HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SONY INTERACTIVE ENTERTAINMENT LLC
bd_9cc5b58ee8582363 · schema v1 · pii pii-v1
Full breach record for SONY INTERACTIVE ENTERTAINMENT LLC →Sony Interactive Entertainment (SIE) notified consumers of a data breach involving its IT vendor, Progress Software. An unauthorized actor exploited a vulnerability in Progress Software's MOVEit Transfer platform on May 28, 2023, to download files containing personal information of SIE employees and family members. SIE discovered the breach on June 2, 2023, took the platform offline, and engaged external experts. Affected data included names and government IDs. SIE offered credit monitoring services.
Vermont clock✗ VT AG >45 bday18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5964ebb36d9098bbNew Hampshire State AGfiled 2023-10-03Verified
- bd_9166ebc934535cb1Maine State AGfiled 2023-10-03Candidate
- bd_ac2e1e883f28b084California State AGfiled 2023-10-03Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-03-sony-interactive-entertainment-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2023
- Raw hash
- 0bbf37e6bf7b64d407ed6edd5358aaeb266a7f3023c0e4d2977b5ce588399734
Reporting entity
- Name
- SONY INTERACTIVE ENTERTAINMENT LLCnorm: sony interactive entertainment
- Domain
- sonyinteractive.com
Victim entity
- Name
- SONY INTERACTIVE ENTERTAINMENT LLCnorm: sony interactive entertainment
- Domain
- sonyinteractive.com
Incident
- Discovered
- Jun 2, 2023
- Materiality determined
- Oct 3, 2023
- Notification sent
- Oct 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(123 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.