J'ai reçu ça...
Citation
de PlayStation Network <PlayStation_Network@playstation-email.com>
répondre à 1649209-0875190662z@playstation-email.com
à XXXXXXXXXXXXXXXX.com
date 27 avril 2011 23:48
objet Important information regarding PlayStation Network and Qriocity services
envoyé par b1a.innovyx.net
signé par innovyx.net
Se désabonner Se désabonner de cet expéditeur
masquer les détails 23:48 (Il y a 9 heures)
Add PlayStation_Network@playstation-email.com to your address book
===================================
PlayStation®Network
===================================
Valued PlayStation Network/Qriocity Customer:
We have discovered that between April 17 and April 19, 2011,
certain PlayStation Network and Qriocity service user account
information was compromised. As a result of what we have found
to date, we have:
1) Temporarily turned off PlayStation Network and Qriocity services;
2) Engaged an outside, recognized security firm to conduct a full and
complete investigation into what happened; and
3) Quickly taken steps to enhance security and strengthen our network
infrastructure by rebuilding our system to provide you with greater
protection of your personal information.
We greatly appreciate your patience, understanding and goodwill as
we do whatever it takes to resolve these issues as quickly and efficiently
as practicable.
Although we are still investigating the details of this incident, we
believe that an unauthorized person has obtained the following information
that you provided: name, address (city, state, zip), country, email address,
birthdate, PlayStation Network/Qriocity password and login, and handle/PSN
online ID. It is also possible that your profile data, including purchase
history and billing address (city, state, zip), and your PlayStation
Network/Qriocity password security answers may have been obtained.
If you have authorized a sub-account for your dependent, the same
data with respect to your dependent may have been obtained.
While there is no evidence at this time that credit card data was
taken, we cannot rule out the possibility. If you have provided your
credit card data through PlayStation Network or Qriocity, out of an
abundance of caution we are advising you that your credit card number
(excluding security code) and expiration date may have been obtained.
For your security, we encourage you to be especially aware of email,
telephone and postal mail scams that ask for personal or sensitive
information. Sony will not contact you in any way, including by email,
asking for your credit card number, social security number or other
personally identifiable information. If you are asked for this information,
you can be confident Sony is not the entity asking. When the PlayStation Network
and Qriocity services are fully restored, we strongly recommend that you
log on and change your password. Additionally, if you use your PlayStation
Network or Qriocity user name or password for other unrelated services or
accounts, we strongly recommend that you change them, as well.
Under Massachusetts law, you have the right to obtain any police report
filed in regard to this incident. If you are the victim of identity theft,
you also have the right to file a police report and obtain a copy of it.
Massachusetts law also allows consumers to place a security freeze on their
credit reports. A security freeze prohibits a credit reporting agency from
releasing any information from a consumer's credit report without written
authorization. However, please be aware that placing a security freeze on
your credit report may delay, interfere with, or prevent the timely approval
of any requests you make for new loans, credit mortgages, employment, housing
or other services.
If you have been a victim of identity theft, and you provide the credit
reporting agency with a valid police report, it cannot charge you to place,
lift or remove a security freeze. In all other cases, a credit reporting
agency may charge you up to $5.00 each to place, temporarily lift, or
permanently remove a security freeze.
To place a security freeze on your credit report, you must send a written
request to each of the three major consumer reporting agencies:
Equifax (www.equifax.com); Experian (www.experian.com); and
TransUnion (www.transunion.com) by regular, certified or overnight
mail at the addresses below:
Equifax Security Freeze
P.O. Box 105788
Atlanta, GA 30348
Experian Security Freeze
P.O. Box 9554
Allen, TX 75013
Trans Union Security Freeze
Fraud Victim Assistance Department
P.O. Box 6790
Fullerton, CA 92834
In order to request a security freeze, you will need to provide the following information:
1. Your full name (including middle initial as well as Jr., Sr., II, III, etc.);
2. Social Security Number;
3. Date of birth;
4. If you have moved in the past five (5) years, provide the addresses
where you have lived over the prior five (5) years;
5. Proof of current address such as a current utility bill or telephone bill;
6. A legible photocopy of a government-issued identification card
(state driver's license or ID card, military identification, etc.)
7. If you are a victim of identity theft, include a copy of either the
police report, investigative report, or complaint to a law enforcement agency
concerning identity theft;
8. If you are not a victim of identity theft, include payment by check,
money order, or credit card (Visa, MasterCard, American Express or
Discover only). Do not send cash through the mail.
The credit reporting agencies have three (3) business days after receiving
your request to place a security freeze on your credit report. The credit
bureaus must also send written confirmation to you within five (5) business
days and provide you with a unique personal identification number (PIN)
or password, or both, that can be used by you to authorize the removal
or lifting of the security freeze.
To lift the security freeze in order to allow a specific entity or individual
access to your credit report, you must call or send a written request to the
credit reporting agencies by mail and include proper identification (name, address,
and social security number) and the PIN number or password provided to
you when you placed the security freeze as well as the identities of those
entities or individuals you would like to receive your credit report or the
specific period of time you want the credit report available. The
credit reporting agencies have three (3) business days after receiving
your request to lift the security freeze for those identified entities or
for the specified period of time.
To remove the security freeze, you must send a written request to each
of the three credit bureaus by mail and include proper identification
(name, address, and social security number) and the PIN number or
password provided to you when you placed the security freeze.
The credit bureaus have three (3) business days after receiving your
request to remove the security freeze.
We thank you for your patience as we complete our investigation of
this incident, and we regret any inconvenience. Our teams are working
around the clock on this, and services will be restored as soon as possible.
Sony takes information protection very seriously and will continue to work
to ensure that additional measures are taken to protect personally
identifiable information. Providing quality and secure entertainment
services to our customers is our utmost priority. Please contact us at
1-800-345-7669 should you have any additional questions.
Sincerely,
Sony Computer Entertainment and Sony Network Entertainment
Ils essayeraient pas de me baiser la gueule la?

Qui croire? perso mot de passe adresse tout ça m'en branle (souvent mis des trucs bidon), par contre le numero de carte bleue je préfere éviter
Citation
DECRYPTAGE - Un expert en sécurité informatique conseille de faire opposition, par mesure de précaution...
De notre correspondant à Los Angeles
Après six jours d'incertitude, Sony est passé aux aveux, mardi: oui, son Playstation Network (PSN) a bien été victime d'attaques de hackers, les 77 millions de comptes sont potentiellement concernés, des données personnelles ont été dérobées et le sort des informations bancaires est incertain. Quelles mesures devez-vous prendre si vous êtes concernés? 20minutes.fr fait le point.
Les contacts utiles
Le questions-réponses de Sony se trouve ici sur le blog officiel Playstation, le communiqué en anglais, là. Pour toute question, contactez la hotline de Sony France: 0820.31.32.33.
Quelles informations ont été dérobées?
Selon Sony: nom, adresse (ville, pays, code postal), adresse email, date de naissance, mot de passe et login PlayStation Network/Qriocity, identifiant de joueur en ligne, question secrète pour mot de passe perdu.
Et les cartes de crédit?
Sony précise: «Il est aussi possible que l’historique de vos achats, les quatre derniers chiffres de votre carte de crédit, sa date d’expiration et l’adresse de facturation» soient touchées. Puis, plus loin: «Il est possible que votre numéro de carte bancaire (excluant le code de sécurité) et sa date d'expiration soient concernés». Contacté par 20minutes.fr mercredi soir, Sony n'avait «aucune nouvelle information» à fournir. Sony précise que les utilisateurs du PSN vont progressivement recevoir des emails pour les tenir au courant de l'évolution de la situation.
Faut-il faire opposition?
Oui, selon un expert de la société de sécurité informatique Sophos. «Si un ami ayant emprunté ma carte bleue me disait qu'il l'a peut-être perdue, je la bloquerais. Si je perdais ma carte dans un taxi, je la bloquerais. Sans attendre de voir une éventuelle transaction frauduleuse apparaître», écrit Graham Cluley. Il rappelle que si les pirates ont bien mis la main sur des données bancaires, ils peuvent les utiliser plus tard, quand la vigilance sera retombée. Il précise qu'on ne sait pas si Sony respectait les normes internationales de sécurité et si les données étaient cryptées. Un utilisateur espagnol affirme que sa carte bleue a été débitée pour des transactions sur Netflix, alors que le service de vidéo à la demande n'est pas disponible en Espagne. Nous n'avons pas pu confirmer l'information dans l'immédiat. Sony France, non plus.
Quelles autres précautions faut-il prendre?
Changer vos login/mot de passe si vous utilisez les mêmes sur d'autres services (lire nos conseils pour choisir un bon mot de passe). Surtout: attention au phishing. Il est fort probable que d'autres hackers saisiront cette opportunité pour envoyer des mails se faisant passer pour Sony et demandant à l'utilisateur de rentrer ses coordonnées bancaires.
Qui se trouve derrière l'attaque?
Dans un premier temps, les doigts accusateurs étaient pointés vers le groupe Anonymous, qui s'en était pris à Visa et Mastercard pour défendre WikiLeaks l'hiver dernier. Le collectif avait récemment annoncé qu'il allait viser Sony, pour protester contre la politique générale du groupe (sur ses relations avec les développeurs, les hackers et l'émulation, entre autre). Mais le groupe a répondu: «Pour une fois, ce n'est pas nous.»
Quelles conséquences pour Sony?
Les retombées sont difficiles à mesurer. Pourquoi avoir attendu six jours pour communiquer? Contacté par 20minutes.fr, Sony France explique en substance qu'il ne voulait pas crier au loup avant de savoir exactement ce qu'il se passait. Sony précise avoir fait appel à une «entreprise de sécurité informatique de renom» pour enquêter, et que cela a «pris du temps». Malgré tout, le sénateur américain Richard Blumenthal n'est pas satisfait et a déjà écrit à Sony pour faire part de son «trouble». Aux Etats-Unis, selon le degré des dégâts, il ne serait pas surprenant de voir des class-actions (plaintes en recours collectif) lancées contre le groupe japonais. Sony «évaluera les actions à mettre en place lorsque le service sera restauré», a priori d'ici une semaine. Un dédommagement pour les clients et les développeurs sera un strict minimum.