All cases

Sony Pictures Entertainment Hack

November – December 2014

DestructivePeak: DestructionAttribution: High ConfidenceMedia
Year
2014
Actor country
North Korea
Target regions
United States
Unpeace score
10

Executive Summary

Destructive intrusion into Sony Pictures Entertainment that exfiltrated confidential data and deployed wiper malware, rendering thousands of workstations inoperable. Accompanied by coercive threats linked to the film 'The Interview,' prompting an unprecedented US public attribution to a state actor.

Why This Matters

Sony Pictures showed that a state can weaponize cyber operations to coerce a private company and suppress speech, raising urgent questions about where corporate cybersecurity meets national security.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2014-09
Intrusion

Network compromise

Attackers gained persistent access to Sony's corporate network and conducted extensive data exfiltration over several weeks.

2014-11-24
Destruction

Wiper deployment and data leak

Destover wiper malware destroyed data on workstations; stolen emails, unreleased films, and employee records published online.

2014-12
Disruption

Coercive threats

Threats of violence against theaters led Sony to temporarily cancel the theatrical release of 'The Interview.'

Threshold Crossings

  • State-sponsored destructive attack against a private company over expressive content
  • First US presidential public attribution of a cyber attack to a specific state

Restraint Factors

  • Targeted a single corporation, not government or critical infrastructure
  • No reported physical harm to individuals

Attribution Assessment

High ConfidenceLazarus Group, attributed by the US government to North Korea's RGB
North Korea
Lazarus GroupHIDDEN COBRAGuardians of Peace
1. Technical

Threat actor mapped to North Korea based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: Novetta: Operation Blockbuster Report

2. Political / Legal
Public AttributionIndictmentSanctions Imposed
  • FBI public attribution statement (Dec 2014)
  • Executive Order 13687 imposing sanctions on North Korean entities (Jan 2015)
  • US DOJ indictment of Park Jin Hyok (Sep 2018)

Sources: FBI: Update on Sony Investigation; US DOJ: North Korean Regime-Backed Programmer Charged

3. Open Source

No dedicated journalistic sources in dataset. See sources section for full references.

High Confidence” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

10

Unpeace Score

Composite severity rating on the peace–conflict spectrum

Stable
Contested
Escalatory
03060100

Contributing Dimensions

Escalation peak5/6
Threshold crossings2/4
Governance flags3/8
Sectors affected1/6
Entanglement3/10
Country scope1/6

Coercive Function

Destructive

Destruction of data or systems — coercive value through denial, punishment, or deterrence signaling.

Observed coercive effects

  • State-sponsored destructive attack against a private company over expressive content
  • First US presidential public attribution of a cyber attack to a specific state

Entanglement Risk

Entanglement score3

Sectors affected

Media

Countries / regions

United States

Impact summary

Massive data breach and destruction of IT infrastructure at a major studio; temporary suppression of a film release.

Infrastructure Meaning

Malware / tooling

DestoverWhiskeyAlfa

Capability profile

Massive data breach and destruction of IT infrastructure at a major studio; temporary suppression of a film release.

4 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • Freedom of expression and non-interference with media
  • Proportionality debate: cyber destruction as retaliation for a film

Policy responses

  • FBI public attribution statement (Dec 2014)
  • Executive Order 13687 imposing sanctions on North Korean entities (Jan 2015)
  • US DOJ indictment of Park Jin Hyok (Sep 2018)

Regulatory changes

  • Elevated private-sector cyber threat awareness for entertainment and media industries

Governance impact assessment

Established the precedent that the US would publicly name state sponsors of cyber attacks against private companies, signaling that corporate targets are within the scope of national security response.

Sources

G

FBI: Update on Sony Investigation

Government2014-12-19
L

US DOJ: North Korean Regime-Backed Programmer Charged

Legal2018-09-06
V

Novetta: Operation Blockbuster Report

Vendor Report2016-02

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.