Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - The Sony Hack – Expert Comments
News & Analysis

The Sony Hack – Expert Comments

ISBuzz TeamBy ISBuzz TeamDecember 19, 2014Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
sony hack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Sony has announced this week that it will be canceling the release of “The Interview” after hackers threatened to attack movie theaters across the United States. Here to comment on the ongoing Sony hack are a number of professionals from prominent information security companies. Tripwire, Kaspersky Lab, Voltage Security, and STEALTHbit Technologies are represented.

Free eBook: Modern Retail Security Risk – Get your copy now.

Tim Erlin, Director of Product Management, Tripwire:

“The average consumer may have a hard time understanding the size and scope of the Sony attack. Not only is it unprecedented for a cyber-attack on a private company to have these kinds of geo-political ramifications, but the technical scope of what the attackers did is unusually large. The attackers claim to have copied nearly 100 terabytes of data out of Sony, and they’ve posted some of it already. Extracting that amount of data from an organization takes time and effort. These attackers not only got into Sony, but they also had the time to assemble and remove this data and then set up a coordinated announcement of their presence via simultaneously displaying an image on systems throughout the organization. We can’t fully understand the scope of the compromise without more information, but it’s substantially more serious than the credit card thefts we’ve seen recently.”

Eugene Kaspersky, CEO, Kaspersky Lab:

“The Sony hack is probably the first one that’s been so globally high-profile. The most worrying aspect for me is that this hacker group was threatening to stage terror attacks. I don’t know if there really is a link between this group and terrorists, but the threat does show that politically-motivated hackers may be embracing terrorists’ methods. A merger between groups of hacktivists and traditional terrorist organisation has been a fear of mine for years.

“Of course, such an attack on the entertainment industry is very damaging and costly, but it’s probably not as dangerous as an attack on critical infrastructure. In any case, it’s a very strong signal that even the most advanced hi-tech companies are not immune to hacker attacks, and we have to prepare ourselves for very serious and painful attacks in the future. Sadly, it’s not easy to say which industry or company will be the next target.”

Brendan Rizzo, Technical Director, Voltage Security:

“The events that continue to unfold at Sony show a startling escalation of cyberattacks that are now becoming a worryingly effective tool for spreading fear and economic damage. This is why it is so important that companies give their utmost attention to protecting their sensitive customer, employee, and company data in a best-practice data-centric manner to shield themselves from any such attacks, including encrypting emails to protect sensitive information. If the recent attack did not result in the theft of unencrypted personal information and digital property, it would have merely been a footnote in an article instead of the global media’s lead story for several weeks running.”

Jonathan Sander, Strategy & Research Officer, STEALTHbits Technologies:

“While experts and US government officials wonder whether North Korea, hacktivists, or just another bunch of bad guys are at fault for the hack, what should be giving people chills as they read about Sony is how familiar it all feels. Sony people were emailing passwords around to one another. They were openly discussing their poor security. Perhaps most scary was that there was a lot of discussion about how they were just about to roll out the project to fix it all. If that sounds familiar to you, it’s because it echoes what’s going on at too many organizations today. An alarming number of enterprises have flawed security measures protecting their data. Employees know it, and there are people yelling about it to executives who continue to demand passwords be emailed to them when they forget. As those executives read these news stories and see themselves in these people, maybe it will be a catalyst for change. Or maybe it will be another news story forgotten as soon as the next celebrity gets into another personal crisis. I hope enlightened self-interest kicks in and we see organizations who recognize themselves in the Sony hack and rush to kick off their security program before it’s too late.

“If mercenaries snuck into the country, locked families out of their suburban California homes, and stole their stuff, there’s no doubt the US Government would react like it was an act of war. The tough choice facing the US government right now is if they will treat this digital invasion of Sony Pictures’ Culver City headquarters the same way. The comparison of the crimes is nearly one for one. Sony is locked out of their virtual homes. While they were shutting Sony out, the bad guys also took all their most sensitive documents, containing extremely personal information, embarrassing secrets, and valuable intellectual property. Imagine the attackers shipping stolen goods from a real invasion to newsrooms, where they are examined and publicly broadcasted everywhere. That’s what has happened to all the digital possessions of Sony. All their unstructured data has been trotted out for everyone to see.”

But it gets worse. Sony’s been blackmailed by the invaders, resulting in a lucrative holiday film release being canceled. The nature of the murky world of hacking means US officials are never going to have foolproof digital evidence that North Korea was behind the attack. If it was North Korea or another nation state, then serious questions need answering. There’s no question that if North Korea had rolled into Culver City in tanks and taken file cabinets full of information, there would be war right now. But it’s a very open question whether the same will happen in this instance.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read

Enhance Your Digital Crime and Security Practices Today

March 28, 20249 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}