
On November 24, 2014, the
hacker
A hacker is a person skilled in information technology who achieves goals and solves problems by non-standard means. The term has become associated in popular culture with a security hackersomeone with knowledge of bug (computing), bugs or exp ...
group "
Guardians of Peace"
leaked confidential data from the film studio
Sony Pictures Entertainment
Sony Pictures Entertainment Inc. is an American diversified multinational mass media and entertainment studio conglomerate that produces, acquires, and distributes filmed entertainment (theatrical motion pictures, television programs, and rec ...
(SPE). The data included employee emails, personal and family information, executive salaries, copies of then-unreleased films, future film plans, screenplays, and other information. The perpetrators then employed a variant of the
Shamoon
Shamoon (), also known as W32.DistTrack, is a modular computer virus that was discovered in 2012, targeting then-recent 32-bit architecture of Windows NT, NT kernel versions of Microsoft Windows. The virus was notable due to the destructive nature ...
wiper malware to erase Sony's computer infrastructure.
During the hack, the group demanded that Sony withdraw its then-upcoming film ''
The Interview'', a
political satire
Political satire is a type of satire that specializes in gaining entertainment from politics. Political satire can also act as a tool for advancing political arguments in conditions where political speech and dissent are banned.
Political satir ...
action comedy film
The action comedy is a film genre that applies to action films where humor plays a much more central role. While early films feature stuntwork and humor, academic Cynthia King wrote that the genre only came into its own as a mainstay of the Americ ...
produced and directed by
Seth Rogen
Seth Aaron Rogen (; born April 15, 1982) is a Canadian actor, comedian, and filmmaker. Known primarily for his comedic Leading actor, leading man roles in films, the accolades he has received include nominations for three Golden Globe Awards, ...
and
Evan Goldberg
Evan D. Goldberg (born September 15, 1982) is a Canadian screenwriter, film producer and director. He has collaborated with his childhood friend Seth Rogen on a variety of films, including '' Superbad'', '' Pineapple Express'', '' This Is the En ...
. The film stars Rogen and
James Franco
James Edward Franco (born April 19, 1978) is an American actor and filmmaker. He has starred in numerous films, including Sam Raimi's Spider-Man (2002 film series), ''Spider-Man'' trilogy (2002–2007), ''Milk (2008 American film), Milk'' (200 ...
as journalists who set up an interview with North Korean leader
Kim Jong Un
Kim Jong Un (born 8 January 1983 or 1984) is a North Korean politician and dictator who has served as supreme leader of North Korea since 2011 and general secretary of the Workers' Party of Korea (WPK) since 2012. He is the third son of Kim ...
only to then be recruited by the
CIA to
assassinate him. The hacker group threatened
terrorist attack
Terrorism, in its broadest sense, is the use of violence against non-combatants to achieve political or ideological aims. The term is used in this regard primarily to refer to intentional violence during peacetime or in the context of war a ...
s at cinemas screening the film, resulting in many major U.S. theater chains opting not to screen ''The Interview''. In response to these threats, Sony chose to cancel the film's formal premiere and mainstream release, opting to skip directly to a downloadable digital release followed by a limited theatrical release the next day.
United States intelligence officials, after evaluating the software, techniques, and network sources used in the hack, concluded that the attack was sponsored by the government of North Korea, which has since denied all responsibility.
Hack and perpetrators
The exact duration of the hack is yet unknown. U.S. investigators say the culprits spent at least two months copying critical files. A purported member of the Guardians of Peace (GOP) who has claimed to have performed the hack stated that they had access for at least a year prior to its discovery in November 2014.
The hackers involved claim to have taken more than 100 terabytes of data from Sony, but that claim has never been confirmed. The attack was conducted using
malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
. Although Sony was not specifically mentioned in its advisory, the
United States Computer Emergency Readiness Team said that attackers used a
Server Message Block
Server Message Block (SMB) is a communication protocol used to share files, printers, serial ports, and miscellaneous communications between nodes on a network. On Microsoft Windows, the SMB implementation consists of two vaguely named Windows ...
(SMB)
Worm
Worms are many different distantly related bilateria, bilateral animals that typically have a long cylindrical tube-like body, no limb (anatomy), limbs, and usually no eyes.
Worms vary in size from microscopic to over in length for marine ...
Tool to conduct attacks against a major entertainment company. Components of the attack included a listening implant,
backdoor, proxy tool, destructive
hard drive
A hard disk drive (HDD), hard disk, hard drive, or fixed disk is an electro-mechanical data storage device that stores and retrieves digital data using magnetic storage with one or more rigid rapidly rotating hard disk drive platter, pla ...
tool, and destructive target cleaning tool. The components clearly suggest an intent to gain repeated entry, extract information, and be destructive, as well as remove evidence of the attack.
Sony was made aware of the hack on Monday, November 24, 2014, as the malware previously installed rendered many Sony employees' computers inoperable by the software, with the warning by a group calling themselves the Guardians of Peace, along with a portion of the confidential data taken during the hack.
Several Sony-related Twitter accounts were also taken over.
This followed a message that several Sony Pictures executives had received via email on the previous Friday, November 21; the message, coming from a group called "God'sApstls" , demanded "monetary compensation" or otherwise, "Sony Pictures will be bombarded as a whole".
This email message had been mostly ignored by executives, lost in the volume they had received or treated as spam email.
In addition to the activation of the malware on November 24, the message included a warning for Sony to decide on their course of action by 11:00p.m. UTC that evening, although no apparent threat was made when that deadline passed.
In the days following this hack, the Guardians of Peace began leaking yet-unreleased films and started to release portions of the confidential data to attract the attention of social media sites, although they did not specify what they wanted in return.
Sony quickly organized internal teams to try to manage the loss of data to the Internet, and contacted the
Federal Bureau of Investigation
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
(FBI) and the private security firm
FireEye
Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company that was founded in 2022. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and ana ...
to help protect Sony employees whose personal data was exposed by the hack, repair the damaged computer infrastructure and trace the source of the leak.
The first public report concerning a North Korean link to the attack was published by ''
Re/code'' on November 28 and later confirmed by
NBC News
NBC News is the news division of the American broadcast television network NBC. The division operates under NBCUniversal Media Group, a division of NBCUniversal, which is itself a subsidiary of Comcast. The news division's various operations r ...
.
On December 8, 2014, alongside the eighth large data dump of confidential information, the Guardians of Peace threatened Sony with language relating to the
September 11 attacks
The September 11 attacks, also known as 9/11, were four coordinated Islamist terrorist suicide attacks by al-Qaeda against the United States in 2001. Nineteen terrorists hijacked four commercial airliners, crashing the first two into ...
that drew the attention of U.S. security agencies.
North Korean
state-sponsored hackers are suspected by the United States of being involved in part due to specific threats made toward Sony and movie theaters showing ''
The Interview'', a comedy film about an assassination attempt against
Kim Jong Un
Kim Jong Un (born 8 January 1983 or 1984) is a North Korean politician and dictator who has served as supreme leader of North Korea since 2011 and general secretary of the Workers' Party of Korea (WPK) since 2012. He is the third son of Kim ...
. North Korean officials had previously expressed concerns about the film to the
United Nations
The United Nations (UN) is the Earth, global intergovernmental organization established by the signing of the Charter of the United Nations, UN Charter on 26 June 1945 with the stated purpose of maintaining international peace and internationa ...
, stating that "to allow the production and distribution of such a film on the assassination of an incumbent head of a sovereign state should be regarded as the most undisguised sponsoring of terrorism as well as an act of war."
In its first quarter financials for 2015, Sony Pictures set aside $15 million to deal with ongoing damages from the hack. Sony bolstered its cyber-security infrastructure as a result, using solutions to prevent similar hacks or data loss in the future.
Sony co-chairperson
Amy Pascal announced in the wake of the hack that she would step down effective May 2015, and instead will become more involved with film production under Sony.
Information obtained
According to a notice letter dated December 8, 2014, from SPE to its employees, SPE learned on December 1, 2014 that personally identifiable information about employees and their dependents may have been obtained by unauthorized individuals as a result of a "brazen cyber-attack", including names, addresses,
Social Security number
In the United States, a Social Security number (SSN) is a nine-digit number issued to United States nationality law, U.S. citizens, Permanent residence (United States), permanent residents, and temporary (working) residents under section 205(c)(2 ...
s and financial information.
On December 7, 2014,
C-SPAN
Cable-Satellite Public Affairs Network (C-SPAN ) is an American Cable television in the United States, cable and Satellite television in the United States, satellite television network, created in 1979 by the cable television industry as a Non ...
reported that the hackers stole 47,000 unique Social Security numbers from the SPE computer network.
Although personal data may have been stolen, early news reports focused mainly on celebrity gossip and embarrassing details about Hollywood and
film industry
The film industry or motion picture industry comprises the technological and commercial institutions of filmmaking, i.e., film production company, production companies, film studios, cinematography, animation, film production, screenwriting, pre- ...
business affairs gleaned by the media from electronic files, including private email messages. Among the information revealed in the emails was that Sony CEO
Kazuo Hirai
is a Japanese businessman. He is best known as the former chairman of Sony Corporation, serving from April 2018 to June 2019, as well as president and CEO from April 2012 to April 2018. He also served as a board member of Sony Computer Entertain ...
pressured Sony Pictures co-chairwoman Amy Pascal to "soften" the assassination scene in ''The Interview''.
Many details relating to the actions of the Sony Pictures executives, including Pascal and
Michael Lynton, were also released, in a manner that appeared to be intended to spur distrust between these executives and other employees of Sony.
Other emails released in the hack showed Pascal and
Scott Rudin, a film and theatrical producer, discussing
Angelina Jolie
Angelina Jolie ( ; born Angelina Jolie Voight, , June 4, 1975) is an American actress, filmmaker, and humanitarian. The recipient of List of awards and nominations received by Angelina Jolie, numerous accolades, including two Academy Awards ...
. In the emails, Rudin referred to Jolie as "a minimally talented spoiled brat" because Jolie wanted
David Fincher
David Andrew Leo Fincher (born August 28, 1962) is an American film director. Often described as one of the preeminent directors of his generation, David Fincher filmography, his films, of which most are psychological thrillers, have collectiv ...
to direct her film ''Cleopatra'', which Rudin felt would interfere with Fincher directing a
planned film about
Steve Jobs
Steven Paul Jobs (February 24, 1955 – October 5, 2011) was an American businessman, inventor, and investor best known for co-founding the technology company Apple Inc. Jobs was also the founder of NeXT and chairman and majority shareholder o ...
. Pascal and Rudin were also noted to have had an email exchange about Pascal's upcoming encounter with
Barack Obama
Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. O ...
that included characterizations described as racist, which led to Pascal's resignation from Sony.
[Christopher Rosen]
Scott Rudin & Amy Pascal Apologize After Racially Insensitive Emails About Obama Leak
, ''The Huffington Post
''HuffPost'' (''The Huffington Post'' until 2017, itself often abbreviated as ''HPo'') is an American progressive news website, with localized and international editions. The site offers news, satire, blogs, and original content, and covers p ...
'', December 11, 2014 The two had suggested they should mention films about African-Americans upon meeting the president, such as ''
Django Unchained'', ''
12 Years a Slave
''Twelve Years a Slave'' is an 1853 memoir and slave narrative by Solomon Northup as told to and written by David Wilson. Northup, a black man who was born free in New York state, details himself being tricked to go to Washington, D.C., whe ...
'' and ''
The Butler'', all of which depict
slavery in the United States
The legal institution of human chattel slavery, comprising the enslavement primarily of List of ethnic groups of Africa, Africans and African Americans, was prevalent in the United States of America from its founding in 1776 until 1865 ...
or the pre-
civil rights era.
Pascal and Rudin later apologized.
Details of lobbying efforts by politician
Mike Moore on behalf of the
Digital Citizens Alliance and
FairSearch against
Google
Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
were also revealed.
The leak revealed multiple details of behind-the-scenes politics on
Columbia Pictures
Columbia Pictures Industries, Inc., Trade name, doing business as Columbia Pictures, is an American film Production company, production and Film distributor, distribution company that is the flagship unit of the Sony Pictures Motion Picture Group ...
' current
''Spider-Man'' film series, including emails between Pascal and others to various heads of
Marvel Studios
Marvel Studios, LLC, formerly known as Marvel Films, is an American film and television production company. Marvel Studios is the creator of the Marvel Cinematic Universe (MCU), a media franchise and shared universe of films and television ser ...
. Due to the outcry from fans, the
Spider-Man
Spider-Man is a superhero in American comic books published by Marvel Comics. Created by writer-editor Stan Lee and artist Steve Ditko, he first appearance, first appeared in the anthology comic book ''Amazing Fantasy'' #15 (August 1962) in ...
license was eventually negotiated to be shared between both studios. In addition to the emails, a copy of the screenplay for the
''James Bond'' film ''
Spectre'', released in 2015, was obtained.
[ Several future Sony Pictures films, including '' Annie'', '' Mr. Turner'', '' Still Alice'' and '' To Write Love on Her Arms'', were also leaked.] The hackers intended to release additional information on December 25, 2014, which coincided with the release date of ''The Interview'' in the United States.
According to ''The Daily Dot
''The Daily Dot'' is a digital media company covering the culture of the Internet and the World Wide Web. It was founded by Nicholas White in 2011, and is headquartered in Austin, Texas.
The site, conceived as the Internet's "hometown newsp ...
'', based on the email leaks, while he was at Sony, executive Charles Sipkins was responsible for following senior executives' orders to edit Wikipedia
Wikipedia is a free content, free Online content, online encyclopedia that is written and maintained by a community of volunteers, known as Wikipedians, through open collaboration and the wiki software MediaWiki. Founded by Jimmy Wales and La ...
articles about them.
In December 2014, former Sony Pictures Entertainment employees filed four lawsuits against the company for not protecting their data that was released in the hack, which included Social Security numbers and medical information. As part of the emails, it was revealed that Sony was in talks with Nintendo
is a Japanese Multinational corporation, multinational video game company headquartered in Kyoto. It develops, publishes, and releases both video games and video game consoles.
The history of Nintendo began when craftsman Fusajiro Yamauchi ...
to make an animated film
Animation is a filmmaking technique whereby still images are manipulated to create moving images. In traditional animation, images are drawn or painted by hand on transparent celluloid sheets to be photographed and exhibited on film. Animati ...
based on the '' Super Mario Bros.'' franchise.
In January 2015, details were revealed of the MPAA
The Motion Picture Association (MPA) is an American trade association representing the five major film studios of the United States, the mini-major Amazon MGM Studios, as well as the video streaming services Netflix and Amazon Prime Video. F ...
's lobbying of the United States International Trade Commission to mandate U.S. ISPs either at the internet transit level or consumer level internet service provider
An Internet service provider (ISP) is an organization that provides a myriad of services related to accessing, using, managing, or participating in the Internet. ISPs can be organized in various forms, such as commercial, community-owned, no ...
, to implement IP address blocking pirate websites as well as linking websites. WikiLeaks
WikiLeaks () is a non-profit media organisation and publisher of leaked documents. It is funded by donations and media partnerships. It has published classified documents and other media provided by anonymous sources. It was founded in 2006 by ...
republished over 30,000 documents that were obtained via the hack in April 2015, with founder Julian Assange
Julian Paul Assange ( ; Hawkins; born 3 July 1971) is an Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of News leak, leaks from Chels ...
stating that the document archive "shows the inner workings of an influential multinational corporation
A multinational corporation (MNC; also called a multinational enterprise (MNE), transnational enterprise (TNE), transnational corporation (TNC), international corporation, or stateless corporation, is a corporate organization that owns and cont ...
" that should be made public. Sony condemned the WikiLeaks publication and their attorneys responded by saying it "indiscriminately" disseminated stolen data, and that this "conduct rewards a totalitarian regime seeking to silence dissident speech". The lawyers also said that "WikiLeaks is incorrect that this Stolen Information belongs in the public domain".
In November 2015, after Charlie Sheen
Carlos Irwin Estévez (born September 3, 1965), known professionally as Charlie Sheen, is an American actor. He is known as a leading man in film and television. Sheen has received numerous accolades including a Golden Globe Award as well as ...
publicly announced in a television interview that he was diagnosed with HIV, it was revealed that Sony executives were aware of the diagnosis as early as March 10, 2014, even though he never told them about it. In December, Snap Inc., due to the hack, was revealed to have acquired Vergence Labs for $15 million in cash and stock, the developers of Epiphany Eyewear, and mobile app
A mobile application or app is a computer program or software application designed to run on a mobile device such as a smartphone, phone, tablet computer, tablet, or smartwatch, watch. Mobile applications often stand in contrast to desktop appli ...
Scan for $150 million.
Threats surrounding ''The Interview''
On December 16, for the first time since the hack, the Guardians of Peace mentioned the then-upcoming film '' The Interview'' by name, and threatened to take terrorist actions against the film's New York City premiere
A premiere, also spelled première, (from , ) is the debut (first public presentation) of a work, i.e. play, film, dance, musical composition, or even a performer in that work.
History
Raymond F. Betts attributes the introduction of the ...
at Sunshine Cinema on December 18, as well as on its U.S.-wide release date, set for December 25. Sony pulled the theatrical release the following day.
Seth Rogen
Seth Aaron Rogen (; born April 15, 1982) is a Canadian actor, comedian, and filmmaker. Known primarily for his comedic Leading actor, leading man roles in films, the accolades he has received include nominations for three Golden Globe Awards, ...
and James Franco
James Edward Franco (born April 19, 1978) is an American actor and filmmaker. He has starred in numerous films, including Sam Raimi's Spider-Man (2002 film series), ''Spider-Man'' trilogy (2002–2007), ''Milk (2008 American film), Milk'' (200 ...
, the stars of '' The Interview'', responded by saying they did not know if it was definitely caused by the film, but later canceled all media appearances tied to the film outside of the planned New York City premiere on December 16, 2014. Following initial threats made towards theaters that would show ''The Interview'', several theatrical chains, including Carmike Cinemas
Carmike Cinemas, Inc. was an American motion picture exhibitor headquartered in Columbus, Georgia. As of March 2016, the company had 276 theaters with 2,954 screens in 41 states, and was the fourth largest movie theater chain in the United State ...
, Bow Tie Cinemas, Regal Entertainment Group
Regal Cinemas (also Regal Entertainment Group) is an American movie theater chain that operates the second-largest theater circuit in the United States, with 5,720 screens in 420 theaters as of December 31, 2024. Founded on August 10, 1989, it ...
, Showcase Cinemas
Showcase Cinemas is a movie theater chain owned and operated by National Amusements. It operates in the United States, Brazil (under the UCI Cinemas brand), the United Kingdom, and Argentina.
Operations
Showcase operates a total of 16 theate ...
, AMC Theatres
AMC Entertainment Holdings, Inc. (doing business as AMC Theatres, originally an abbreviation for American Multi-Cinema; often referred to simply as AMC) is an American movie theater chain founded in Kansas City, Missouri, and now headquartered ...
, Cinemark Theatres
Cinemark Holdings, Inc. (stylized as CineMark from 1998 until 2022 and in all caps since 2022) is an American movie theater chain that started operations in 1977 and since then it has operated theaters with hundreds of locations throughout the A ...
, as well as several independent movie theater owners announced that they would not screen ''The Interview''. The same day, Sony stated that they would allow theaters to opt out of showing ''The Interview'', but later decided to fully pull the national December 25 release of the film, as well as announce that there were "no further release plans" to release the film on any platform, including home video, in the foreseeable future.
On December 18, two messages (both allegedly from the Guardians of Peace) were released. One, sent in a private message to Sony executives, stated that they would not release any further information if Sony never releases the film and removed its presence from the internet. The other, posted to Pastebin, a web application used for text storage that the Guardians of Peace had used for previous messages, stated that the studio had "suffered enough" and could release ''The Interview'', but only if Kim Jong Un's death scene was not "too happy". The post also stated that the company cannot "test hem
A hem in sewing is a garment finishing method, where the edge of a piece of cloth is folded and sewn to prevent unravelling of the fabric and to adjust the length of the piece in garments, such as at the end of the sleeve or the bottom of the ga ...
again", and that "if ony Picturesmakes anything else, heywill be here ready to fight".
President Barack Obama, in an end-of-year press speech on December 19, commented on the Sony hacking and stated that he felt Sony made a mistake in pulling the film, and that producers should "not get into a pattern where you are intimidated by these acts". He also said, "We will respond proportionally and we will respond in a place and time and manner that we choose." In response to President Obama's statement, Sony Entertainment's CEO Michael Lynton said on the CNN
Cable News Network (CNN) is a multinational news organization operating, most notably, a website and a TV channel headquartered in Atlanta. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable ne ...
program '' Anderson Cooper 360'' that the public, the press and the President misunderstood the events. Lynton said the decision to cancel the wide release was in response to a majority of theaters pulling their showings and not to the hackers' threats. Lynton stated that they would seek other options to distribute the film in the future, and noted "We have not given in. And we have not backed down. We have always had every desire to have the American public see this movie."
On December 23, Sony opted to authorize approximately 300 mostly-independent theaters to show ''The Interview'' on Christmas Day, as the four major theater chains had yet to change their earlier decision not to show the film.["''The Interview'': Obama hails move to screen North Korea film."]
''BBC
The British Broadcasting Corporation (BBC) is a British public service broadcaster headquartered at Broadcasting House in London, England. Originally established in 1922 as the British Broadcasting Company, it evolved into its current sta ...
''. Retrieved December 24, 2014. The FBI worked with these theaters to detail the specifics of the prior threats and how to manage security for the showings, but noted that there was no actionable intelligence on the prior threats. Sony's Lynton stated on the announcement that "we are proud to make it available to the public and to have stood up to those who attempted to suppress free speech". ''The Interview'' was also released to Google Play
Google Play, also known as the Google Play Store, Play Store, or sometimes the Android Store (and was formerly Android Market), is a digital distribution service operated and developed by Google. It serves as the official app store for certifie ...
, Xbox Video, and YouTube
YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
on December 24. No incidents predicated by the threats occurred with the release, and instead, the unorthodox release of the film led to it being considered a success due to increased interest in the film following the attention it had received.
On December 27, the North Korean National Defence Commission released a statement accusing Obama of being "the chief culprit who forced the Sony Pictures Entertainment to indiscriminately distribute the movie."
U.S. accusations and formal charges against North Korea
U.S. government officials stated on December 17, 2014 their belief that the North Korean government was "centrally involved" in the hacking, although there was initially some debate within the White House whether or not to make this finding public. White House officials treated the situation as a "serious national security matter", and the FBI formally stated on December 19 that they connected the North Korean government to the cyber-attacks. Including undisclosed evidence, these claims were made based on the use of similar malicious hacking tools and techniques previously employed by North Korean hackers—including North Korea's cyberwarfare agency Bureau 121 on South Korean targets. According to the FBI:
* " technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korea previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks.
*"The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. government has previously linked directly to North Korea. For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack. The FBI later clarified that the source IP addresses were associated with a group of North Korean businesses located in Shenyang in northeastern China.
*"Separately, the tools used in the SPE attack have similarities to a cyber-attack in March of last year against South Korean banks and media outlets, which was carried out by North Korea."
The FBI later clarified more details of the attacks, attributing them to North Korea by noting that the hackers were "sloppy" with the use of proxy IP addresses that originated from within North Korea. At one point the hackers logged into the Guardians of Peace Facebook
Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
account and Sony's servers without effective concealment. FBI Director James Comey
James Brien Comey Jr. (; born December 14, 1960) is an American lawyer who was the seventh director of the Federal Bureau of Investigation (FBI) from 2013 until Dismissal of James Comey, his termination in May 2017. Comey was a registered Repub ...
stated that Internet access is tightly controlled within North Korea, and as such, it was unlikely that a third party had hijacked these addresses without allowance from the North Korean government. The National Security Agency
The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
assisted the FBI in analyzing the attack, specifically in reviewing the malware and tracing its origins; NSA director Admiral Michael S. Rogers agreed with the FBI that the attack originated from North Korea. A disclosed NSA report published by ''Der Spiegel
(, , stylized in all caps) is a German weekly news magazine published in Hamburg. With a weekly circulation of about 724,000 copies in 2022, it is one of the largest such publications in Europe. It was founded in 1947 by John Seymour Chaloner ...
'' stated that the agency had become aware of the origins of the hack due to their own cyber-intrusion on North Korea's network that they had set up in 2010, following concerns of the technology maturation of the country.
The North Korean news agency KCNA denied the "wild rumours" of North Korean involvement, but said that "The hacking into the SONY Pictures might be a righteous deed of the supporters and sympathizers with the DPRK in response to its appeal." North Korea offered to be part of a joint probe with the United States to determine the hackers' identities, threatening consequences if the United States refused to collaborate and continued the allegation. The U.S. refused and asked China for investigative assistance instead. Some days after the FBI's announcement, North Korea temporarily suffered a nationwide Internet outage, which the country claimed to be the United States' response to the hacking attempts.
On the day following the FBI's accusation of North Korea's involvement, the FBI received an email purportedly from the hacking group, linking to a YouTube
YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
video entitled "you are an idiot!", apparently mocking the organization.
On December 19, 2014, U.S. Secretary of Homeland Security Jeh Johnson released a statement saying, "The cyber attack against Sony Pictures Entertainment was not just an attack against a company and its employees. It was also an attack on our freedom of expression
Freedom of speech is a principle that supports the freedom of an individual or a community to articulate their opinions and ideas without fear of retaliation, censorship, or legal sanction. The rights, right to freedom of expression has been r ...
and way of life." He encouraged businesses and other organizations to use the Cybersecurity Framework developed by the National Institute of Standards and Technology
The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into Outline of p ...
(NIST) to assess and limit cyber risks and protect against cyber threats. On the same day, U.S. Secretary of State John Kerry
John Forbes Kerry (born December 11, 1943) is an American attorney, politician, and diplomat who served as the 68th United States secretary of state from 2013 to 2017 in the Presidency of Barack Obama#Administration, administration of Barac ...
published his remarks condemning North Korea for the cyber-attack and threats against movie theatres and moviegoers. "This provocative and unprecedented attack and subsequent threats only strengthen our resolve to continue to work with partners around the world to strengthen cybersecurity, promote norms of acceptable state behavior, uphold freedom of expression, and ensure that the Internet remains open
Open or OPEN may refer to:
Music
* Open (band), Australian pop/rock band
* The Open (band), English indie rock band
* ''Open'' (Blues Image album), 1969
* ''Open'' (Gerd Dudek, Buschi Niebergall, and Edward Vesala album), 1979
* ''Open'' (Go ...
, interoperable
Interoperability is a characteristic of a product or system to work with other products or systems. While the term was initially defined for information technology or systems engineering services to allow for information exchange, a broader de ...
, secure and reliable," he said.
On January 2, 2015, the U.S., under an Executive Order
In the United States, an executive order is a directive by the president of the United States that manages operations of the federal government. The legal or constitutional basis for executive orders has multiple sources. Article Two of the ...
issued by President Obama, installed additional economic sanctions on already-sanctioned North Korea for the hack, which North Korean officials called out as "groundlessly stirring up bad blood towards" the country.
Doubts about accusations against North Korea
Cyber security expert Kurt Stammberger from cyber security firm Norse, DEFCON organizer and Cloudflare
Cloudflare, Inc., is an American company that provides content delivery network services, cybersecurity, DDoS mitigation, wide area network services, reverse proxies, Domain Name Service, ICANN-accredited domain registration, and other se ...
researcher Marc Rogers, Hector Monsegur, and Kim Zetter, a security journalist at ''Wired
Wired may refer to:
Arts, entertainment, and media Music
* ''Wired'' (Jeff Beck album), 1976
* ''Wired'' (Hugh Cornwell album), 1993
* ''Wired'' (Mallory Knox album), 2017
* "Wired", a song by Prism from their album '' Beat Street''
* "Wired ...
'' magazine, have expressed doubt and tended to agree that North Korea might not be behind the attack.
Michael Hiltzik
Michael A. Hiltzik (born November 9, 1952) is an American columnist, reporter and author who has written extensively for the ''Los Angeles Times''. In 1999, he won a beat reporting Pulitzer Prize for co-writing a series of articles about corrupti ...
, a journalist for the ''Los Angeles Times
The ''Los Angeles Times'' is an American Newspaper#Daily, daily newspaper that began publishing in Los Angeles, California, in 1881. Based in the Greater Los Angeles city of El Segundo, California, El Segundo since 2018, it is the List of new ...
'', said that all evidence against North Korea was "circumstantial" and that some cybersecurity experts were "skeptical" about attributing the attack to the North Koreans.[Hiltzik, Michael (December 19, 2014)]
"The Sony hack: What if it isn't North Korea?"
''Los Angeles Times
The ''Los Angeles Times'' is an American Newspaper#Daily, daily newspaper that began publishing in Los Angeles, California, in 1881. Based in the Greater Los Angeles city of El Segundo, California, El Segundo since 2018, it is the List of new ...
''. Retrieved December 21, 2014. Cybersecurity expert Lucas Zaichkowsky said, "State-sponsored attackers don't create cool names for themselves like 'Guardians of Peace' and promote their activity to the public." Kim Zetter of ''Wired'' magazine called released evidence against the government "flimsy".[ Zetter, Kim (December 17, 2014)]
"The Evidence That North Korea Hacked Sony Is Flimsy."
''Wired''. Retrieved December 21, 2014. Former hacker Hector Monsegur, who once hacked into Sony, explained to CBS News
CBS News is the news division of the American television and radio broadcaster CBS. It is headquartered in New York City. CBS News television programs include ''CBS Evening News'', ''CBS Mornings'', news magazine programs ''CBS News Sunday Morn ...
that exfiltrating one or one hundred terabyte
The byte is a unit of digital information that most commonly consists of eight bits. Historically, the byte was the number of bits used to encode a single character of text in a computer and for this reason it is the smallest addressable un ...
s of data "without anyone noticing" would have taken months or years, not weeks. Monsegur doubted the accusations due to North Korea's insufficient internet infrastructure to handle the transfer of that much data. He believed that it could have been either Chinese, Russian, or North Korean-sponsored hackers working outside of the country, but most likely to be the deed of a Sony employee.
Stammberger provided to the FBI Norse's findings that suggest the hack was an inside job
An inside job is a crime committed by a person in a position of trust, or with the help of someone either employed by the victim or entrusted with access to the victim's affairs or premises.
Inside Job may also refer to:
Books
* ''Inside J ...
, stating, "Sony was not just hacked; this is a company that was essentially nuked from the inside. We are very confident that this was not an attack master-minded by North Korea and that insiders were key to the implementation of one of the most devastating attacks in history." Stammberger believes that the security failure may have originated from six disgruntled former Sony employees, based on their past skill sets and discussions these people made in chat rooms. Norse employees identified these people from a list of workers that were eliminated from Sony during a restructuring in May 2014, and noted that some had made very public and angry responses to their firing, and would be in appropriate positions to identify the means to access secure parts of Sony's servers. After a private briefing lasting three hours, the FBI formally rejected Norse's alternative assessment.
Seth Rogen also expressed doubts about the claims that North Korea was behind the hack. Based on the timeline of events and the amount of information hacked, he believes the hack may have been conducted by a Sony employee. "I've also heard people say that they think someone was hired to do the hack as a way of getting Amy Pascal fired. I don't know if I subscribe to those theories, but I kind of don't think it was North Korea."
Other investigations
In response to allegations that the intrusion was the result of an inside job, or something other than a state-sponsored cyber attack, computer forensic specialist Kevin Mandia, president of the security firm FireEye
Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company that was founded in 2022. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and ana ...
, commented that there was not a "shred of evidence" that an insider was responsible for the attack and that the evidence uncovered by his security firm supports the position of the United States government.
In February 2016, analytics firm Novetta issued a joint investigative report into the attack. The report, published in collaboration with Kaspersky Lab
Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky a ...
, Symantec, AlienVault, Invincea, Trend Micro
is an American-Japanese cyber security software company. The company has globally dispersed R&D in 16 locations across every continent excluding Antarctica. The company develops enterprise security software for servers, containers, and cloud ...
, Carbon Black
Carbon black (with subtypes acetylene black, channel black, furnace black, lamp black and thermal black) is a material produced by the incomplete combustion of coal tar, vegetable matter, or petroleum products, including fuel oil, fluid cataly ...
, PunchCyber, RiskIQ, ThreatConnect and Volexity, concluded that a well-resourced organization had committed the intrusion, and that "we strongly believe that the SPE attack was not the work of insiders or hacktivists". The analysis said that the same group is engaged in military espionage campaigns.[Collaborative Operation Blockbuster aims to send Lazarus back to the dead]
symantec.com, February 24, 2016.
Formal charges
The U.S. Department of Justice issued formal charges related to the Sony hack on North Korean citizen Park Jin-hyok on September 6, 2018. The Department of Justice contends that Park was a North Korean hacker that worked for the country's Reconnaissance General Bureau, the equivalent of the Central Intelligence Agency
The Central Intelligence Agency (CIA; ) is a civilian foreign intelligence service of the federal government of the United States tasked with advancing national security through collecting and analyzing intelligence from around the world and ...
. The Department of Justice also asserted that Park was partially responsible for arranging the WannaCry ransomware attack
The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the form ...
of 2017, having developed part of the ransomware software. The Department of Justice had previously identified Park and had been monitoring him for some time, but could not indict him immediately as much of the information around him was classified. The Criminal Complaint was unsealed by the US Department of Justice via a press release in September 2018.
Legal responses
Obama also issued a legislative proposal to Congress to update current laws such as the Racketeer Influenced and Corrupt Organizations Act
The Racketeer Influenced and Corrupt Organizations (RICO) Act is a United States federal law that provides for extended criminal penalties and a civil cause of action for acts performed as part of an ongoing criminal organization.
RICO was e ...
and introduce new ones to allow federal and national law enforcement officials to better respond to cybercrimes like the Sony hack, and to be able to prosecute such crimes compatibly to similar off-line crimes, while protecting the privacy of Americans.
Public discussion
About reporting on the hack
In December 2014, Sony requested that the media stop covering the hack.[ Sony also threatened legal action if the media did not comply, but according to law professor ]Eugene Volokh
Eugene Volokh (; born Yevhen Volodymyrovych Volokh (); February 29, 1968) is an American legal scholar known for his scholarship in American constitutional law and Libertarianism in the United States, libertarianism as well as his prominent leg ...
, Sony's legal threats are "unlikely to prevail". Sony then threatened legal action against Twitter
Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
if it did not suspend accounts of people who posted the hacked material. American screenwriter Aaron Sorkin wrote an op-ed
An op-ed, short for "opposite the editorial page," is a type of written prose commonly found in newspapers, magazines, and online publications. They usually represent a writer's strong and focused opinion on an issue of relevance to a targeted a ...
for ''The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' opining that the media was helping the hackers by publishing and reporting on the leaked information. On December 18, Reddit
Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
banned the subreddit
Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
r/SonyGOP that was being used to distribute the hacked files.
About pulling ''The Interview''
The threats made directly at Sony over ''The Interview'' were seen by many as a threat to free speech. The decision to pull the film was criticized by several Hollywood filmmakers, actors, and television hosts, including Ben Stiller
Benjamin Edward Meara Stiller (born November 30, 1965) is an American actor, comedian, and filmmaker. Known for his blend of slapstick humor and sharp wit, Stiller rose to fame through comedies such as ''There's Something About Mary'' (1998), ' ...
, Steve Carell, Rob Lowe
Robert Hepler Lowe (born March 17, 1964) is an American actor, filmmaker, and entertainment host. Following numerous television roles in the early 1980s, he came to prominence as a teen idol and member of the Brat Pack with starring roles in ...
, Jimmy Kimmel
James Christian Kimmel (born November 13, 1967), known professionally as Jimmy Kimmel, is an American television host, comedian, writer, voice actor, and producer. He has been the host and executive producer of '' Jimmy Kimmel Live!'', a late-n ...
and Judd Apatow
Judd Apatow (; born December 6, 1967) is an American director, producer, screenwriter, and comedian known for his work in comedy films. Apatow is the founder of Apatow Productions, through which he wrote, produced, and directed his films ''The 4 ...
. Some commentators contrasted the situation to the non-controversial release of the 2004 '' Team America: World Police'', a film that mocked the leadership of North Korea's prior leader, Kim Jong Il
Kim Jong Il (born Yuri Kim; 16 February 1941 or 1942 – 17 December 2011) was a North Korean politician who was the second Supreme Leader (North Korean title), supreme leader of North Korea from Death and state funeral of Kim Il Sung, the de ...
. The Alamo Drafthouse
The Alamo Drafthouse Cinema is an American cinema chain founded in 1997 in Austin, Texas, which is famous for serving dinner and drinks during the film, as well as its strict policy of requiring its audiences to maintain proper cinema-going etiq ...
was poised to replace showings of ''The Interview'' with ''Team America'' until the film's distributor Paramount Pictures
Paramount Pictures Corporation, commonly known as Paramount Pictures or simply Paramount, is an American film production company, production and Distribution (marketing), distribution company and the flagship namesake subsidiary of Paramount ...
ordered the theaters to stop.
In light of the threats made to Sony over ''The Interview'', New Regency cancelled its March 2015 production plans for a film adaptation of the graphic novel '' Pyongyang: A Journey in North Korea'', which was set to star Steve Carell. '' Hustler'' announced its intentions to make a pornographic parody film of ''The Interview''. ''Hustler'' founder Larry Flynt said, "If Kim Jong-un and his henchmen were upset before, wait till they see the movie we're going to make".
Outside the United States
In China, the media coverage of the hackings has been limited and outside sources have been censored. A search for "North Korea hack" on Baidu
Baidu, Inc. ( ; ) is a Chinese multinational technology company specializing in Internet services and artificial intelligence. It holds a dominant position in China's search engine market (via Baidu Search), and provides a wide variety of o ...
, China's leading search engine returned just one article, which named North Korea as "one of several suspects." However, Google, which was and is inaccessible in China, returned more than 36 million results for the same query.
Hua Chunying
Hua Chunying ( zh, s=华春莹; born 24 April 1970) is a Chinese diplomat who has been serving as Vice Minister of Foreign Affairs of China since 2024. She most notably served as spokesperson of the Ministry of Foreign Affairs.
After graduating ...
, a spokeswoman of foreign affairs, "shied away from directly addressing" the Sony hacking situation.
See also
* 2013 South Korea cyberattack
* 2015–16 SWIFT banking hack
* North Korea's illicit activities
References
{{Hacking in the 2010s
2014 controversies in the United States
2014 in computing
2014 in North Korea
Attacks in the United States in 2014
Cyberattacks
Cyberwarfare in the United States
Data breaches in the United States
Email hacking
Hacking in the 2010s
North Korea–United States relations
November 2014 crimes in the United States
November 2014 in the United States
Sony Pictures Entertainment
Film controversies
Film controversies in the United States
Information published by WikiLeaks