If you use Sony’s PSN or SOE services there are a number of risks that you’re now exposed to.
Depending on the level of access gained by the hackers and the information they were able to glean you could be exposed to some or all of the following:
1. Credit Card Fraud
Issue: Some credit card details have been taken by the hackers. Sony claim this information was encrypted and that the details from the SOE attack date back to 2007.
Risk: Your current credit card details were included in those that were stolen and the hackers have been able to decrypt and use them or sell them on.
Precautions: Keep an eye on your credit card statements and notify your card issuer of any suspicious or unauthorised transactions. Alternatively, if you’re very worried you could cancel your cards and get new ones. It’s also possibly worth keeping an eye on your financial history and credit rating via someone like Experian to make sure you haven’t been the victim of further fraud.
2. Identity Theft
Issue: It appears that an awful lot of data was harvested in the attacks. Alongside the credit card details which may have been compromised, Sony have admitted that users names, addresses, dates of birth and other potentially useful ID information has been compromised.
Risk: The criminals behind this kind of attack are after exactly this type of information which they can use themselves or sell on to other professional ID thieves. You could become the victim of partial or full identity theft. This could put you at risk of significant financial loss, reputational damage and could cost you a considerable amount of money, merely to correct the damage.
Precautions: Fairly similar to credit card fraud – you need to keep an eye on all your credit, bank and any other financial transactions. In addition, it’s a good idea to check your history on a regular basis and possibly even take out ID theft insurance – but check with your provider that you’re covered retrospectively, otherwise you could be paying out for nothing.
3. Online Compromise
Issue: The hackers have gained valuable information on millions of users, including usernames and passwords. Many users use the same account and password credentials across many different online and offline services. This can range from using the same username with multiple online services such as Hotmail and Gmail to using the same password for Facebook and you online bank account.
Risk: If you reuse the same credentials across multiple platforms and one of them is compromised then they all are – it is only a matter of time before your other services are accessed. This can lead to a whole host of problems, from someone posting questionable “status updates” on Facebook or Twitter, to them attempting to access your online banking, or even manipulating your friends into giving out their personal details.
Precautions: Change your passwords! Don’t reuse the same passwords on multiple platforms, particularly social and financial systems. And don’t always trust that your friend is the only person using their social networking account – it may have been compromised.
4. Social Engineering
Issue: The sheer number of people who have had some or all of their Sony account details compromised makes it very attractive to criminals attempting different approaches. Some will use the simple ID theft and credit card fraud approaches. Others will attempt to gain access to other online resources. Yet another set may attempt to “socially engineer” the individuals concerned – which essentially means to “con” them into giving out other details by making them believe they are being contacted by a legitimate company (including Sony themselves!).
Risk: You might take a call or receive a letter, email or social media contact informing you that you’re the victim of Sony’s hack or some other related issue. If this happens you will be asked to prove you are the person concerned, and so you will be asked for other “security” details. All of this information can be used to further compromise you financially, steal your identity or access other online resources.
Precautions: Don’t take off the cuff calls or other contacts at face value. Be suspicious. Tell the caller that you will call them back, get their name and office details and then call the main switchboard number of the company they claim to be from. Do the same for emails and letters. Remember, no legitimate organisation will ask you for your full password or PIN number for an account.
Hopefully, nobody will ultimately fall victim to the criminals who masterminded the attack on Sony. Unfortunately that’s pretty unlikely. All anybody can do now is to defend themselves to the best of their ability and take precautions to limit the damage that can be inflicted upon them.
This kind of attack, where major corporates are targeted, is likely to occur more and more as service provider’s offer ever increasing online services to an ever growing online community.
What we need to do is attempt to defend ourselves and improve the security of the services provided online, designing them with security in mind from the start rather than implementing security as an afterthought.

