Sony server found to host phishing website

When it rains it pours for Sony and its ongoing security woes. Three weeks of downtime for gamers following the PSN hack, followed by an easy workaround for stealing a PSN user account two days after Sony turned the servers back on. Now another threat has been found, but this time it’s not related to Sony’s gaming service.
sonyth1 sonyth1

Security vendor F-Secure has discovered that the server holding the official Sony website for Thailand also has a phishing site active on it. The official site is located at sony.co.th, where as the phishing site is live on hdworld.sony.co.th (do not visit). As the image below shows, it relates to an Italian credit card company.

The less savvy users surfing the web may rightly think this is an official partner page as it is hosted on Sony’s site. But the reality is someone has managed to hack the Sony Thailand server and inject this page without Sony noticing.

F-Secure has reported the hack to Sony who should take it down in short order. In the meantime, we suggest steering clear of any pages hosted on sony.co.th.

sonyth2

 

Sources: Geek.com, F-Secure