← Case Files · The Breach Files

2011 · Gaming

PlayStation Network, 2011: 77 million accounts and 23 days offline

Case file · 4 min read · Published 14 September 2026

People affected
77 million PSN accounts, plus 24.6 million Sony Online Entertainment accounts
When it happened
17 – 19 April 2011
Made public
26 April 2011
How they got in
Intrusion into application servers running outdated, unpatched software behind an inadequately protected network boundary
Attributed to
Never definitively attributed; several groups were speculated about at the time and none established
What it cost
Sony estimated around $171 million; the UK ICO fined it £250,000 in 2013

What was exposed: Names · Addresses · Email addresses · Dates of birth · PSN login credentials · Purchase history · Some card details on file

For 23 days in the spring of 2011, nobody could play online on a PlayStation 3. It remains the longest outage a major consumer online service has taken voluntarily, and Sony took it because the alternative was bringing back a network it no longer trusted.

What happened

Between 17 and 19 April 2011, attackers reached application servers behind Sony's PlayStation Network infrastructure. Sony detected unusual activity on 19 April and took the service offline on 20 April.

The regulator's later account is the clearest public description of the conditions. Servers were running software that was out of date and for which patches had been available. The network was not adequately protected at its boundary. Password protection did not meet the standard expected of a company with Sony's resources. In the ICO's assessment the attack could have been prevented.

On 26 April, a week after taking the network down, Sony disclosed that account information for approximately 77 million accounts had been taken: names, addresses, email addresses, dates of birth, login credentials, and purchase history. Days later it disclosed a separate intrusion affecting 24.6 million Sony Online Entertainment accounts.

The week of silence is what the case is remembered for. Sony took the network down on 20 April and told users only that the service was unavailable. The confirmation that personal data had been taken came on 26 April. In that gap, 77 million people had a compromised password and no reason to change it anywhere else. Breach notification law in most of the world now sets a hard clock — 72 hours under GDPR — precisely because a company's instinct in that first week is to say nothing until the picture is complete, and the picture is never complete in the window when the warning would help.

Rebuilding rather than restoring

Sony's technical response was more decisive than its communications. Rather than patching the compromised environment and bringing it back, the company moved the service to a different data centre, rebuilt the architecture, added new monitoring and a new firewall design, and appointed its first chief information security officer.

This is the right call and it is rarely made, because it is enormously expensive and every day of the rebuild is a day of lost revenue and public anger. The judgement underneath it is simple: after an intrusion of unknown depth, you cannot prove the attacker is gone from an environment you did not rebuild. Most organisations decide they can live with that uncertainty. Sony decided it could not.

The return was staged through mid-May, with a mandatory password reset and a firmware update required before any console could reconnect.

The timeline

  1. 17 – 19 April 2011 — Intrusion into PlayStation Network infrastructure.
  2. 20 April 2011 — Sony takes the entire network offline, citing an unspecified issue.
  3. 26 April 2011 — Sony discloses that personal data for approximately 77 million accounts was taken.
  4. 1 May 2011 — A press conference in Tokyo; executives bow in apology and announce the Welcome Back programme.
  5. 2 May 2011 — A separate breach of 24.6 million Sony Online Entertainment accounts is disclosed.
  6. 4 May 2011 — Sony responds in writing to questions from a US congressional subcommittee.
  7. 14 May 2011 — Phased restoration of PlayStation Network begins.
  8. January 2013 — The UK ICO fines Sony £250,000; Sony appeals and later withdraws the appeal.
  9. 2014 — A US class action settles for up to $15 million in games, credits and subscription time.

What it changed

It made breach notification timing a political issue. The congressional questions to Sony were substantially about the six-day gap, and that argument fed directly into the drafting of notification requirements over the following decade. The 72-hour rule in GDPR is the direct descendant of incidents like this one.

Gaming accounts stopped being treated as trivial. A PSN account held a real name, a date of birth, a home address and a card on file. The industry had secured them like game saves. After 2011, two-factor authentication, purchase confirmation and account recovery hardening arrived across every major gaming platform.

Sony created a security function that reported upwards. The appointment of a chief information security officer in the aftermath reflected a structural point the incident had exposed: security had been distributed among divisions with nobody accountable across them. Sony Pictures would be attacked three years later, which is a reminder that structure alone does not settle the question.

"Not stored in plain text" became a phrase people learned to interrogate. It sounds like a reassurance and commits to nothing. Users, journalists and regulators started asking which algorithm, with what work factor, and whether the values were salted — questions that are now standard in any breach disclosure that mentions passwords.

If you had a PSN account then

  1. Any password from that era that you still use anywhere should be changed. Fifteen years is long enough for any hash of that vintage to have been worked through.
  2. Turn on two-factor authentication on gaming accounts. They hold payment methods, purchase libraries worth real money, and an identity that other players trust.
  3. Remove stored cards you do not need. A saved card is a convenience you use occasionally and a liability that is held permanently.
  4. Date of birth was in this file. It is still asked as an identity check by banks and telecoms companies today, which is a good argument for not treating it as secret.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Were PlayStation Network passwords encrypted?

Sony initially said only that they were not stored in plain text, which is a statement that can cover anything from robust protection to a reversible transformation. Days later it said the passwords had been hashed. The UK regulator's later finding was that password security was not up to standard for a company of Sony's resources. The gap between the first vague statement and the later detail is the part users remember.

Were credit cards stolen?

Sony said there was no evidence card data was taken, while acknowledging it could not rule it out, and noted that the card table was encrypted. Widespread card fraud attributable to the incident was never established. Given 77 million accounts, the absence of a documented fraud wave is reasonable evidence the card data held.

Why was PlayStation Network down for 23 days?

Because Sony did not simply patch and restart. It rebuilt the service on new infrastructure in a different data centre with a redesigned security architecture, having concluded that the existing environment could not be trusted. That is the right decision and it is also why the outage was measured in weeks. Recovering from a breach and restoring a service are different projects.

What did Sony give affected users?

A Welcome Back programme of free games and PlayStation Plus subscription time, plus identity theft protection in some regions. A US class action settled in 2014 for up to $15 million in games and credits. The UK ICO fine of £250,000 was appealed and the appeal later withdrawn.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →