Inside the Hack of the Century

Source 
Author 
Coverage Type 

A cyber-invasion brought Sony Pictures to its knees and terrified corporate America. The story of what really happened -- and why Sony should have seen it coming. This is part one of a special three-part investigation:

On Monday, Nov. 3, 2014, a four-man team from Norse Corp, a small “threat-intelligence” firm based in Silicon Valley, arrived early for an 11:30 am meeting on the studio lot of Sony Pictures Entertainment, in the Los Angeles suburb of Culver City (CA). They were scheduled to see Sony’s top cybersecurity managers to pitch Norse’s services in defending the studio against hackers, who had been plaguing Sony for years.

Three weeks later -- starting at about 7 a.m. Pacific time on Monday, Nov. 24 -- a crushing cyberattack was launched on Sony Pictures. Employees logging on to its network were met with the sound of gunfire, scrolling threats, and the menacing image of a fiery skeleton looming over the tiny zombified heads of the studio’s top two executives. Before Sony’s IT staff could pull the plug, the hackers’ malware had leaped from machine to machine throughout the lot and across continents, wiping out half of Sony’s global network. It erased everything stored on 3,262 of the company’s 6,797 personal computers and 837 of its 1,555 servers. To make sure nothing could be recovered, the attackers had even added a little extra poison: a special deleting algorithm that overwrote the data seven different ways. When that was done, the code zapped each computer’s startup software, rendering the machines brain-dead.


Inside the Hack of the Century