Sony took to its blog to explain just why:
“There’s a difference in timing between when we identified there was an intrusion and when we learned of consumers’ data being compromised. We learned there was an intrusion 19th April and subsequently shut the services down. We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident. It was necessary to conduct several days of forensic analysis, and it took our experts until yesterday to understand the scope of the breach. We then shared that information with our consumers and announced it publicly yesterday evening.”
Yesterday evening being April 26, exactly seven days since Sony learnt its security had been compromised. In this day and age where we’re accustomed to being alerted to privacy infringements straight away – I mean, how many emails have you had from e-tailers apologising about a possible security breach recently? – it’s shocking that it should take Sony seven days to cough up and explain what happened.