I work at Sony Pictures. This is what it was like after we got hacked.
An employee* in the Los Angeles office of Sony Pictures Entertainment SNE opened up to Fortune about the personal ordeal they went through following revelations of North Korea's alleged cyber attack on the company.
Context & Ripple Effects
Days after the breach became public, a [[a:null|Sony Pictures]] employee tells Fortune what the aftermath felt like from inside the Los Angeles office — the human ledger of an attack that CBS News was already dissecting technically, asking how North Korea could have pulled it off. This account matters because it arrives before the institutional story settles: the NYT's early interviews found the company slow to realize the gravity of the hack, and Fortune's own investigation would later dig into how that happened.
What came after gives this testimony its weight — by mid-2015, reporting showed Sony had prioritized not offending North Korea over hardening its defenses, and employees were still living with the consequences a year on.
First-order effects
- Employees at the studio bear the immediate cost: their personal data and workplace routines are exposed, and the alleged North Korean attribution makes them targets of a state-directed operation rather than ordinary crime victims.
- Sony Pictures Entertainment must manage a workforce in distress at the same moment it is managing a public crisis, with internal communication now under scrutiny as much as its IT systems.
Second-order effects
- The employee-level damage pressures Sony's leadership toward risk calculations that favor optics over engineering — the later reporting shows the company weighing security costs against perceived risks instead of investing in hardened defenses.
- Rival studios and other Hollywood employers face the same exposure calculus: if a state actor will hit a content company over its output, every entertainment firm's employee data and internal systems become part of the geopolitical battleground.
Third-order effects
- If the pattern holds, corporate cybersecurity decisions get made through a diplomatic lens — companies attacked by nation-states may soften technical remediation to avoid escalation, leaving employees as the residual risk-bearers.
- Sustained insider accounts like this one shift the record from a technical incident to a labor issue, pushing future breach coverage and possibly regulation toward how companies treat exposed workers, not just exposed servers.
The trend: Nation-state cyberattacks on media companies are turning employees into primary casualties while corporate responses increasingly trade technical hardening for geopolitical caution.