← Case Files · The Breach Files
Sony Pictures, 2014: the breach that destroyed the computers on the way out
- People affected
- about 47,000 individuals' details, plus the company's internal correspondence
- When it happened
- November 2014
- Made public
- 24 November 2014
- How they got in
- Not fully detailed publicly; the malware included a component that wiped drives
- Attributed to
- A group calling itself Guardians of Peace; attributed by the FBI to North Korea
- What it cost
- Destroyed infrastructure, an $8 million employee settlement, and the resignation of a studio co-chair
What was exposed: Employee names · Social Security numbers · Salaries · Medical and HR records · Internal emails · Unreleased films
On 24 November 2014, employees arriving at Sony Pictures Entertainment found a red skeleton on their screens and a message from the "Guardians of Peace". By the end of the day the studio was running on paper, whiteboards and personal phones. The attackers had not only taken the data — they had destroyed the machines it lived on.
What happened
The malware used included a wiper component that overwrote hard drives and boot records, rendering thousands of computers and servers unusable. Restoring from backup is one thing; rebuilding an entire corporate IT estate from bare metal while the business continues is another. Sony ran significant parts of its operations manually for weeks.
Meanwhile the attackers began publishing. Not all at once, but in batches over weeks, each timed for maximum coverage:
- Unreleased films, distributed on file-sharing networks before their cinema dates.
- Employee data — around 47,000 people, including Social Security numbers, salaries, performance reviews and some medical records, covering current and former staff and contractors.
- Executive email archives, which produced months of coverage about what film executives say about actors, each other and their own projects.
- Contracts, budgets and business plans, handing competitors a complete view of the studio's operations.
The stated demand concerned The Interview, a comedy about the assassination of North Korea's leader. Threats were made against cinemas showing it; major chains withdrew; Sony cancelled the theatrical release and then, after substantial criticism, released the film online and through independent cinemas.
The people who paid for it. The email leaks got the attention, and the employees got the damage. Current and former staff had their salaries, medical claims and identity documents published permanently, with no involvement in any decision about any film. A class action was settled for around $8 million. It is a pattern worth noticing across this archive: the coverage follows the embarrassment, and the harm follows the ordinary people in the file.
Attribution, and why it mattered
In December 2014 the FBI publicly attributed the attack to North Korea, citing technical similarities to previously observed tooling and infrastructure. Several independent researchers were sceptical, arguing the published evidence was thin — a reasonable objection given how little was disclosed.
In 2018 the Department of Justice charged Park Jin Hyok, a North Korean national it linked to the group later widely known as Lazarus, connecting the Sony operation to the WannaCry ransomware outbreak and to intrusions at banks. The complaint laid out considerably more detail than the 2014 statement.
The significance was procedural as much as factual: it was the first time the United States formally and publicly blamed a nation for a destructive attack on a private company, and it established that a commercial breach could be treated as a foreign policy matter, with sanctions attached.
What it changed
Destructive attacks entered corporate threat models. Before Sony, the working assumption was that attackers wanted data and needed systems to keep running. Wiper malware inverted that. Recovery planning shifted towards assuming the infrastructure itself might be gone — offline backups, rebuild procedures, and out-of-band communications for a company whose email no longer exists.
Executives learned that email is a permanent record. The cultural legacy is at least as durable as the technical one. The candour of internal correspondence in 2014 has not survived the knowledge that it might be read aloud in public.
Employee data got recognised as a breach category. HR systems hold everything a customer database holds, plus salaries and medical information, and they had received a fraction of the attention. That changed.
If your employer is breached
- Your employer holds more about you than most companies you buy from. Identity documents, bank details for payroll, medical claims, next of kin. Ask what happens to it when you leave — retention of former employee records is where much of the Sony exposure sat.
- Do not assume internal messages are private. Not because anyone is reading them today, but because a breach makes archives public in bulk, unedited, years later.
- If you are notified, take the identity protection and freeze your credit. Salary and Social Security data together is a complete fraud kit.
- For anyone planning recovery: practise the scenario where the systems are gone, not merely encrypted. It is the harder exercise and the one Sony had to improvise.
Questions people ask
What made the Sony Pictures hack different?
Three things happened at once: data was stolen, systems were destroyed by wiper malware, and the stolen material was published in stages as a pressure campaign. Most breaches do one of those. This one combined theft, sabotage and publication in service of a demand about a film's release.
Was it really North Korea?
The FBI publicly attributed the attack to North Korea in December 2014, and in 2018 the US Department of Justice charged Park Jin Hyok, a North Korean national, in connection with it and other operations. Some independent researchers questioned the attribution at the time, largely because the public evidence was limited. The indictment set out considerably more.
What was in the leaked emails?
Internal correspondence among executives, producers and agents — candid, unflattering, and quoted for months. Employee data mattered more and got less attention: around 47,000 people had Social Security numbers, salaries and in some cases medical information published, including former employees with no remaining connection to the company.
Did the film get released?
Yes. Major cinema chains initially declined to show The Interview after threats were made against venues, and Sony cancelled the theatrical release, drawing criticism including from the US president. It was then released online and in independent cinemas in December 2014.
Sources
- Federal Bureau of Investigation — update on Sony Investigation, December 2014
- US Department of Justice — criminal complaint against Park Jin Hyok, September 2018
- In re Sony Pictures Entertainment Data Breach Litigation — settlement, 2015
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.