Sony Data Breach History
WebsiteSony Group Corporation is a Japanese multinational conglomerate. Fortune 500.
This page shows all data breaches of Sony. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Sony Breaches
- 2023 MOVEit breach — 6,791 employees notified 6.8K records Share
- 2023 RansomedVC claims 260GB theft — under investigation Unknown records Share
- 2017 OurMine accesses PlayStation social accounts Unknown records Share
- 2014 Lizard Squad DDoS — PSN down over Christmas 160.0M records Share
- 2014 Guardians of Peace — 100TB Sony Pictures stolen (North Korea) Unknown records Share
Sony Data Breach Summary
This page tracks the Sony data breach history and cybersecurity incidents affecting Sony (Japan). BreachHistory currently indexes 15 publicly disclosed or catalogued incidents spanning 2008 through 2023, with approximately 378.6 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Sony breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 4 remain unverified claims pending independent verification.
Largest Sony Data Breaches
The largest indexed incidents include the 2014 Lizard Squad DDoS — PSN down over Christmas, the 2011 Sony PSN — 77M accounts, and the 2011 PlayStation Network — 77M accounts, multi-week outage, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Sony or a regulator. Below is the list of large data breaches:
- 2014 Lizard Squad DDoS — PSN down over Christmas — about 160.0M records exposed · Unverified claim
- 2011 2011 Sony PSN — 77M accounts — about 77.0M records exposed · Catalogued incident
- 2011 PlayStation Network — 77M accounts, multi-week outage — about 77.0M records exposed · Catalogued incident
- 2011 Sony Online Entertainment — 25M customer details stolen — about 25.0M records exposed · Catalogued incident
- 2011 2011 — Sony Online Entertainment: Hacking, 24,600,000 records — about 24.6M records exposed · Catalogued incident
- 2014 2014 — Sony: Data breach reported, 10.0M records — about 10.0M records exposed · Catalogued incident
- 2011 2011 Sony PSN — 3M UK users (77M global) — about 3.0M records exposed · Catalogued incident
- 2011 Sony Pictures sites hacked — 1M+ accounts — about 1.0M records exposed · Unverified claim
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, phone numbers, names, physical addresses, payment card and financial account data, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Sony Data Breach 2026
At the time of this update, no Sony data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Sony data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Sony breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.