Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

North Korea Behind Sony Hack: FBI

Hackers Threaten Sony over N. Korea Film

Hackers Threaten Sony over N. Korea Film

North Korea was responsible for a “destructive” cyber attack on Sony Pictures, the US Federal Bureau of Investigation said Friday, warning it would hunt down the perpetrators and make them pay.

The November attack prompted the movie giant to cancel the Christmas Day release of “The Interview,” a madcap satire about a fictional CIA plot to kill North Korean leader Kim Jong-Un.

The anonymous hackers invoked the memory of September 11, 2001 in threatening attacks on cinemas screening the film, prompting major theater chains to say they would not screen it.

In addition to the threats, Sony has seen the release of a trove of embarrassing emails, scripts and other internal communications, including information about salaries and employee health records.

“The FBI now has enough information to conclude that the North Korean government is responsible for these actions,” the agency said in a statement.

“Such acts of intimidation fall outside the bounds of acceptable state behavior.”

The attack involves the use of malware and rendered thousands of Sony Pictures computers “inoperable,” forcing the company to take its entire network offline, the FBI said.

Advertisement. Scroll to continue reading.

“We are deeply concerned about the destructive nature of this attack on a private sector entity and the ordinary citizens who worked there,” the FBI said.

The accusation came shortly before President Barack Obama was due to hold his last press conference of the year at 1830 GMT — virtually ensuring that he would be asked to address it.

A Sony source had told AFP that the studio also believes Pyongyang was behind the attack.

“We don’t know, but it appears so,” said the source.

‘Costs and consequences’

Pyongyang has so far denied involvement in the brazen November 24 cyber attack, but nevertheless hailed it as a “righteous deed.”

The North’s top military body, the National Defense Commission, slammed Sony for “abetting a terrorist act while hurting the dignity of the supreme leadership,” according to the state-run KCNA news agency.

The FBI nevertheless warned the attack would not go unpunished.

It said it would “identify, pursue, and impose costs and consequences on individuals, groups, or nation states who use cyber means to threaten the United States or US interests.”

Senior Republican lawmaker John McCain — the incoming chairman of the Senate Armed Services Committee — on Friday called the cyber attack an “act of war.”

But the FBI statement appeared to indicate the US government was treating the incident as more of a criminal act.

“We follow the facts and evidence wherever they lead, to identify the fingers at the keyboards that threaten our people, our companies, and our national security,” said John Carlin, assistant US attorney general for national security.

“Identifying those responsible for these attacks is only the first step, and we will continue to do our part to protect and defend our nation from the asymmetric threats posed through cyberspace.”

Free speech advocates and foreign policy hawks slammed Sony’s decision to pull “The Interview” as cowardice in the face of a hidden enemy.

McCain said it set a “troubling precedent that will only empower and embolden bad actors to use cyber as an offensive weapon even more aggressively in the future.”

But Sony defended its decision, saying the safety of theater patrons was at risk.

“This was a terrorist act, and you don’t take that lightly,” the company source said. “This is much bigger than us … it’s a whole new world, now warfare is on the cyber level.”

Related: Why You Should Demand Proof Before Believing The U.S. Government On North Korea and Sony

Written By

AFP 2023

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cyberwarfare

Websites of German airports, administration bodies and banks were hit by DDoS attacks attributed to Russian hacker group Killnet

Cyberwarfare

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cyberwarfare

Iranian APT Moses Staff is leaking data stolen from Saudi Arabia government ministries under the recently created Abraham's Ax persona

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Nation-State

The North Korean APT tracked as TA444 is either moonlighting from its previous primary purpose, expanding its attack repertoire, or is being impersonated by...

Cyberwarfare

Russia-linked cyberespionage group APT29 has been observed using embassy-themed lures and the GraphicalNeutrino malware in recent attacks.