Sony’s September: Rhysida, Ransomed.vc, and Claim Triage

📋 Key Takeaways
  • What happened
  • Anatomy of the extortion claims
  • Timeline
  • Defensive lessons
  • The verification gap in ransomware reporting
6 min read · 1,120 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

Quick Answer — In September 2023, Sony was hit with ransomware claims: two apparently competing extortion crews — the established Rhysida operation and a newcomer calling itself Ransomed.vc — both posted Sony data. Ransomed.vc touted a full dump (“more servers will be hacked”), while Rhysida ran a Bitcoin auction for material subsequently reported to include credentials from Sony’s systems. Sony confirmed it was investigating an intrusion but disputed the breathless scale. For defenders the episode was a masterclass in claim-triage during extortion noise: verify before you amplify, because ransom crews lie as routinely as they encrypt.

The story of September 2023’s noisiest non-catastrophe: double extortion claims, dueling leak-site press releases, and a giant that mostly yawned — a case study in attribution hedging, claim verification, and why “6TB stolen” is a marketing number until proven otherwise.

What happened

  • The first claim (Ransomed.vc): The new crew posted screenshots purporting to show Sony internal files, bragging that its members planned to sell the data because ransom wasn’t paid — attention-seeking as a launch strategy.
  • The second claim (Rhysida): Days later, the Rhysida leak site listed a Sony auction with a ~$1M+ starting price and 6-day countdown, later publishing chunks of data (reported as including an internal PKI code-signing certificate and credentials).
  • Sony’s position: The company acknowledged investigating the claims; reporting indicated most exposed material traced to a relatively contained footprint rather than the “everything” the crews implied. No confirmation of the claimed 6TB scale ever materialized.
  • The market backdrop: A third-party vendor exposure (per reporting, linked to Sony’s India-based distribution partner) muddied attribution further, illustrating how enterprise claims get tangled with supplier incidents.

Anatomy of the extortion claims

Element What was claimed vs. what verified
Data volume Claimed: massive exfiltration (“entire systems”); Verified: selective samples, scale never confirmed
Sensitive content Claimed: credentials, PKI certs; Verified: some credential material and a code-signing certificate appeared — the genuinely actionable part
Double extortion Claimed: “sell because no ransom paid”; Verified: two separate crews, likely different access — not a negotiation gone public
Impact on Sony Claimed: catastrophic compromise; Verified: contained investigation, no confirmed operational shutdown
Attribution confidence Both crews unproven: Ransomed.vc later reported as likely a rebrand/scam mix; Rhysida tracked as RaaS with uncertain initial-access origins
data-hmmnm-seam="2">

Timeline

Date Event
2023-09-14 (event) Ransomed.vc posts its Sony claims with file-tree screenshots — the first public extortion volley lands
2023-09-19 Rhysida lists a Sony data auction (BTC starting bid), converting attention into a bidding spectacle; press coverage spikes
2023-09-25 (our peg) Sony statements settle to “investigating”; threat-intel firms publish triage read-outs disputing the claimed blast radius; coverage pivots to the PKI certificate worry
2023-Q4 Rhysida publishes further data batches on its countdown schedule; Ransomed.vc’s credibility collapses amid scam accusations and reported law-enforcement interest
2024 per CISA/international advisories on the crew’s hospital campaigns); Sony fades from its leak sites without confirmed catastrophe
data-hmmnm-seam="3">

Defensive lessons

  • Triage extortion claims like threat intel, not press releases. Demand artifact-level proof (file trees, PKI certs, ticket exports) before accepting volume or sensitivity claims; crews inflate both by default.
  • Protect code-signing chains hardest. The most damaging verified artifact class in this saga was signing material — its leakage creates supply-chain risk for customers, not just embarrassment for you.
  • Map your supplier exposure before someone auctions it. Attribution ping-ponged partly because enterprise claims entangled with partner infrastructure — your periphery is their attack surface.
  • Pre-write your claim-denial comms. Sony’s calm “investigating” posture kept the news cycle from metastasizing; orgs that ad-lib either over-confirm or over-deny and lose either way.
  • Track the crews’ theatrics as IOCs. Auction countdowns, launch-brag posts, and dueling claims are behavioral signatures — useful for scanning leak-site chatter about your estate.
data-hmmnm-seam="4">

The verification gap in ransomware reporting

The Sony episode became a reference lesson in epistemic hygiene under extortion. Security journalism faced twin failure modes: laundering crew claims into headlines (“6TB of Sony data!”) and reflexive skepticism that buries real nuance (some data was real, including credential and PKI material). The mature playbook that crystallized: aggregate claims, but annotate with verification state — claimed vs. observed vs. confirmed — and treat leak-site countdown timers as negotiation theater, not deadlines that carry evidentiary weight. Ransomed.vc itself proved the point by imploding: the same month’s reporting tracked the crew’s mix of re-used access, outright fabrications, and rumor-grade claims. The 2026 analyst inherits this landscape at machine scale — AI-summarized leak sites, automated amplification, and claim-laundering “threat intel” accounts. The Sony September taught the discipline that survives that environment: artifacts before adjectives, provenance before propagation. If your org’s incident comms can’t state confidently what is verified versus merely claimed about your own breach, the crews will happily fill the gap — at auction volume.

data-hmmnm-seam="5">

Why it still matters in 2026

Ransom claims have since become ambient noise — every enterprise now expects a leak-site cameo at some point, and dueling-crew pile-ons (two claims on one victim) recurred in 2024–25 hospital and municipal incidents. Sony’s September remains the cleanest classroom example because both failure archetypes appeared at once: a hype-driven newcomer (Ransomed.vc) and a transactional professional (Rhysida) hitting the same logo. The durable takeaways are procedural: maintain an internal “claims ledger” during incidents (what each crew asserts, what evidence backs it), pre-position code-signing revocation and rotation runbooks, and brief leadership that exposure ≠ apocalypse — containment statements built on artifact-level facts age well. And keep an eye on the auction format: it reappears whenever crews believe a victim’s ecosystem of partners and customers will bid to keep data private — a market mechanism your third-party risk program should model today.

Did Sony actually get breached?

Yes, in the limited sense that intrusions occurred and some Sony-linked data (including credential material and, per reporting, a signing certificate) was real. What was never verified was the claimed scale — the “everything is ours” framing the crews marketed.

Who were Ransomed.vc and Rhysida?

Rhysida: a ransomware-as-a-service operation active in 2023, notorious for hospital and public-sector campaigns, later targeted by international advisories and enforcement actions. Ransomed.vc: a short-lived crew whose gimmick was claiming legal-invoicing legitimacy (posing as a GDPR-style “fine collector”) — widely assessed as a mix of recycled access and theater, which collapsed within months amid scam accusations.

Was the code-signing certificate the real damage?

Potentially, yes. Signing material, if abused, lets attackers ship malware that inherits trust from the breached brand — a supply-chain hazard for every customer. Sony-side rotation and customer-side signature-inventory checks neutralized most of that risk in practice, which is why the incident ended as noise rather than a SolarWinds-grade event.

Why did two crews hit the same victim?

Most plausibly separate initial-access resale — a common brokered commodity — plus appetite for shared headlines. Ransom affiliate economics reward visibility, and a big logo already in the news is cheap marketing for a newcomer launch.

Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.