
What happened
On 24 November 2014, employees at a major entertainment company found their computers displaying a threatening message, shortly before internal data, executive emails and unreleased films began appearing online. According to a technical alert issued by US-CERT, the intrusion used a toolkit built around a worm that spread through Windows file-sharing with stolen credentials, alongside a component that overwrote the first sections of affected hard drives and the master boot record, rendering machines unusable. The alert, addressed generally to a major entertainment company, does not name the victim or attribute the intrusion to any actor; it documents only the malware's mechanics.
On 2 January 2015, the US Treasury announced sanctions against North Korean entities and officials, stating the action responded to the recent cyber-attack targeting Sony Pictures Entertainment and the threats against movie theaters and moviegoers. Treasury's announcement attributes the attack to the government of North Korea and describes it as an effort to intimidate US businesses and suppress free expression, while noting that the FBI's investigation was continuing.
Confidence and limits
The two sources describe different halves of the same episode: one is a purely technical account of the malware with no attribution, the other a formal government attribution and sanctions response with no technical detail. Read together they support that a destructive attack occurred against a major entertainment company in late 2014 and that the US government held North Korea's government responsible. Neither document states a financial cost, a full list of what was stolen, or the specific evidence linking the malware to North Korean state actors.
Why it mattered
The attack combined three elements rarely seen together before: theft of internal data, deliberate public leaking of it to cause reputational harm, and destructive wiping of affected systems. Earlier destructive incidents against critical infrastructure had shown wiper malware could disable operational systems; this attack showed the same destructive intent could target a media company's network as coercion tied to specific content. It became a reference case for boards and insurers weighing how much a single intrusion, without any encryption or ransom demand, could cost in leaked communications and rebuilt infrastructure.
Defensive takeaway
Treat destructive malware and data-leak extortion as related but separate risks in your incident-response planning, since a response built only around restoring encrypted files will not address an attacker whose goal is publication rather than payment.
- Does your incident-response plan address an attacker who wants to publish stolen data rather than sell it back to you?
- Could an attacker with domain credentials push a destructive payload to every workstation on your network before you noticed the intrusion?
- Who in your organisation is authorised to decide how to respond if internal communications are threatened with public release?
The technical alert and the sanctions announcement were issued by different parts of the US government for different audiences, and neither was written to give a complete account of the intrusion; together they establish only that a destructive, credential-based attack occurred and that Washington held North Korea responsible, not the fuller narrative that later reporting and legal proceedings have added since.
Treat destructive malware and data-leak extortion as related but separate risks in your incident-response planning, since a response built only around restoring encrypted files will not address an attacker whose goal is publication rather than payment.
A technical alert describes the malware without attribution, and a separate Treasury sanctions announcement attributes the attack to North Korea's government without technical detail; together they support both halves of the record, but neither states a financial cost or full data inventory, and this article does not rely on any later criminal proceedings.
Sources & reading trail
Technical description of the SMB worm and disk-wiping components used against a major entertainment company, without attribution.
government-primary · Source published: 19 December 2014 · Retrieved: 16 September 2026
US government's formal attribution of the Sony Pictures attack to North Korea's government and its stated rationale for sanctions.
government-primary · Source published: 2 January 2015 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.