It's kind of a fascinating look at how data is clumsily handled within corporations. I mean, how do they keep everything synced between the sheets that contain salaries/benefits, severance actions, etc.? (shudder)
It's kind of a fascinating look at how data is clumsily handled within corporations. I mean, how do they keep everything synced between the sheets that contain salaries/benefits, severance actions, etc.? (shudder)
Also, the Reddit thread which seems to have started the media firestorm was entitled, "I used to work for Sony Pictures. My friend still works there and sent me this. It's on every computer all over Sony Pictures nationwide." [2] (refers to this picture: https://imgur.com/qXNgFVz).
This leads me to believe that the attacker compromised most/all corporate desktops and exfiltrated data directly from those machines. No better place to get that spreadsheet than directly from the workstation of the employee who works on it daily!
[1]: http://www.bloomberg.com/news/2014-11-24/sony-corp-computers... [2]: https://www.reddit.com/r/hacking/comments/2n9zhv/i_used_to_w...
From my years working with at&t's payroll system, Export-to-csv out of SAP(www.sap.com) to be manually looked at and/or imported into some other program was very common. If at&t were the target of this whole mess, I'd assume the Windows 2000 machines running crystal reports(www.crystalreports.com/) got compromised; which would generate very sensitive payroll files.
Email, of course!