North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated wiper malware that crippled the studio.
Reviewed by the Social Engineering Examples team.
In fall 2014, attackers working on behalf of North Korea breached Sony Pictures Entertainment, stole large volumes of confidential data (unreleased films, executive emails, salaries, ~47,000 Social Security numbers and other employee PII), and then deployed wiper malware that rendered thousands of Sony computers inoperable. On Nov 24, 2014, employees found workstations locked behind a red-skeleton image from the "Guardians of Peace," who leaked the stolen material over the following weeks and later threatened theaters showing the comedy "The Interview," which depicts the assassination of North Korea's leader. The FBI publicly attributed the attack to North Korea on Dec 19, 2014. In June 2018 (unsealed September 2018), the U.S. DOJ filed a criminal complaint charging North Korean programmer Park Jin Hyok, tying the Sony attack, the 2016 Bangladesh Bank heist, and 2017 WannaCry to the same conspiracy. The incident is real and extensively documented; North Korean state responsibility is the U.S. government's formal attribution, and Park's individual role remains an allegation/charge (he is at large).
The FBI affidavit describes the group scouting targets via internet/social-media reconnaissance, then sending highly tailored spear-phishing emails that copied legitimate service emails almost verbatim but swapped in malicious links. Security researcher Stuart McClure of Cylance, analyzing the leaked Sony inboxes, found the dominant lure was fake "Apple ID"/AppleCare "verify your account" emails: near-identical clones of real Apple notices claiming unauthorized activity and demanding verification within 48 hours. Recipients who clicked reached a convincing fake Apple verification page (e.g., a domain like ioscareteam.net) and entered their Apple ID and password. Targets were selected by cross-referencing LinkedIn for Sony staff with network privileges (system engineers, administrators). Because password reuse across personal and work accounts is common, harvested Apple credentials helped the attackers guess or obtain Sony network logins. Stolen usernames/passwords for high-access accounts were then hard-coded into the wiper malware; an administrator account for Sony's software-distribution tool (SCCM) plausibly let the attackers push the malware across the enterprise as if it were a legitimate update. A flat, poorly segmented network let the wiper (variously called Destover/WIPALL, a Shamoon-family variant) spread and overwrite master boot records and data.
Lure: an email that looks exactly like Apple/AppleCare warning of "unauthorized activity on your Apple account: verify your Apple ID within 48 hours or be locked out," linking to a polished fake verification page. Tells: the request arrives by email and drives you to a login page via a link rather than to Apple's own app/site; the destination domain is not apple.com (e.g., a look-alike like ioscareteam.net); artificial deadline and lockout threat; a personal-account (Apple) prompt landing in a work inbox; and the ask to re-enter credentials. Safer path: never verify via an emailed link. Open the vendor's app or type the official domain yourself, and never reuse work passwords on personal accounts.
Massive data theft and public leaks; destruction of much of Sony's IT infrastructure (systems rebuilt over months, staff reverted to paper and old phones); executive resignations and reputational damage; theatrical release of "The Interview" disrupted. U.S. government formally attributed the attack to North Korea (Dec 2014) and later charged Park Jin Hyok (2018); no arrest, and he remains a fugitive on the FBI's wanted list.
A landmark case showing that a single successful credential-phish against privileged staff can escalate to nation-state-level data theft and physically destructive sabotage of an entire enterprise. It highlights how password reuse, weak MFA, LinkedIn-driven target selection, brand-impersonation lures, and flat networks combine, and it became the first cyberattack the U.S. president formally attributed to a nation-state.
Phishing-resistant MFA on email, VPN, and admin accounts so stolen passwords alone don't grant access; eliminate work/personal password reuse (password managers, unique credentials); email authentication (SPF/DKIM/DMARC), link rewriting/time-of-click analysis, and attachment sandboxing at the gateway; verify account alerts only via the vendor's own app or a hand-typed official domain, never via emailed links; least-privilege and tight control/monitoring of software-distribution tools (e.g., SCCM); network segmentation and EDR to limit lateral movement and catch wiper behavior; ongoing security-awareness training with a no-blame reporting culture and phishing simulations.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power utilities,…