Sony A.I CyberSecurity Scoring
Sony
Company Information
Website:https://www.sony.com/en/
Employees number:23,248
Number of followers:1,312,351
NAICS:71
Industry Type:Entertainment Providers
Homepage:sony.com
Sony Risk Score (AI oriented)
Between 600 and 649
SonyEntertainment Providers
Updated:
01/04/2026
01/04/2026
628/1000
Poor
Caa
Sony Global Score (TPRM)
xxxx
SonyEntertainment Providers
Score locked

SonyPoor
Current Score
628Caa (POOR)
01000
8 incidents
-57.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
637
MAY 2026
640
APRIL 2026
634
MARCH 2026
659
Breach
10 Mar 2026 • Sony
Salesforce, Snowflake, Okta, Sony, LastPass and AMD: Salesforce Customer Data Breach Linked to ShinyHunters
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
629
CRITICAL-30
SALLASAMDSNOSONOKT1773153462
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
The hacking group ShinyHunters has claimed responsibility for stealing data from approximately 100 major companies by exploiting misconfigurations in Salesforce’s Experience Cloud platform. According to reports, the group accessed information from around 400 websites and organizations, including high-profile targets like Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself.
Salesforce confirmed that a "known threat actor group" is actively scanning public-facing Experience Cloud sites portals used for customer, partner, and employee interactions due to overly permissive guest user configurations. The company clarified that the issue stems from customer-defined guest user profiles, not a vulnerability in Salesforce’s core platform.
### How the Attack Works
Experience Cloud sites can be configured to allow guest users (unauthenticated visitors) to view public pages and submit forms. However, if these guest profiles are granted excessive permissions, attackers can query and extract CRM data that was never intended to be public.
ShinyHunters reportedly used a modified version of AuraInspector, an open-source tool originally designed by Mandiant to detect misconfigurations in Salesforce’s Aura endpoints. The altered tool enables mass scanning of public-facing sites, extracting data when guest permissions are too broad.
### ShinyHunters’ Track Record
Active since 2019, ShinyHunters has been linked to numerous high-profile breaches, often employing "pay or leak" tactics demanding ransoms to prevent data exposure. Recent incidents include the 2024 Snowflake breach, as well as attacks on universities and consumer platforms, leveraging phishing, social engineering, and SaaS misconfigurations.
### The Broader Risk of Misconfiguration
This incident highlights a persistent cybersecurity challenge: misconfiguration remains a leading attack vector. While SaaS platforms like Salesforce offer robust security controls, human error in permission settings can expose sensitive data. Experience Cloud’s flexibility designed for public-facing portals becomes a liability when guest user profiles are improperly configured, allowing unauthorized access to CRM records.
### Salesforce’s Response & Mitigation Steps
Salesforce has urged customers to:
- Audit guest user permissions across all Experience Cloud sites.
- Set default external access to "private" to block unauthenticated queries.
- Disable guest access to public APIs and remove API-enabled permissions from guest profiles.
- Monitor logs for unusual activity, such as large-scale scanning attempts.
The incident underscores the need for ongoing security reviews rather than one-time configurations, as cloud environments evolve and threat actors refine their tactics. With regulatory scrutiny and reputational risks escalating, enterprises must treat access control and governance as continuous priorities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
658
JANUARY 2026
763
DECEMBER 2025
651
NOVEMBER 2025
648
OCTOBER 2025
727
Ransomware
03 Oct 2025 • Sony
Salesforce
Scattered Lapsus$ Hunters Ransomware Attack on Salesforce Customer Data via Salesloft Drift Integration
642
CRITICAL-85
SAL5592855100325
The ransomware group ShinyHunters (Scattered Lapsus$ Hunters) breached Salesforce by exploiting stolen OAuth tokens from Salesloft Drift’s AI chatbot integration, compromising 1.5 billion records across 760 companies (including Cisco, Disney, and Marriott). The leaked data includes PII (names, DOBs, passports, employment histories), shipping details, chat transcripts, flight records, and car ownership data—validated by cybersecurity researchers. Attackers first infiltrated Salesloft’s GitHub repository, extracting private source code and OAuth tokens, then laterally moved to Google Workspace, Microsoft 365, and Okta platforms of victims. The group demanded separate ransoms from Salesforce and listed 39 high-profile victims on a darkweb leak site, pressuring them to pay under threat of full data exposure. The attack leveraged social engineering (vishing, phishing, IT impersonation) to trick employees into granting access, highlighting vulnerabilities in third-party supply-chain integrations and weak 2FA/OAuth security controls.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
727
AUGUST 2025
725
JULY 2025
723
APRIL 2025
717
Vulnerability
01 Apr 2025 • Sony
HP
Privilege Escalation Vulnerability in Plantronics Hub Software
714
HIGH-3
HP909040125
A critical security vulnerability was found in Plantronics Hub software, which has been discontinued by HP. Attackers could escalate privileges using an unquoted search path weakness when combined with OpenScape Fusion for MS Office during startup. The vulnerability takes advantage of a flaw in how Windows handles unquoted paths. Attackers with write access to the C:\ directory can plant malicious files that execute with elevated privileges, allowing them to bypass User Account Control and escalate privileges. As OpenScape Fusion launches Plantronics Hub, the malicious code is executed, leading to privilege escalation. HP has not released a patch but recommends quoting the registry path and restricting write permissions to the C:\ directory as mitigation strategies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2025
745
Breach
01 Mar 2025 • Sony
Sony
Leak of AI-Powered PlayStation Character Tech Demo
715
HIGH-30
SON955031125
An internal PlayStation character tech demo has been leaked, showcasing an AI-powered version of Aloy from the Horizon franchise. The leaked prototype reveals Sony's explorations into using AI for game development, with Aloy responding to players using AI-generated voice and facial movements. This early glimpse into game character development via AI has sparked concerns among players regarding the potential loss of a personal touch and immersion that typical voiceovers and motion capture bring. The video was spread across various platforms, raising issues of intellectual property infringement and stirring discussions on the future implications of AI in the gaming industry.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
774
Breach
01 Feb 2025 • Sony
Grubhub: Grubhub confirms hackers stole data in recent security breach
Grubhub Data Breach Amid Extortion Demands by ShinyHunters
744
CRITICAL-30
GRU1768529823
Grubhub Confirms Data Breach Amid Extortion Demands by ShinyHunters
Grubhub has acknowledged a recent data breach after hackers accessed its systems, with sources indicating the company is now facing extortion demands. The food delivery platform confirmed unauthorized access but stated that sensitive data such as financial information or order history remained unaffected.
While Grubhub declined to provide further details, including the breach timeline or whether customer data was compromised, it confirmed collaboration with a third-party cybersecurity firm and law enforcement. Multiple sources identified the ShinyHunters cybercrime group as the likely perpetrators, though the threat actors refused to comment when contacted.
The extortion demands reportedly involve Bitcoin payments to prevent the release of stolen data, including older Salesforce records from a February 2025 breach and newer Zendesk data accessed in the recent incident. Grubhub uses Zendesk for its customer support chat system, which handles orders, account issues, and billing.
The breach appears linked to credentials stolen during the August 2025 Salesloft Drift attacks, where threat actors exploited stolen OAuth tokens to compromise Salesforce integrations. Google’s Mandiant reported that the stolen data including AWS access keys, passwords, and Snowflake tokens was later used in follow-up attacks. ShinyHunters previously claimed responsibility for the Salesloft breach, alleging the theft of 1.5 billion records from 760 companies.
This incident follows a separate wave of scam emails sent from Grubhub’s b.grubhub.com subdomain last month, promoting a cryptocurrency scam. While Grubhub stated it contained the issue, it remains unclear whether the two events are connected.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
807
Breach
01 Jan 2025 • Sony
Grubhub: Ex-Grubhub Worker Alleges Food App Negligently Allowed Data Hack
Grubhub Faces Class Action Lawsuit Over January 2025 Data Breach
773
CRITICAL-34
GRU1769118538
Grubhub Faces Class Action Lawsuit Over January 2025 Data Breach
A former Grubhub employee has filed a class action lawsuit against the food delivery platform, alleging the company failed to implement adequate security measures to protect sensitive personal and financial data. The complaint, filed on February 5, 2025, in the U.S. District Court for the Northern District of Illinois, claims cybercriminals accessed the information of tens of thousands of customers and employees in a January 2025 breach.
The exposed data reportedly included Social Security numbers, addresses, and financial details. Grubhub notified affected individuals on February 3, 2025, acknowledging the incident. The lawsuit, led by plaintiff Brian Bianchi, accuses Grubhub of negligence in safeguarding user data, potentially leaving victims vulnerable to identity theft and fraud.
The case highlights growing scrutiny over corporate cybersecurity practices and the legal consequences of failing to protect consumer information. No further details on the breach’s scope or the attackers’ methods have been disclosed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2023
837
Data Leak
01 Sep 2023 • Sony
Sony
NTT Docomo Ransomware Attack
798
CRITICAL-39
SON02421023
The renowned ransomware group Ransomed. vc reported a new victim today in the form of the major Japanese telecommunications company NTT Docomo in response to the newly disclosed Sony data leak.
Notably, the statement coincided nearly exactly with the release of additional Sony data leaks that shed some light on the data breach's predecessor.
The largest NTT Docomo is being asked to pay $1,015,000 to the bad actors. The bad guys released the stolen data after Sony declined to fulfill the ransom demands.
It was discovered that if businesses don't pay, hackers will release the data they've stolen, which could result in regulatory penalties that occasionally exceed the ransom.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JUNE 2014
837
Vulnerability
16 Jun 2014 • Sony
Sony
Sony Pictures Entertainment Cyberattack
825
CRITICAL-12
SON601050824
In 2014, Sony Pictures Entertainment suffered a massive cyberattack resulting in the loss of over 100 Terabytes of data containing confidential company information. This breach not only led to financial losses estimated to be well over $100 million but also severely damaged the company’s reputation. The attack was conducted through phishing emails, where the attackers disguised themselves as colleagues using fake Apple ID verification emails. Utilizing a combination of LinkedIn data and compromised Apple ID logins, the assailants were able to acquire passwords that matched those used for Sony’s network. This significant incident underscores the importance of enforcing robust cybersecurity measures and the necessity of employing unique passwords for different online services to mitigate the risk of such breaches.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Sony ??
What was Sony's A.I Rankiteo Cyber Score in May 2026 ??
What was Sony's A.I Rankiteo Cyber Score in April 2026 ??
What was Sony's A.I Rankiteo Cyber Score in March 2026 ??
What was Sony's A.I Rankiteo Cyber Score in February 2026 ??
What was Sony's A.I Rankiteo Cyber Score in January 2026 ??
What was Sony's A.I Rankiteo Cyber Score in December 2025 ??
What was Sony's A.I Rankiteo Cyber Score in November 2025 ??
What was Sony's A.I Rankiteo Cyber Score in October 2025 ??
What was Sony's A.I Rankiteo Cyber Score in September 2025 ??
What was Sony's A.I Rankiteo Cyber Score in August 2025 ??
What was Sony's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Sony's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Sony ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Sony's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?