In new email sent to Sony executives, hackers threaten further release of “sensitive data” pending any “additional trouble”
Source: Hackers send new message to Sony — NEW YORK (CNNMoney) — The hackers behind a devastating cyberattack at Sony Pictures …
Context & Ripple Effects
This email is an escalation in the Sony Pictures breach: the hackers are no longer just dumping data, they are negotiating — conditioning further release of sensitive material on the company avoiding "additional trouble." It lands days before an FBI bulletin warned that the same attackers had threatened an unnamed news organization, signaling the campaign was expanding beyond its original target.
Sony had already moved to contain the spill by threatening to sue Twitter over tweets containing hacked emails — a legal containment play running alongside the hackers' own pressure tactic. The standoff set up what became a permanent public record: months later, WikiLeaks published a cache of 276,394 Sony Pictures documents, making the leaked material searchable regardless of how the negotiation resolved.
First-order effects
- Sony Pictures executives are now directly addressed as negotiable parties, shifting the company's decision from incident response to whether conceding or resisting limits further disclosure.
- Sony must run two fronts at once: the hackers' release threats and platform-level takedown pressure, where it has already threatened litigation against Twitter for hosting hacked emails.
Second-order effects
- Threats spreading to a news organization, as flagged in the FBI bulletin, turn the attackers from a single-company extortionist into a multi-target pressure campaign that forces other potential victims and media platforms onto alert.
- The breach's aftermath creates a secondary market: by early 2015, a US security firm reported Russian hackers claiming to sell access to Sony's network, meaning even a "resolved" incident leaves exploitable footholds in circulation.
Third-order effects
- WikiLeaks' republication shows the structural endpoint of this attack class: once stolen corporate archives escape, they become permanent, citable public records that outlast any settlement between attacker and victim.
- The pattern recurs — nearly a decade later Sony opened another investigation after the Ransomed.vc group claimed a fresh breach and threatened to sell or post stolen data, suggesting extortion-by-leak against Sony became a repeatable playbook rather than a one-off.
The trend: Corporate cyberattackers are shifting from one-time data dumps toward ongoing leverage campaigns, with leaked archives persisting as public records and victim companies facing repeat targeting across years.