Sony switched the PlayStation Network and Qriocity off on the evening of Wednesday 20 April 2011, it said afterwards, in order to conduct a thorough investigation and to verify the smooth and secure operation of network services going forward. For two days no cause was given. On 22 April Patrick Seybold, the senior director of corporate communications and social media, posted the sentence that changed the story: "An external intrusion on our system has affected our PlayStation Network and Qriocity services." Four dates matter in what followed and they are not interchangeable. The intrusion ran between 17 and 19 April. The shutdown came on the 20th. Sony's forensic teams confirmed the scope on the 25th. The account holders were told on the 26th.

That notice was specific about what had gone and careful about what might have. Sony said an unauthorised person had obtained "name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID", that profile data including purchase history and the password security answers might also have been taken, and that "while there is no evidence at this time that credit card data was taken, we cannot rule out the possibility." A post the next day drew the line the industry would quote for years afterwards. "The entire credit card table was encrypted and we have no evidence that credit card data was taken," it read. "The personal data table, which is a separate data set, was not encrypted." Notification went to all 77 million registered accounts.

On Sunday 1 May, at Sony's Tokyo headquarters, Kazuo Hirai, who ran the PlayStation business, bowed for several seconds alongside two senior vice presidents. "We deeply apologize for the inconvenience we have caused," Hirai said. He put the cards believed to be involved at about 10 million, and said Sony did not know whether they had been taken. Attribution stayed a claim. A statement posted on AnonNews on 22 April, headed "For Once We Didn't Do It", allowed that other Anons might have acted by themselves but said AnonOps was not related to the incident and took no responsibility for it. Sony's written answers to the United States House of Representatives, dated 3 May and released at the subcommittee's hearing on 4 May in place of an appearance it had declined, said intruders had left a file named "Anonymous" on a Sony Online Entertainment server bearing the words "We are Legion".

Service came back region by region from 14 May, North America first, and stopped short of Japan. The Ministry of Economy, Trade and Industry was not satisfied; its director of media and content, Kazushige Nobutani, who had met Sony representatives on 6 and 13 May, said the company was as of 13 May incomplete in carrying out the measures announced on 1 May and that two areas needed further explanation, while adding that the government was not itself preventing a restart. A phased restoration in Japan began on 28 May, and Sony did not call services there fully restored until 6 July. On 23 May Sony put the costs it then knew of at approximately 14 billion yen, about $171 million — an estimate of incident costs for the fiscal year, not a measure of lost revenue. A second intrusion, at Sony Online Entertainment, belongs to May 2011.

Also that month · 1–4 April

The outsourced address book

Epsilon, an email marketing unit of Alliance Data Systems in Texas, said it had detected an unauthorised entry into its email system on 30 March 2011, exposing a subset of its clients' customer data. Its statement of 1 April said the information obtained "was limited to email addresses and/or customer names only" — its own characterisation, not an independent finding — and an update on 4 April put the affected clients at about 2 per cent of its roughly 2,500 email clients. The lists were the point. Notices went out from JPMorgan Chase, Citibank, Capital One, Walgreens, Best Buy and Marriott, each telling customers that a company they had never heard of held their address. Brian Krebs set out the consequence on 4 April: a name paired with a bank made phishing cheap. Epsilon, like Sony, declined to testify before the House subcommittee on 4 May. An indictment unsealed in Atlanta on 6 March 2015 charged two Vietnamese citizens and a Canadian over the theft of more than a billion email addresses from Epsilon and other providers; one of them, Giang Hoang Vu, was extradited from the Netherlands and pleaded guilty.

Also that month · 13 and 21 April

Root, and then a routing change

On 13 April 2011 Matt Mullenweg told WordPress.com's users that Automattic "had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed." He added: "we presume our source code was exposed and copied", including sensitive parts of Automattic's code. Beyond that, he said, the disclosure appeared limited and there was no evidence of passwords being taken. The advice to users was thin because the exposure was structural: one intrusion reached across a platform hosting millions of sites. Eight days later the same lesson arrived without an attacker. At 12.47 in the morning Pacific time on 21 April a network change made during routine scaling in one availability zone of Amazon's US East region pushed traffic onto a lower-capacity network, isolating a block of Elastic Block Store nodes and setting off a re-mirroring storm; about 13 per cent of volumes in the zone were left hunting for capacity, and a long list of sites went down. By Amazon's own account all but 1.04 per cent of the affected volumes had been recovered by half past twelve in the afternoon on 24 April, and 0.07 per cent of the volumes in the zone could not be returned to customers in a consistent state at all. Nothing had been breached. The concentration was the same.

India desk · April 2011

Thirty-six hours, no judge

Four sets of rules under the Information Technology Act were notified together on 11 April 2011, and one of them rearranged who decides what stays online. The Information Technology (Intermediaries Guidelines) Rules, 2011, published as G.S.R. 314(E) in the Gazette of India, were made under section 87(2)(zg) read with section 79(2) — the safe harbour for what users do. The shield now carried conditions. Rule 3 required the intermediary to publish its rules, privacy policy and user agreement, and through them to tell users not to host anything "grossly harmful, harassing, blasphemous, defamatory, obscene, pornographic, paedophilic, libellous", anything disparaging, or anything that "threatens the unity, integrity, defence, security or sovereignty of India". On obtaining knowledge of such material it "shall act within thirty six hours", and preserve the records for at least ninety days.

No judge appeared anywhere in that sequence. That was the objection. The Centre for Internet and Society and the Software Freedom Law Centre called the rules unconstitutional: a private company had been made the first and usually the only judge of a stranger's speech, on a clock, with no hearing for whoever had posted it. Sunil Abraham of CIS told the Washington Post that July that "in comparison with other democracies in North America and Europe, the Indian rules appear to be on the China end of the spectrum"; Sachin Pilot, the minister of state, said the government was balancing freedom of speech against codes of conduct. The rest is elsewhere in this archive: the Delhi proceedings (January 2012), the motion to annul the rules in the Rajya Sabha (May 2012), the reading-down by the Supreme Court (March 2015).

AI Tech desk · April 2011

Microsoft opens the Kinect to Windows

Microsoft showed the Kinect for Windows software development kit at MIX11 in Las Vegas on 13 April 2011. The promise was older — in February Craig Mundie and Don Mattrick had said a non-commercial SDK would come that spring — and hobbyists had been reading the sensor's depth data through unofficial drivers since the previous November. MIX11 supplied the detail: skeletal tracking of one or two people, a four-element microphone array, a colour stream beside the depth stream, and the WorldWide Telescope steered by gesture on stage. The beta shipped in June, and the cheap depth camera became standard equipment in robotics laboratories for most of the decade. On 4 April Heritage Provider Network had opened its $3 million Heritage Health Prize on Kaggle, a two-year contest to predict from claims data who would be admitted to hospital the following year; no entry reached the accuracy threshold, and the leading team took $500,000 in 2013. On 27 April Chrome 11 shipped speech input through HTML: a microphone in a text field, with Google's servers transcribing.

Digital Guard desk · April 2011

The FBI tells a botnet to stop

On 13 April 2011 the Justice Department and the FBI said they had taken control of Coreflood, a credential-stealing botnet the government put at about 2.3 million computers. Two days earlier, on a civil complaint against 13 unnamed defendants, the federal court in Connecticut had granted a temporary restraining order: five command servers and 29 domain names were seized, and infected machines routed to a substitute server run by the Internet Systems Consortium, which answered each check-in with a command to stop the malware running. No American authority had done that before, and the Electronic Frontier Foundation told Wired it was "an extremely sketchy action to take". American check-ins fell from nearly 800,000 to under 100,000 in a week. Judge Vanessa Bryant made the order a preliminary injunction, also allowing removal where identified owners consented in writing; two dozen did, about 19,000 uninstall commands went out without reported harm, and on 14 June the FBI told the court the substitute server was no longer needed. Microsoft added Coreflood to April's Malicious Software Removal Tool at the government's request.

⏳ Time capsule — April 2011

  • On 2 April India beat Sri Lanka by six wickets at the Wankhede Stadium in Mumbai to win the Cricket World Cup, chasing 275 in 48.2 overs with 97 from Gautam Gambhir and 91 not out from the captain, M. S. Dhoni; it was the first time a host country had won the final.
  • On 17 April HBO broadcast the first episode of Game of Thrones, watched by 2.2 million people on its first airing, 4.2 million across that night's repeat and 6.8 million by the end of the following week; the season ran ten episodes.
  • Between 25 and 28 April the largest tornado outbreak on record crossed the southern United States, with 348 deaths, 324 of them caused by tornadoes, and 224 tornadoes confirmed on 27 April alone.
  • On 29 April Prince William and Catherine Middleton married at Westminster Abbey; the peak British television audience was put at 26.3 million, and YouTube counted 72 million live streams across 188 countries.
Where it stands today — 2026

The month disclosure got a clock

The regulatory ending arrived twenty-one months later. On 24 January 2013 Britain's Information Commissioner's Office issued a monetary penalty notice of £250,000 against Sony Computer Entertainment Europe, finding that it had not kept up with technical developments and had lacked measures such as cryptographic controls to protect passwords; the deputy commissioner, David Smith, called it one of the most serious cases reported to his office. Sony said it strongly disagreed, that it had been the victim of a focused and determined criminal attack, and appealed; in July 2013 it dropped the appeal rather than argue network detail in public, and paid. The American class actions settled with about $15 million in games and online currency plus identity-theft reimbursement. This archive has found no public attribution of the PlayStation Network intrusion and no charge brought over it.

What changed was the clock. In April 2011 how fast to tell 77 million people was a judgement a company made for itself, and Sony's six days drew letters from legislators on two continents without breaching any fixed statutory deadline. Notification now has a number attached to it: seventy-two hours to a supervisory authority under the European regulation that took effect in May 2018, six hours to CERT-In under India's 2022 direction, and a duty to inform affected people under the DPDP Act of 2023. The other lesson was the smaller one, and Sony had published it itself: the card table was encrypted and the table with the names in it was not. Sony's networks were broken into again in November 2014.