On November 24, 2014, employees arriving at Sony Pictures Entertainment found their computer screens displaying a red skeleton graphic and a message from a group calling themselves "Guardians of Peace." The attackers claimed to have all of Sony's data. They were not bluffing. Over the following weeks, they released tens of thousands of confidential documents - unreleased films, executive salary data, embarrassing internal emails, social security numbers for thousands of employees, and private correspondence that would end careers and damage diplomatic relationships. The Sony Pictures hack was the first time a nation-state conducted a destructive cyberattack against a private entertainment company in the United States, and it was provoked by a comedy film.

The Malware: DESTOVER

The primary payload deployed against Sony Pictures was a wiper malware called DESTOVER, attributed to North Korea's Lazarus Group. Wipers are designed to destroy data rather than steal or ransom it; unlike ransomware, there is no decryption key to sell. DESTOVER overwrote the master boot record and file system of infected machines, rendering them unbootable. It also exfiltrated data before wiping, giving the attackers material to leak publicly.

DESTOVER was deployed against Sony's Windows systems with domain administrator credentials the attackers had previously obtained. The wiper ran simultaneously on thousands of machines, beginning a cascade of destruction that Sony's IT team was unable to stop once triggered. The wiping affected approximately 70% of Sony Pictures' computer infrastructure.

A secondary payload, RATANKBA (a backdoor also attributed to Lazarus), had been present on Sony's network for weeks or months before the destructive action, used for reconnaissance, data exfiltration, and lateral movement. This pattern - extended reconnaissance followed by triggered destructive payload - has since become the Lazarus signature for operations intended to cause visible damage.

[TECHNICAL NOTE]
DESTOVER's wiper functionality overwrote the first 60KB of disk storage including the MBR with a custom bootsector containing a message from "Guardians of Peace." The technique of overwriting the MBR had been used in the Shamoon wiper deployed against Saudi Aramco in 2012 and was later reused in the Petya/NotPetya family. Recovering wiped systems required physical reimaging of every affected machine.

The Provocation: The Interview

The trigger for the attack was "The Interview," a comedy film starring James Franco and Seth Rogen in which CIA agents plot to assassinate Kim Jong-un. North Korea had formally protested the film to the United Nations before the attack occurred, calling it "an act of war" and demanding the film not be released.

The attackers' demands included both stopping the film's release and ongoing threats about "9/11-type" consequences if cinemas screened it. Multiple major cinema chains - Regal, AMC, Cinemark, and Carmike - cancelled screenings in the week before the planned release after the threat. Sony initially cancelled the release entirely. President Obama publicly criticized the decision, describing it as "a mistake" and stating that no company should be intimidated into self-censorship by cyberattacks.

Sony subsequently released the film via digital platforms on December 24, 2014 - the same day as a planned theatrical release to the approximately 300 independent cinemas that had agreed to show it. The digital release made approximately $15 million in its first four days. The film itself received mixed reviews.

The Data Leaks

The material released by Guardians of Peace caused damage that extended far beyond Sony's internal operations.

Unreleased films were the first major leak: "Annie," "Mr. Turner," "Still Alice," and "Fury" were uploaded to BitTorrent within days of the initial breach announcement. The film industry's annual awards season is heavily dependent on the exclusivity of certain films; the leaks disrupted Sony's awards strategy.

Executive email archives were the most damaging leaks from a reputational standpoint. Emails between Sony Pictures co-chairman Amy Pascal and producer Scott Rudin included racially charged jokes about President Obama's presumed movie preferences. Pascal resigned from Sony in February 2015. Rudin's reputation faced intense scrutiny (though he continued working; a subsequent New York Times investigation in 2021 detailed his pattern of abusive behavior, drawing on the 2014 leaks among other sources).

Employee data: social security numbers, salary information, and performance reviews for over 47,000 current and former Sony employees were released, exposing the company to significant identity theft and privacy liability.

Diplomatic complications: emails discussing talent and projects exposed contract terms and confidential conversations with actors, directors, and business partners that created lasting friction in Hollywood relationships.

[WARNING]
Cybersecurity researchers, journalists, and others who downloaded and published information from the leaked Sony files were criticized by some legal commentators for potentially violating the Computer Fraud and Abuse Act or receiving stolen property. The ethical questions around reporting on hacked data - particularly private communications that the public might consider newsworthy - have not been resolved by the Sony case.

Attribution and the FBI Response

The FBI attributed the attack to North Korea in December 2014, before the full technical evidence had been made public. The attribution was controversial; several security researchers questioned the speed of the public attribution and argued the evidence was insufficient.

The subsequent technical analysis supported the attribution. Code overlaps between DESTOVER and previously observed Lazarus Group malware - including the Jokra wiper used against South Korean banks and broadcasters in 2013 - were documented. Infrastructure overlaps with North Korean IP address space were identified. The specific compilation artifacts and code style matched the Lazarus canon. Later indictments in 2018 (against Park Jin Hyok) and 2021 (against Jon Chang Hyok and Kim Il) laid out the technical evidence in public legal filings.

The FBI's rapid public attribution was itself significant: it was the first public US government attribution of a cyberattack to North Korea, and one of the first prominent cases of the US government publicly naming a nation-state adversary for a specific cyberattack on a private company. The attribution precedent set here contributed to the subsequent attribution culture that produced public Mandiant APT reports, DOJ indictments, and joint CISA/NSA advisories naming specific threat actors.

Consequences and North Korean Cyber Evolution

The US response to the Sony hack was limited: new sanctions against North Korea, a temporary internet outage (widely attributed to NSA action) affecting North Korean infrastructure, and the DOJ indictments filed years later. No cyber offensive response was publicly acknowledged.

North Korea drew conclusions from the Sony operation that shaped subsequent Lazarus campaigns. The destructive wiper capability demonstrated that cyber operations could impose real costs on adversaries without crossing the threshold of armed conflict. The financial operations that followed - Bangladesh Bank SWIFT heist in 2016, WannaCry in 2017, the cryptocurrency theft campaigns running through 2025 - showed a pivot toward operations that generated revenue rather than just causing damage.

The Sony hack also influenced US corporate security posture. The combination of ransomware threats, destructive wiper deployment, and public data leaking - triple extortion before the term existed - became a template that criminal ransomware groups subsequently adopted. REvil's publication of stolen data, Clop's mass exfiltration campaigns, and the modern double-extortion model all owe something to the Sony playbook, even if the criminal groups developed these tactics independently.

The film "The Interview" is remembered more for the attack than for its content. It grossed approximately $12 million in theatrical release and remains one of the most internationally significant comedies in cinema history not because of its artistic merit but because a nuclear-armed state found its premise threatening enough to wage a cyberwar over it.