Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Sony

Sony Vendor Cyber Rating & Cyber Score

sony.com

Sony’s purpose is simple. We aim to fill the world with emotion, through the power of creativity and technology. We want to be responsible for getting hearts racing, stirring ambition, and putting a smile on the faces of our customers. That challenge, combined with our spirit of innovation, motivates us to create groundbreaking technology, entertainment, and services for people worldwide. Our history as a global brand has been built around employees that all have a passion for touching peoples'​ lives, and pride in pushing beyond the status quo to produce truly extraordinary results. We’re uniquely positioned because we operate in many different industries - from movies and music to video games and electronics. And, with offices around


Sony A.I CyberSecurity Scoring

Sony
Company Information
Website:https://www.sony.com/en/
Employees number:23,248
Number of followers:1,312,351
NAICS:71
Industry Type:Entertainment Providers
Homepage:sony.com
Sony Risk Score (AI oriented)
Between 600 and 649
logo
SonyEntertainment Providers
Updated:
01/04/2026
628/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Sony Global Score (TPRM)
xxxx
logo
SonyEntertainment Providers
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Sony
SonyPoor
Current Score
628Caa (POOR)
01000
8 incidents
-57.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
637Before Incident
MAY 2026
640Before Incident
APRIL 2026
634Before Incident
MARCH 2026
659Before Incident
Breach
10 Mar 2026Sony
Salesforce, Snowflake, Okta, Sony, LastPass and AMD: Salesforce Customer Data Breach Linked to ShinyHunters

ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft

629After Incident
CRITICAL-30
SALLASAMDSNOSONOKT1773153462
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft The hacking group ShinyHunters has claimed responsibility for stealing data from approximately 100 major companies by exploiting misconfigurations in Salesforce’s Experience Cloud platform. According to reports, the group accessed information from around 400 websites and organizations, including high-profile targets like Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself. Salesforce confirmed that a "known threat actor group" is actively scanning public-facing Experience Cloud sites portals used for customer, partner, and employee interactions due to overly permissive guest user configurations. The company clarified that the issue stems from customer-defined guest user profiles, not a vulnerability in Salesforce’s core platform. ### How the Attack Works Experience Cloud sites can be configured to allow guest users (unauthenticated visitors) to view public pages and submit forms. However, if these guest profiles are granted excessive permissions, attackers can query and extract CRM data that was never intended to be public. ShinyHunters reportedly used a modified version of AuraInspector, an open-source tool originally designed by Mandiant to detect misconfigurations in Salesforce’s Aura endpoints. The altered tool enables mass scanning of public-facing sites, extracting data when guest permissions are too broad. ### ShinyHunters’ Track Record Active since 2019, ShinyHunters has been linked to numerous high-profile breaches, often employing "pay or leak" tactics demanding ransoms to prevent data exposure. Recent incidents include the 2024 Snowflake breach, as well as attacks on universities and consumer platforms, leveraging phishing, social engineering, and SaaS misconfigurations. ### The Broader Risk of Misconfiguration This incident highlights a persistent cybersecurity challenge: misconfiguration remains a leading attack vector. While SaaS platforms like Salesforce offer robust security controls, human error in permission settings can expose sensitive data. Experience Cloud’s flexibility designed for public-facing portals becomes a liability when guest user profiles are improperly configured, allowing unauthorized access to CRM records. ### Salesforce’s Response & Mitigation Steps Salesforce has urged customers to: - Audit guest user permissions across all Experience Cloud sites. - Set default external access to "private" to block unauthenticated queries. - Disable guest access to public APIs and remove API-enabled permissions from guest profiles. - Monitor logs for unusual activity, such as large-scale scanning attempts. The incident underscores the need for ongoing security reviews rather than one-time configurations, as cloud environments evolve and threat actors refine their tactics. With regulatory scrutiny and reputational risks escalating, enterprises must treat access control and governance as continuous priorities.
INCIDENT DETAILS -
TYPE
Data Theft
MOTIVATION
Data TheftExtortion (Pay or Leak Tactics)
IMPACT
Data Compromised: CRM data from approximately 400 websites and organizationsSystems Affected: Salesforce Experience Cloud sites with misconfigured guest user permissionsBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: CRM dataSensitivity Of Data: High (Personally Identifiable Information likely included)Data Exfiltration: YesPersonally Identifiable Information: Likely
FEBRUARY 2026
658Before Incident
JANUARY 2026
763Before Incident
DECEMBER 2025
651Before Incident
NOVEMBER 2025
648Before Incident
OCTOBER 2025
727Before Incident
Ransomware
03 Oct 2025Sony
Salesforce

Scattered Lapsus$ Hunters Ransomware Attack on Salesforce Customer Data via Salesloft Drift Integration

642After Incident
CRITICAL-85
SAL5592855100325
The ransomware group ShinyHunters (Scattered Lapsus$ Hunters) breached Salesforce by exploiting stolen OAuth tokens from Salesloft Drift’s AI chatbot integration, compromising 1.5 billion records across 760 companies (including Cisco, Disney, and Marriott). The leaked data includes PII (names, DOBs, passports, employment histories), shipping details, chat transcripts, flight records, and car ownership data—validated by cybersecurity researchers. Attackers first infiltrated Salesloft’s GitHub repository, extracting private source code and OAuth tokens, then laterally moved to Google Workspace, Microsoft 365, and Okta platforms of victims. The group demanded separate ransoms from Salesforce and listed 39 high-profile victims on a darkweb leak site, pressuring them to pay under threat of full data exposure. The attack leveraged social engineering (vishing, phishing, IT impersonation) to trick employees into granting access, highlighting vulnerabilities in third-party supply-chain integrations and weak 2FA/OAuth security controls.
INCIDENT DETAILS -
TYPE
Data BreachRansomwareSupply Chain AttackSocial Engineering
MOTIVATION
Financial Gain (Extortion/Ransom)Data Theft for Dark Web SalesReputation Damage
IMPACT
Personally Identifiable Information (PII)Shipping InformationMarketing Lead DataCustomer Support Case RecordsChat TranscriptsFlight DetailsCar Ownership RecordsEmployment HistoriesPassport NumbersFull Contact InformationSalesforce CRM InstancesSalesloft Drift AI ChatbotGoogle WorkspaceMicrosoft 365Okta PlatformsGitHub Repository (Salesloft)Potential Disruption to CRM OperationsCustomer Data Exposure RisksIncident Response ActivationHigh (Public Data Leak Site)Loss of Customer TrustMedia ScrutinyPotential GDPR/CCPA ViolationsRegulatory FinesClass-Action LawsuitsIdentity Theft Risk: High (Exposed PII Includes Passport Numbers, DOBs, Contact Details)
DATA BREACH
PIICustomer Support RecordsChat TranscriptsMarketing DataShipping InformationFlight DetailsEmployment HistoriesNumber Of Records Exposed: 1,500,000,000 (claimed)Sensitivity Of Data: High (Includes Passport Numbers, Nationalities, Contact Details)Data Exfiltration: Confirmed (Samples Validated by Researchers)Data Encryption: No (Data Stolen in Plaintext)Database DumpsCSV/Excel FilesJSON/Log FilesChat TranscriptsFull NamesDates of BirthNationalitiesPassport NumbersEmail AddressesPhone NumbersPhysical AddressesEmployment Histories
SEPTEMBER 2025
727Before Incident
AUGUST 2025
725Before Incident
JULY 2025
723Before Incident
APRIL 2025
717Before Incident
Vulnerability
01 Apr 2025Sony
HP

Privilege Escalation Vulnerability in Plantronics Hub Software

714After Incident
HIGH-3
HP909040125
A critical security vulnerability was found in Plantronics Hub software, which has been discontinued by HP. Attackers could escalate privileges using an unquoted search path weakness when combined with OpenScape Fusion for MS Office during startup. The vulnerability takes advantage of a flaw in how Windows handles unquoted paths. Attackers with write access to the C:\ directory can plant malicious files that execute with elevated privileges, allowing them to bypass User Account Control and escalate privileges. As OpenScape Fusion launches Plantronics Hub, the malicious code is executed, leading to privilege escalation. HP has not released a patch but recommends quoting the registry path and restricting write permissions to the C:\ directory as mitigation strategies.
INCIDENT DETAILS -
TYPE
Privilege Escalation
MOTIVATION
Privilege Escalation
IMPACT
Plantronics HubOpenScape Fusion for MS Office
MARCH 2025
745Before Incident
Breach
01 Mar 2025Sony
Sony

Leak of AI-Powered PlayStation Character Tech Demo

715After Incident
HIGH-30
SON955031125
An internal PlayStation character tech demo has been leaked, showcasing an AI-powered version of Aloy from the Horizon franchise. The leaked prototype reveals Sony's explorations into using AI for game development, with Aloy responding to players using AI-generated voice and facial movements. This early glimpse into game character development via AI has sparked concerns among players regarding the potential loss of a personal touch and immersion that typical voiceovers and motion capture bring. The video was spread across various platforms, raising issues of intellectual property infringement and stirring discussions on the future implications of AI in the gaming industry.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: AI-powered character tech demo
DATA BREACH
Type Of Data Compromised: Intellectual Property
FEBRUARY 2025
774Before Incident
Breach
01 Feb 2025Sony
Grubhub: Grubhub confirms hackers stole data in recent security breach

Grubhub Data Breach Amid Extortion Demands by ShinyHunters

744After Incident
CRITICAL-30
GRU1768529823
Grubhub Confirms Data Breach Amid Extortion Demands by ShinyHunters Grubhub has acknowledged a recent data breach after hackers accessed its systems, with sources indicating the company is now facing extortion demands. The food delivery platform confirmed unauthorized access but stated that sensitive data such as financial information or order history remained unaffected. While Grubhub declined to provide further details, including the breach timeline or whether customer data was compromised, it confirmed collaboration with a third-party cybersecurity firm and law enforcement. Multiple sources identified the ShinyHunters cybercrime group as the likely perpetrators, though the threat actors refused to comment when contacted. The extortion demands reportedly involve Bitcoin payments to prevent the release of stolen data, including older Salesforce records from a February 2025 breach and newer Zendesk data accessed in the recent incident. Grubhub uses Zendesk for its customer support chat system, which handles orders, account issues, and billing. The breach appears linked to credentials stolen during the August 2025 Salesloft Drift attacks, where threat actors exploited stolen OAuth tokens to compromise Salesforce integrations. Google’s Mandiant reported that the stolen data including AWS access keys, passwords, and Snowflake tokens was later used in follow-up attacks. ShinyHunters previously claimed responsibility for the Salesloft breach, alleging the theft of 1.5 billion records from 760 companies. This incident follows a separate wave of scam emails sent from Grubhub’s b.grubhub.com subdomain last month, promoting a cryptocurrency scam. While Grubhub stated it contained the issue, it remains unclear whether the two events are connected.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion (Bitcoin payments to prevent data release)
IMPACT
Data Compromised: Salesforce records (February 2025), Zendesk data (recent incident)Zendesk customer support chat systemSalesforce integrationsPayment Information Risk: None (sensitive financial data unaffected)
DATA BREACH
Salesforce recordsZendesk customer support dataSensitivity Of Data: Non-sensitive (financial information and order history unaffected)Data Exfiltration: Yes (threatened for extortion)
JANUARY 2025
807Before Incident
Breach
01 Jan 2025Sony
Grubhub: Ex-Grubhub Worker Alleges Food App Negligently Allowed Data Hack

Grubhub Faces Class Action Lawsuit Over January 2025 Data Breach

773After Incident
CRITICAL-34
GRU1769118538
Grubhub Faces Class Action Lawsuit Over January 2025 Data Breach A former Grubhub employee has filed a class action lawsuit against the food delivery platform, alleging the company failed to implement adequate security measures to protect sensitive personal and financial data. The complaint, filed on February 5, 2025, in the U.S. District Court for the Northern District of Illinois, claims cybercriminals accessed the information of tens of thousands of customers and employees in a January 2025 breach. The exposed data reportedly included Social Security numbers, addresses, and financial details. Grubhub notified affected individuals on February 3, 2025, acknowledging the incident. The lawsuit, led by plaintiff Brian Bianchi, accuses Grubhub of negligence in safeguarding user data, potentially leaving victims vulnerable to identity theft and fraud. The case highlights growing scrutiny over corporate cybersecurity practices and the legal consequences of failing to protect consumer information. No further details on the breach’s scope or the attackers’ methods have been disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Social Security numbers, addresses, financial detailsBrand Reputation Impact: Potential reputational damage due to negligence allegationsLegal Liabilities: Class action lawsuit filedIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personal and financial dataNumber Of Records Exposed: Tens of thousandsSensitivity Of Data: High (Social Security numbers, financial details)Personally Identifiable Information: Social Security numbers, addresses
SEPTEMBER 2023
837Before Incident
Data Leak
01 Sep 2023Sony
Sony

NTT Docomo Ransomware Attack

798After Incident
CRITICAL-39
SON02421023
The renowned ransomware group Ransomed. vc reported a new victim today in the form of the major Japanese telecommunications company NTT Docomo in response to the newly disclosed Sony data leak. Notably, the statement coincided nearly exactly with the release of additional Sony data leaks that shed some light on the data breach's predecessor. The largest NTT Docomo is being asked to pay $1,015,000 to the bad actors. The bad guys released the stolen data after Sony declined to fulfill the ransom demands. It was discovered that if businesses don't pay, hackers will release the data they've stolen, which could result in regulatory penalties that occasionally exceed the ransom.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
JUNE 2014
837Before Incident
Vulnerability
16 Jun 2014Sony
Sony

Sony Pictures Entertainment Cyberattack

825After Incident
CRITICAL-12
SON601050824
In 2014, Sony Pictures Entertainment suffered a massive cyberattack resulting in the loss of over 100 Terabytes of data containing confidential company information. This breach not only led to financial losses estimated to be well over $100 million but also severely damaged the company’s reputation. The attack was conducted through phishing emails, where the attackers disguised themselves as colleagues using fake Apple ID verification emails. Utilizing a combination of LinkedIn data and compromised Apple ID logins, the assailants were able to acquire passwords that matched those used for Sony’s network. This significant incident underscores the importance of enforcing robust cybersecurity measures and the necessity of employing unique passwords for different online services to mitigate the risk of such breaches.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: Over $100 millionData Compromised: Over 100 Terabytes of confidential company informationBrand Reputation Impact: Severely damaged
DATA BREACH
Type Of Data Compromised: Confidential company information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Sony ?
?
What was Sony's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Sony's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Sony's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Sony's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Sony's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Sony's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Sony's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Sony's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Sony's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Sony's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Sony's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Sony's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Sony ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Sony's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?