Eight days after Sony took the PlayStation Network offline, rumors and misinformation continue to swirl around the unprecedented shutdown and massive data breach that affected an estimated 77 million users.
Security expert Kevin Stevens of TrendMicro tweeted today, April 28, that low-level cybercriminals using "carder" online forums were offering to sell a database of 2.2 million credit-card numbers taken during the PlayStation Network breach.
Independent security blogger Brian Krebs then posted screenshots of four hackers discussing the purported database in a chat room.
"xxx: format is: fname, lnams, address, zipcode, country, phone, email, email password, dob, ccnum, cvv2, exp date," wrote user "Sutekh" in one of the screenshots.
In plain English, that's the first name, last name, address, postal code, country, telephone number, email address, email password, date of birth, credit-card number, credit-card security code and credit-card expiration date attached to each of 2.2 million accounts — including "150k german ones," as Sutekh said in a different posting.
"Sony was supposedly offered a chance to buy the DB (database) back but didn't," tweeted Stevens.
Neither Stevens nor Krebs claimed to have seen the actual database being offered, and it almost sounds too good to be true. Why, for example, would Sony have the passwords to users' third-party email accounts, such as Yahoo or Gmail accounts?
For its part, Sony dribbled out a bit more information today.
In an FAQ posted on various PlayStation websites worldwide, the company said that "your credit card security code (sometimes called a CVC or CSC number) has not been obtained because we never requested it from anyone who has joined the PlayStation Network or Qriocity, and is therefore not stored anywhere in our system."
(Qriocity is a separate entertainment-delivery network owned and run by Sony, which was also affected by the PlayStation Network breach.)
Sony also stated that, "The entire credit card table was encrypted and we have no evidence that credit card data was taken."
So either the hackers selling the database are lying about having credit card security codes, or Sony is not telling the truth about having them in the first place.
The latter scenario seems far less likely, as Sony would open itself to enormous lawsuits if it were found to be less than truthful about the breach — except that, as was reported yesterday, unencrypted credit card numbers with security codes are exactly what amateur hackers claimed to have found in PlayStation Network development channels two months ago.