Looking for a complete Sony data breaches list? This page answers common searches like "Sony hacked," "Sony breach history," and "list of Sony data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Sony data breach history: The 2011 PlayStation Network outage—77 million accounts—still defines gaming breach history. BreachHistory indexes 14 verified or attested incidents tied to Sony, spanning 2008–2023. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Sony notice drops.
Why Sony stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Sony for credentials, source code, CRM exports, and employee directories. When you read headlines about "Sony hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Sony
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2023 — MOVEit breach — 6,791 employees notified (7K+ records)
- 2023 — RansomedVC claims 260GB theft — under investigation (Unverified / not disclosed records)
- 2017 — OurMine accesses PlayStation social accounts (Unverified / not disclosed records)
- 2014 — Lizard Squad DDoS — PSN down over Christmas (160M+ records)
- 2014 — Guardians of Peace — 100TB Sony Pictures stolen (North Korea) (Unverified / not disclosed records)
- 2014 — Sony: Data breach reported, 10.0M records (10M+ records)
- 2011 — Sony: Hackers called LulzSec obtained over one million… (1M+ records)
- 2011 — Sony Pictures sites hacked — 1M+ accounts (1M+ records)
- 2011 — Sony Online Entertainment — 25M customer details stolen (25M+ records)
- 2011 — Sony PSN — 3M UK users (77M global) (3M+ records)
- 2011 — PlayStation Network — 77M accounts, multi-week outage (77M+ records)
- 2011 — Sony PSN — 77M accounts (77M+ records)
- 2010 — Sony: Customers who placed orders through Sony Style… (Unverified / not disclosed records)
- 2008 — PlayStation site — SQL injection, fake antivirus prompt (Unverified / not disclosed records)
Biggest and most consequential incidents
Lizard Squad DDoS — PSN down over Christmas
DDoS took down PSN for up to 160M gamers. Lizard Squad claimed responsibility. Attacker later sentenced to 27 months. Full incident record →
PlayStation Network — 77M accounts, multi-week outage
PSN hacked; names, emails, addresses, birthdates, passwords stolen. Service down weeks. Sony delayed disclosure; credit card numbers possibly at risk (no CVV). Full incident record →
2011 Sony PSN — 77M accounts
PSN and Qriocity shut down April 2011. One of largest gaming breaches. 77M accounts compromised. Full incident record →
Sony Online Entertainment — 25M customer details stolen
Personal details of 25M SOE accounts stolen (names, addresses, birthdates, phones, game purchases). Database from 2007 with 10k+ EU direct debit records also compromised. Taken Apr 16–17. Full incident record →
By the numbers (catalog snapshot)
- 14 incidents indexed under Sony on BreachHistory
- 354M+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2014 — year of the largest attested row in our catalog
Patterns in Sony's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Sony customers even when corporate HQ databases stay intact.
What to do if you used Sony
- Enable multi-factor authentication on every Sony account and linked SSO identity.
- Check Have I Been Pwned when new Sony headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Sony security communications—not SMS links from unknown numbers.
Related searches
- Sony data breach list
- Has Sony been hacked?
- Sony hack history
- Sony data leak timeline
- How many times has Sony been breached?
- Sony breach records on BreachHistory
FAQ
How many data breaches has Sony had?
BreachHistory indexes 14 verified or attested Sony data breaches spanning 2008–2023. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Sony data breach?
The largest attested incident in our catalog is 160M+ records (Lizard Squad DDoS — PSN down over Christmas). See the full timeline for sources and remediation details.
Has Sony been hacked?
Yes — Sony appears on breach trackers with 14 indexed incidents including Lizard Squad DDoS — PSN down over Christmas. This page links every catalog row with primary sources and what users should do if affected.
Does Sony send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Sony incident on BreachHistory
Browse the full catalog: Sony breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.