Data breach
Sony
- Records
- 37,098
- Breach date
- 2 June 2011Estimated
- Added
- 24 July 2026
What was exposed
1 type of data · 3 more reported
- Email addresses1
- PasswordsReported, not counted
- Home addressesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
LulzSec, a hacking group active in 2011, breached Sony Pictures websites using a simple SQL injection attack, and our investigation team estimates that about 37,098 user records from that incident are included in this listing. The group announced the intrusion on June 2, 2011, claiming it had compromised more than one million users' personal information on SonyPictures.com. Sony Pictures disputed that figure, saying in a statement that roughly 37,500 people who entered promotional contests "may have had some personally identifiable information stolen." The group posted stolen data publicly, including records tied to two Sony-sponsored promotions, a "Seinfeld: We're Going to Del Boca Vista!" sweepstakes and a "Summer of Restless Beauty" campaign, as reported by Computerworld and the Los Angeles Times. The attack came weeks after a separate breach of Sony's PlayStation Network affected tens of millions of accounts.
May 30, 2011: According to an FBI indictment later reported by The Atlantic, the hacking operation began and took about three days to execute.
June 2, 2011: LulzSec publicly announced the breach and posted a portion of the stolen data online, including records from Sony promotional campaigns. Sony says it learned of the attack the same day.
June 9, 2011: Sony Pictures stated publicly that about 37,500 user accounts were affected, far fewer than the one million LulzSec claimed.
September 2011: The FBI announced the arrest of Cody Kretsinger, a LulzSec member charged in connection with the Sony Pictures hack.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, in an amount we could not confirm from the indexed records.
LulzSec's own claims, reported by Forbes and BBC News, described passwords, email addresses, home addresses, dates of birth, and opt-in marketing data taken from the site. The leaked files posted by the group contained roughly 37,000 accounts from the two promotional campaigns, and Computerworld's later analysis found widespread password reuse among them. Sony's statement said the stolen information did not include credit card numbers, Social Security numbers, or driver's license numbers. The group also claimed the passwords were stored in unencrypted plain text.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because email addresses and passwords were involved, people whose data appeared in the leak face a real risk of account takeovers on other services where they reused the same password. Security researchers who examined the leaked password files found that most users with matching email addresses had used identical passwords across accounts. Stolen email addresses can also be used for phishing messages that look legitimate. Home addresses and dates of birth, where taken, add to the pool of personal details that scammers can use to impersonate victims or guess security questions.
What Is Sony Doing in Response?
In its June 2011 statement, Sony said it retained outside experts to conduct a forensic investigation, took all potentially affected databases containing personal information offline, and contacted the FBI to help identify those responsible. Federal prosecutors later charged LulzSec members; Cody Kretsinger pleaded guilty, and a second member, Raynaldo Rivera, surrendered to the FBI in 2012, according to CBC News.
What Should You Do If You Were Affected?
If you entered one of the Sony promotions in question or believe your data was exposed, take these steps:
Change your password on Sony sites and anywhere else you reused it, especially email and banking accounts.
Use a unique password for each service, ideally with a password manager.
Turn on two-factor authentication wherever it is offered.
Be cautious with emails claiming to come from Sony, and avoid clicking links or entering credentials through them.
Watch your accounts for unexpected sign-ins or password reset requests.
In the news
- Los Angeles Times: Sony Pictures says LulzSec hacked 37,500 user accounts, not 1 millionlatimes.com (opens in a new tab)
- Computerworld: LulzSec's Sony hack shows rampant password re-usecomputerworld.com (opens in a new tab)
- BBC News: Sony investigating another hackbbc.com (opens in a new tab)
- Forbes: LulzSec Hackers Purge SonyPictures.comforbes.com (opens in a new tab)
- The Atlantic: LulzSec's Sony Hack Really Was as Simple as It Claimed
