Why It Took Sony 7 Days To Alert PSN Users To The Security Breach

Why It Took Sony 7 Days To Alert PSN Users To The Security Breach

Personal details, and maybe even credit card details as well, have been stolen from the PlayStation Network after hackers broke into the system sometime before April 19. But why did it take Sony so long to tell its customers – me! You! Your neighbour! – that they were hacked?

Sony took to its blog to explain just why:

“There’s a difference in timing between when we identified there was an intrusion and when we learned of consumers’ data being compromised. We learned there was an intrusion 19th April and subsequently shut the services down. We then brought in outside experts to help us learn how the intrusion occurred and to conduct an investigation to determine the nature and scope of the incident. It was necessary to conduct several days of forensic analysis, and it took our experts until yesterday to understand the scope of the breach. We then shared that information with our consumers and announced it publicly yesterday evening.”

Yesterday evening being April 26, exactly seven days since Sony learnt its security had been compromised. In this day and age where we’re accustomed to being alerted to privacy infringements straight away – I mean, how many emails have you had from e-tailers apologising about a possible security breach recently? – it’s shocking that it should take Sony seven days to cough up and explain what happened.

Oh, sorry – perhaps Sony’s CSI agents were too busy doing their “forensic analysis”. [PlayStation Blog via Kotaku]