainment
- Domain
- sonyinteractive.com
Incident
- Discovered
- Jun 2, 2023
- Materiality determined
- —
- Notification sent
- Oct 3, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.