The 2011 PlayStation Network (PSN) breach was a sophisticated criminal intrusion into Sony’s network. Attackers accessed servers and account-related personal information, concealed their activity and deleted log files. Sony’s public records describe what happened after the attackers got in, but do not identify the precise vulnerability, stolen credential or other route they used to gain initial access.
What happened in the 2011 PSN breach?
Sony said that PSN and Qriocity account information was compromised between April 17 and April 19, 2011, in an “illegal and unauthorized intrusion” into its network. Sony’s network team detected unusual activity and unexpected server reboots on April 19. The company took PSN services offline the next day while it investigated and worked to prevent further unauthorized activity.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Sony Playstation 3 160GB System (Renewed) | $184.24 | Buy on Amazon |
| 2 |
|
Sony PlayStation 3 Slim 320 GB Charcoal Black Console (Renewed) | $222.26 | Buy on Amazon |
| 3 |
|
PlayStation 3 Slim Console 120GB (Old Model) (Renewed) | $128.45 | Buy on Amazon |
| 4 |
|
PlayStation 3 500 GB Super Slim System (Renewed) | $211.11 | Buy on Amazon |
| 5 |
|
Sony PlayStation 3 - 80GB System (Renewed) | $217.22 | Buy on Amazon |
The incident affected account information associated with approximately 77 million PSN and Qriocity customers, according to Australia’s Office of the Australian Information Commissioner (OAIC) in 2011. That figure describes the scale of accounts associated with personal information at risk; it does not mean that every account’s data was necessarily accessed in the same way.
How did the attackers get into PSN?
The available public primary accounts establish that outsiders gained unauthorized access to Sony servers. They do not establish the initial foothold: they do not specify an exploited application vulnerability, a stolen password, a particular credential path or a named individual responsible. It would therefore be misleading to state a specific exploit as the confirmed way the PSN network was hacked.
#1 Best Overall
- Internet Ready With Built-in Wi-Fi with a Cell Broadband Engine Advanced Microprocessor
- When starting up the system for the first time, hold the power button until a "screen display" message shows up on screen. Select the desired output, and the system will startup normally.
- 160GB system
- Blu-ray player to give you pristine picture quality
- The best high-definition viewing experience available
What investigators found after entry
A U.S. Senate account of the forensic findings said the intruders used “very sophisticated and aggressive techniques” to access servers and hide from system administrators. Investigators also found that log files had been deleted. These details show concealment after access, but they do not reveal how the attackers first crossed the network’s defenses.
In a separate congressional response, Sony said a file named “Anonymous” containing the words “We are Legion” had been planted on a Sony Online Entertainment server. This is evidence of a planted file on that service; it does not, by itself, identify who conducted the PSN intrusion or prove the initial access method.
Rank #2
- New slimmer, lighter PS3 system, Wireless controller
- 320GB HDD for storing games, music, videos, and photos
- Streams thousands of movies and TV shows instantly from Netflix
- Built-in Blu-ray player with 3D capabilities. HDMI output for 1080p resolution.
What information was exposed—and were credit cards stolen?
Sony warned customers that the information it believed had been obtained included names, addresses, country, email addresses, birth dates, PSN login details and passwords, and online IDs. It also said purchase history, billing addresses and password security answers might have been accessed.
Sony said it had no evidence at the time that credit-card data had been taken, but could not rule out access to card numbers and expiration dates. The security code was not included in Sony’s warning about potentially exposed card data. The careful distinction is that card-data access was possible, not confirmed by the public notice.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- HDMI + Bravia Sync functionality that provides both 1080p output resolution.
- A new 33% slimmer, 36% lighter PlayStation 3 entertainment system that is also more energy efficient.
- Includes a Dualshock 3 wireless controller and a built-in 120GB HDD for storing games, music, videos, and photos.
- Built-in Wi-Fi for connectivity anywhere and multiple media format compatibility.
- Free membership and access to all the events, as well as game, movie, TV and other media content available on the PlayStation Network (PSN).
How the breach was detected and disclosed
| Date | What happened |
|---|---|
| April 17–19, 2011 | Sony placed the compromise of PSN and Qriocity account information within this period. |
| April 19 | Sony’s network team found unexpected server reboots and unusual activity. Sony’s European operation also became aware of the cyberattack. |
| April 20 | Sony shut down PSN services and began a larger investigation. |
| April 21–23 | Additional forensic firms imaged servers. Investigators later reported sophisticated access techniques, concealment and deleted log files. |
| April 25 | Forensic teams confirmed the likely scope of personal information accessed, but could not rule out access to credit-card data. |
| April 26 | Sony publicly notified customers about compromised personal information and the possibility that card numbers and expiration dates had been accessed. |
| May 1–2 | Sony Online Entertainment discovered that data might also have been taken and shut down its service. |
The interval between Sony becoming aware of the attack and its April 26 public warning later drew regulatory attention in Australia. The OAIC said reasonable security steps appeared to have been taken and closed its investigation, while recommending that Sony review the time taken to notify customers.
What Sony did after the intrusion
Sony temporarily disabled services, brought in outside security firms, investigated and rebuilt network infrastructure. Its congressional response described measures that included stronger encryption, intrusion detection, monitoring for unusual activity, firewalls, a new data center and the appointment of a chief information security officer. Sony also offered identity-theft protection and a Welcome Back package to customers.
Rank #4
- Your Favorite Franchises Live Here: Dig into a huge catalog of exclusive games, including generation defining titles like The Last of Us and entries in popular franchises like LittleBigPlanet, God of War, Gran Turismo, and UNCHARTED.
- High-Definition Blu-ray player for the best movie experience. Plays DVDs and CDs
- 500GB HDD for storing games, music, videos, and photos
- Internet ready with built-in Wi-Fi
- Blu-ray player
The response had two distinct sides: containment and security improvements, and the timing of customer notification. The OAIC’s assessment addressed both, accepting that reasonable security measures appeared to have been taken while recommending a review of notification delays.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the public record does—and does not—show
- Established: Sony reported an unauthorized intrusion between April 17 and 19, 2011, involving PSN and Qriocity account information.
- Established: Investigators found signs of concealment, including deleted log files; Sony also reported unusual activity and server reboots.
- Established: Sony warned that personal account information had been compromised and that card-number and expiration-date access could not be ruled out.
- Not established in the cited public accounts: the exact initial exploit or credential path, a specific unpatched application, or the identity of the person or group that first gained access.
In short, PSN was penetrated by an external attacker who hid activity after gaining access. The public primary record documents the breach’s effects and investigation, but does not disclose a confirmed technical entry route.
Recommended Free Tools
Quick Recap
Best Value
- Built-in Wi-Fi access for easy connection to gaming services and the Internet
- Built-in Blu-ray player to give you the best high-definition viewing experience and pristine picture quality
- 80 GB of hard disk storage for all your games, music, videos, and photos
- This product is NOT backwards compatible
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

