Hackers in “underground” Internet forums have been talking about selling credit card information allegedly stolen during the recent PlayStation Network security attack. Forum chatter is easy to dismiss, but several security experts believe that there might be something there. Here’s a clip from The NY Times:
Kevin Stevens, senior threat researcher at the security firm Trend Micro, said he had seen talk of the database on several hacker forums, including indications that the Sony hackers were hoping to sell the credit card list for upwards of $100,000. Mr. Stevens said one forum member told him the hackers had even offered to sell the data back to Sony but did not receive a response from the company.
“Sony is saying the credit cards were encrypted, but we are hearing that the hackers made it into the main database, which would have given them access to everything, including credit card numbers,” said Mathew Solnik, a security consultant with iSEC Partners who frequents hacker forums to track new hacks and vulnerabilities that could affect his clients. Mr. Solnik said that people on the forums had details about the servers used by Sony, which may indicate that they had direct knowledge of the attack.
I’m not sure about this one. A lot of it seems like fear mongering. I also expect more from The NY Times. Using anonymous forum chatter as a news source is like writing a videogame story based on a NeoGAF thread. Oh wait, that actually happens.
Anyway, what do you guys and dolls make of this? Is it fear mongering? Or are millions of PlayStation Network users at risk?