How North Korea could have pulled off Sony Pictures hack
Sources tell CBS News the sophisticated and damaging cyberattack against Sony Pictures originated in North Korea and flowed through a vast array of computer servers in other countries in an attempt to hide its origin.
Context & Ripple Effects
The attribution case is assembling fast: the New York Times reported U.S. officials concluded Pyongyang ordered the attack on Sony, Krebs on Security traced the hacker group mainly to North Korea including a Japan-based cell of ethnic North Koreans, and Ars Technica found the 'sophisticated' malware was actually slapdash code. CBS News now adds the operational layer — the attack originated in North Korea but was laundered through computer servers across multiple other countries specifically to obscure that origin.
What makes this more than an attribution story is what came after: the NSA reportedly tapped into North Korean networks before the attack, meaning Washington likely saw the operation coming or in progress, and Fortune later reported Sony had prioritized not offending Pyongyang over hardening its defenses, fearing security costs more than risks. The gap between known capability and unhardened targets is the real story.
First-order effects
- Sony Pictures absorbs the immediate damage of a destructive, data-leaking intrusion while the FBI builds its public attribution case against North Korea, converting a corporate breach into a state-on-state incident.
Second-order effects
- Other studios and large enterprises face pressure to close the gap Fortune identified at Sony — treating nation-state attackers as a budget line rather than an unlikely risk — while the NSA's pre-existing access to North Korean networks becomes central to how the U.S. chooses to respond.
Third-order effects
- The server-laundering technique described here foreshadows the provenance problem now standard in attribution, and the pattern extends beyond disruption: per the surrounding record, North Korean actors moved on to industrial-scale cryptocurrency theft, with the FBI attributing the $1.5B Bybit heist to Pyongyang, UN monitors tracing $147.5M laundered through Tornado Cash, and the reported Research Center 227 unit pursuing AI-based hacking inside the Reconnaissance General Bureau.
The trend: State-sponsored hacking is evolving from one-off disruptive attacks like Sony into a standing revenue and espionage apparatus for sanctioned regimes, with attribution racing against increasingly deliberate origin-masking.