RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 24 November 2014 event · prepared 16 September 2026

The Sony Pictures attack paired data leaks with disk-wiping malware

A CISA alert and a Treasury sanctions notice together record the malware's mechanics and the US attribution to North Korea.

Visual for this record: The Sony Pictures attack paired data leaks with disk-wiping malware
Visual published by home.treasury.gov, shown for identification of the record. Credit: home.treasury.gov · source page ↗ Rights: owner-review-pending.

What happened

On 24 November 2014, employees at a major entertainment company found their computers displaying a threatening message, shortly before internal data, executive emails and unreleased films began appearing online. According to a technical alert issued by US-CERT, the intrusion used a toolkit built around a worm that spread through Windows file-sharing with stolen credentials, alongside a component that overwrote the first sections of affected hard drives and the master boot record, rendering machines unusable. The alert, addressed generally to a major entertainment company, does not name the victim or attribute the intrusion to any actor; it documents only the malware's mechanics.

On 2 January 2015, the US Treasury announced sanctions against North Korean entities and officials, stating the action responded to the recent cyber-attack targeting Sony Pictures Entertainment and the threats against movie theaters and moviegoers. Treasury's announcement attributes the attack to the government of North Korea and describes it as an effort to intimidate US businesses and suppress free expression, while noting that the FBI's investigation was continuing.

Confidence and limits

The two sources describe different halves of the same episode: one is a purely technical account of the malware with no attribution, the other a formal government attribution and sanctions response with no technical detail. Read together they support that a destructive attack occurred against a major entertainment company in late 2014 and that the US government held North Korea's government responsible. Neither document states a financial cost, a full list of what was stolen, or the specific evidence linking the malware to North Korean state actors.

Why it mattered

The attack combined three elements rarely seen together before: theft of internal data, deliberate public leaking of it to cause reputational harm, and destructive wiping of affected systems. Earlier destructive incidents against critical infrastructure had shown wiper malware could disable operational systems; this attack showed the same destructive intent could target a media company's network as coercion tied to specific content. It became a reference case for boards and insurers weighing how much a single intrusion, without any encryption or ransom demand, could cost in leaked communications and rebuilt infrastructure.

Defensive takeaway

Treat destructive malware and data-leak extortion as related but separate risks in your incident-response planning, since a response built only around restoring encrypted files will not address an attacker whose goal is publication rather than payment.

  • Does your incident-response plan address an attacker who wants to publish stolen data rather than sell it back to you?
  • Could an attacker with domain credentials push a destructive payload to every workstation on your network before you noticed the intrusion?
  • Who in your organisation is authorised to decide how to respond if internal communications are threatened with public release?

The technical alert and the sanctions announcement were issued by different parts of the US government for different audiences, and neither was written to give a complete account of the intrusion; together they establish only that a destructive, credential-based attack occurred and that Washington held North Korea responsible, not the fuller narrative that later reporting and legal proceedings have added since.

Defensive takeaway

Treat destructive malware and data-leak extortion as related but separate risks in your incident-response planning, since a response built only around restoring encrypted files will not address an attacker whose goal is publication rather than payment.

A technical alert describes the malware without attribution, and a separate Treasury sanctions announcement attributes the attack to North Korea's government without technical detail; together they support both halves of the record, but neither states a financial cost or full data inventory, and this article does not rely on any later criminal proceedings.

Sources & reading trail

Targeted Destructive Malware (TA14-353A) ↗

Technical description of the SMB worm and disk-wiping components used against a major entertainment company, without attribution.

government-primary · Source published: 19 December 2014 · Retrieved: 16 September 2026

Treasury Sanctions Individuals and Entities in Response to the Government of North Korea's Ongoing Provocative, Destabilizing, and Repressive Actions and Policies ↗

US government's formal attribution of the Sony Pictures attack to North Korea's government and its stated rationale for sanctions.

government-primary · Source published: 2 January 2015 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.