Senator Richard Blumenthal (D-CT) wrote the President and CEO of Sony Computer Entertainment America today demanding answers over the company's failure to notify millions of customers of a data breach in the PlayStation Network on April 20, 2011. Blumenthal noted that a breach of such a widely used service -- estimated by news reports as having 50 to 75 million customers -- immediately "raises concerns of data privacy, identity theft, and other misuse of sensitive personal and financial data, such as names, email addresses, and credit and debit card information."
"When a data breach occurs, it is essential that customers be immediately notified about whether and to what extent their personal and financial information has been compromised I am concerned that PlayStation Network users' personal and financial information may have been inappropriately accessed by a third party," Blumenthal wrote in the letter. "Compounding this concern is the troubling lack of notification from Sony about the nature of the data breach. Although the breach occurred nearly a week ago, Sony has not notified customers of the intrusion, or provided information that is vital to allowing individuals to protect themselves from identity theft, such as informing users whether their personal or financial information may have been compromised."
Blumenthal called for Sony to provide PlayStation Network users with financial data security services, including free access to credit reporting services for two years, the costs of which should be borne by the company. Additionally, he argued that affected individuals should be provided with sufficient insurance to protect them from the possible financial consequences of identity theft.