Sony ISP 'So-net' hacked, customer rewards stolen

So-net, a subsidiary of Sony, was breached by hackers this week. Unlike April's PlayStation Network attack, the criminal(s) took something tangible this time: reward points gifted to customers and estimated at over $1,200.

In a week already punctuated by an overlooked PSN password change exploit and a phishing scheme integrated into the company's Thailand page, this is a sad exclamation point for the Japanese giant.

Originally broke by the Wall Street Journal, Time's Techland detailed the almost comedic break-in.

According to the site, an email sent by So-net to its customers claimed the culprit(s) essentially tried signing into the rewards site 10,000 times from a single IP address using email addresses they had obtained. The hackers worked around a lack of passwords by using auto-generated ones, says the site, cracking into nearly 200 accounts in total - the stolen points culled from 128 of those.

Techland broaches an interesting question, and one most are now probably asking themselves: why wasn't there a security lock-out once the hacker failed to provide an accurate password after a few tries? A fair question, and one Sony may be asked to answer in the coming days.

For it's part, Sony is loathe to tie this recent cyber break-in to the calamitous attack it suffered in April, which effectively forced the company to turn off the PlayStation Network for nearly a month as it worked towards building a better, more secure version.

Keisuke Watabe, a spokesperson for So-net, said in a statement, "Although we can't completely rule out the possibility that there is a connection with the PSN issue, the likelihood is low."

Sony came under heavy fire for its perceived poor handling of the PSN situation; the company waited nearly a week to reveal that over 70 million customers' personal information was compromised due to the security breach. Another attack leveled against the company targeted its Sony Online Entertainment (SOE) division, affecting 24 million users.

No posts to display