Skip to main content

How did HBO get hacked? A cyber security expert has two theories

game of thrones
Helen Sloan/HBO
Hackers recently absconded with 1.5 terabytes of data from HBO, and have since leaked unaired episodes of Ballers, Room 104, and Game of ThronesHBO says it has been looking into the hack since it was discovered, but few conclusive details are known. So Digital Trends sought answers; we asked a cybersecurity expert exactly how the HBO hack could have happened.

The answers aren’t pretty.

Roderick Jones is the founder of cybersecurity and privacy firm Rubica, and has been involved in cybersecurity for more than 15 years. Before he was helping Ashton Kutcher keep his data secure, he was a member of Scotland Yard’s Special Branch focusing on international counterterrorism. The cyberattacks he dealt with during his time on Special Branch are classified, but Jones does say he was involved with protecting a prominent British cabinet member.

Roderick Jones Image used with permission by copyright holder

“The entertainment industry is probably five or six years behind where it needs to be,” Jones told us. He claims one movie studio had no cybersecurity before he helped out, following the massive Sony Pictures hack in 2014. The damage these hacks can cause are no joke — but the entertainment industry’s security is laughable.

Jones says hackers are usually in a system for months and believes the HBO situation may have followed the same pattern. Here’s how the biggest hack in HBO history probably happened.

H-B-Old

Jones’s primary theory: The entire hack was possible because HBO uses old tech to house its content. “The Wannacry attack, the ransomware that kind of shut down the health service in Britain? That was targeted at an old Windows system,” Jones said. “That has created a vulnerability for HBO. I would say that’s probably a certainty, because that’s where the weaknesses are.”

“The entertainment industry is probably five or six years behind where it needs to be.”

Windows has been a gateway for hackers to enter the entertainment industry’s computer systems as of late. The malware used in the infamous 2014 hack of Sony Pictures targeted and manipulated Windows management tools.

And Netflix lost 10 episodes from Orange Is The New Black‘s fifth season this year because the episodes were on servers running Windows 7. Larson Studios, the post-production company that was hacked, claims the perps weren’t even looking for the show, just computers running Windows.

After the first four episodes of Game of Thrones’ fifth season leaked before the season premiere in 2015, HBO announced it would have critics stream advance episodes online, instead of the company sending DVDs. Stopping opportunistic TV critics is one thing, but preventing sophisticated hackers from entering your system is more complicated for entertainment companies.

Image used with permission by copyright holder

“People think you can just flick a switch and say ‘oh, I’ll have cybersecurity.’ It just doesn’t work like that, because the machines they have running all of this content are going to be legacy systems. You just can’t do it overnight,” said Jones.

This is when things could get personal.

If it wasn’t Windows, it was this

Jones’s secondary theory is the hackers targeted individual employees. Even if HBO keeps all of its files and internal documents behind heavily encrypted security, it likely doesn’t extend that level of security to each individual employee.

The damage these hacks can cause are no joke, yet the entertainment industry’s security is laughable.

“If you’re a senior executive at one of these companies you probably have some security when you’re sitting in the office at the company. But not when you go home,” Jones asserted. “The hackers understand, ‘I’ll just wait for you to go home. Or I’ll wait until you get a cup of coffee from around the corner of the movie studio.'”

This method of attack could be the culprit; Variety reported hackers appear to have accessed the personal info of an HBO senior executive. Some of the information stolen may have given the hackers access to the executive’s work email, according to reports.

Jones said that very access could do HBO exponentially worse damage than leaked Game of Thrones episodes. “The financial damage is not through leaked episodes of Games of Thrones. It’s through details, emails between staff, all of the mechanics of the business.”

Trouble ahead

Verizon acquired Yahoo earlier this year for $350 million less than originally reported, following a disclosure by Yahoo that 32 million email accounts were hacked. AT&T agreed to acquire HBO parent company Time Warner for $85.4 billion in October 2016. With a Department of Justice investigation slowing the deal’s finalization, this hack could lead to AT&T lowering its offer or even potentially walking away from the deal. Entertainment deals are big business, in other words — and hacking is having a big effect on them.

Sony had 200 gigabytes of data stolen in 2014, and thousands of incriminating emails were released, including racially insensitive messages from Amy Pascal, co-chair of Sony Pictures Entertainment. Pascal resigned as head of Sony Pictures shortly after the emails became public. This time, hackers have obtained nearly six times as much data from HBO and are preparing to leak information every week.

If history repeats itself, HBO may never be the same again. Winter really is here.

Keith Nelson Jr.
Former Digital Trends Contributor
Keith Nelson Jr is a music/tech journalist making big pictures by connecting dots. Born and raised in Brooklyn, NY he…
Game of Thrones: How George R. R. Martin’s world can expand in animation
Young Princess Rhaenyra with her dragon Syrax looming behind her.

The recent Warner Bros. Discovery merger seems to have added a layer of tense unpredictability regarding the state of WB's IPs, but it seems that writer George R. R. Martin's Game of Thrones world will stay the course with the upcoming House of the Dragon around the corner.

It would be bizarre if it didn't, as it is HBO's most historic TV series and proved to be a cultural phenomenon in the process. And with reports of many spinoffs in the works, the network should look to animation as another worthy avenue to explore. Per those reports, there are at least some such projects already in development, and taking advantage of animation's newfound appreciation could prove to be something more than worth doubling down on.
Exploring uncharted territory
House of the Dragon | Official Trailer | HBO Max

Read more
HBO Max’s Hacks season 2 teaser is testing out new material
Hannah Einbinder and Jean Smart in Hacks.

The first season of Hacks quickly became one of the most popular original comedy series on HBO Max last year. Audiences just couldn't resist the two lead characters, Deborah Vance (Jean Smart) and Ava Daniels (Hannah Einbinder). On paper, the two women have little in common beyond comedic chops. However, Deborah badly needed new jokes to freshen up her Las Vegas comedy act while Ava was haunted by an insensitive tweet she wrote years before that nearly destroyed her Hollywood dreams. But as Deborah's new comedy writer, Ava has a chance to prove herself again and put the controversy behind her.

The first teaser trailer for Hacks season 2 has arrived, and it shows us the ups and downs of Deborah and Ava's relationship. There are times when Deborah acts like Ava's best friend in the world, but as the trailer also shows, there are moments when Deborah's wrath toward Ava is intense and frightening.

Read more
Elden Ring is ripe for an HBO Max animated series
Elden Ring still of the Tarnished fighting the dragon Agheel on horseback.

FromSoftware's latest dark-fantasy epic Elden Ring has been out for less than two months, but it's already proven to be another landmark video game in the medium. The way it transcends what's been considered the norm in games of its genre is akin to the impact the likes of Super Mario 64, The Elder Scrolls V: Skyrim, and The Legend of Zelda: Breath of the Wild had at the time of their releases. With Elden Ring, the game takes FromSoftware's past Souls-like titles like Dark Souls III, Bloodborne, and Sekiro: Shadows Die Twice and creates an ambitious open-world action RPG by blending them with the rewarding level of exploration and traversal in Skyrim and Breath of the Wild.

However, as acclaimed as this new IP is as a game, it has boundless potential outside of the format as well. It seems that Bandai Namco recognizes that too, as a press release from the Japanese video game publisher stated that "We will continue to expand Elden Ring, not only as a game but using all parts of the IP (such as characters) in various ways, so please look forward to it." Even before this, it could've been seen as foreshadowing ever since it was announced that A Song of Ice and Fire author George R. R. Martin helped write the foundational lore for Elden Ring's world of the Lands Between. With the game's marketing, Martin's ties to HBO for Game of Thrones projects, and the grand scope of the game's lore, Elden Ring makes a strong case for making an HBO Max animated series its next site of grace.
Animation is the blueprint for gaming adaptations

Read more