CompanySep 30, 202611 min read

The Preview: How the Sony Hack Became North Korea’s Blueprint for Modern Cyber Warfare


Almost nobody remembers the Sony hack for what it actually was.

What they remember is the emails, the celebrity gossip, the pay gap revelations, and the racially insensitive jokes. The salacious details generated a seemingly endless churn of a media spectacle, SNL sketches, and fodder for late-night teasing. What gets forgotten (or never fully registered) is the rest of it: a foreign, nuclear-armed nation state reduced one of America’s largest entertainment companies to digital rubble, threatened to bomb movie theaters, and successfully censored a Hollywood film called The Interview that made fun of North Korea and its leadership.

Episode 4 of To Catch a Thief goes back to the moment North Korea’s cyber offensive hit America.


 

A Red Letter Event

Kevin Mandia, who has responded to more cyber attacks than anyone in the private sector, had seen a lot by 2014. But nothing prepared him for Sony.

“I call it a red letter event,” he said.

The attackers called themselves the Guardians of Peace—but the name was a distraction. The group used the same skeleton imagery as a 2013 attack against South Korean banks and broadcasters that wiped hard drives and knocked ATMs offline across Seoul. 

Mandiant, brought in to investigate, had no doubts: this was North Korea. The malware shared infrastructure, IP addresses, tooling and tactics with an earlier North Korean espionage operation Mandiant had tracked.

But what made the Sony hack different was the intent. Earlier operations stayed quiet. This one didn’t want to hide. It wanted to take credit while Sony bled.

Marshall Heilman, who led Mandiant’s on-site response, was surprised by the effectiveness of the attack. “For me, North Korea came a bit out of nowhere.” 

That admission, from someone who had spent years inside the most complex corporate intrusions in the world, reveals how little North Korea was on the private sector’s radar. Steve Stone, who had spent time in the intelligence community was blunter: “We were just totally wrong in our assessments."

Jenny Town, director of the North Korea-focused think tank 38 North, put it plainly: “The US intelligence community constantly underestimates what the North Koreans are capable of doing.”


 

The Attribution War

From the moment Mandiant’s forensic team began pulling data from Sony’s destroyed systems, competing voices bagan circling. The Big Four consultants Sony had also brought on-site argued the attack had to be the work of a disgruntled insider. Just because they didn’t have access to forensic data didn’t stop them from having opinions about the hack.

“If you’re not looking at the ones and zeros, I don’t know why anybody would have an opinion on what happened,” Steve Stone said. “They actually have no idea.”

When the FBI formally pinned the attack on North Korea—and President Obama confirmed it on national television—the backlash accelerated. Cybersecurity startups went on cable news with counter-theories. PBS NewsHour aired a segment questioning whether North Korea was even capable of something this sophisticated. Andrew Scott, who wrote the FBI’s attribution statement from inside the NSA and National Security Council, had one word for watching it unfold: “Maddening.”

Rob Joyce, who ran the NSA’s hacking division at the time, saw a troubling pattern. The attribution was correct. The intelligence community knew it and the cybersecurity firms who examined the evidence confirmed it. “The wisdom of crowds was already there,” he said.

And then, the moment the government made it official, the conspiracy theories exploded.

That reflex—to question the attribution staring us right in the face, to dismiss North Korea as too unsophisticated—would become a pattern. Adversaries learned they didn’t have to hide completely. They just had to sow enough doubt to hijack the conversation.


 

How the Hackers Won

While Americans debated whether North Korea had done this, the hackers were achieving their objectives in real time.

Theater chains buckled under threats of physical violence. The major Hollywood studios—unlike the publishing industry that rallied to Penguin’s defense during Iran’s fatwa against Salman Rushdie—stayed silent. Almost no studio reached out to Sony in solidarity.

Michael Lynton, Sony’s CEO at the time, watched a foreign dictatorship carry out a successful act of censorship against an American company while the press obsessed over leaked emails. “Everybody was so caught up in the salaciousness of the e-mails that nobody actually chose to look at the bigger issue,” he said.

The Interview was eventually released online and in a few hundred  of independent theaters. But the wide theatrical release of the movie was effectively scuttled.

“Ask yourself,” Nicole Perlroth says in the episode, “When was the last time you saw a major Hollywood film about Kim Jong Un? You haven’t.”

Steve Stone was direct: “The bad guys won. They definitively won, and that really bothered me.”


 

From Hollywood to the Ballot Box

What makes the Sony hack more than a Hollywood story is what came next.

Less than two years later, Russia hacked the Democratic National Committee (DNC). When stolen emails started dropping—drip by drip, through online personas, amplified by algorithms and WikiLeaks—the playbook looked familiar.

“Before 2014, Russia absolutely hacked networks,” Rob Joyce said. “But leaking stolen data to shape the public narrative was not a central repeatable doctrine for them. Sony, I think, gave them a template in 2014.”

America responded to the DNC hack the same way it had responded to Sony—attribution debates, conspiracy theories, and a media fixation on the contents of the emails (John Podesta’s risotto tips and Pizzagate, for example) rather than the fact of the breach. The conversation was successfully hijacked. Again.

The lesson adversaries took from Sony wasn’t just that destructive attacks work. It was that stolen information, released at the right moment and amplified by a fractured media environment, can do more damage than any piece of malware. 

North Korea ran the experiment. The world’s most sophisticated nation-state hackers took notes.


 

Listen: To Catch a Thief

Episode 4 of To Catch a Thief traces the origins of North Korea’s cyber offensive—from the first attacks against South Korea, to Sony, to the broader playbook that reshaped how nation states conduct information warfare. It includes interviews with Kevin Mandia, Marshall Heilman, and Steve Stone from Mandiant; Rob Joyce, former head of NSA’s TAO division; John Carlin from the Justice Department; Andrew Scott from CIA and NSC; Michael Lynton, former CEO of Sony Entertainment; and Dan Sterling, screenwriter of The Interview.

To Catch a Thief is co-produced by Nicole Perlroth and Rubrik, in partnership with Pod People. Follow the show wherever you listen to podcasts.

 

Related Articles

Blog by This Author