The encyclopedia · Legal & Compliance · Strategic decision · 2005–2007
Sony BMG put rootkits on 22 million music CDs and paid millions in settlements
Sony BMG secretly installed rootkit DRM on 22 million CDs. The software created security holes for malware. Lawsuits cost millions.
Sony BMG · Sony · Bertelsmann · 2005-10-31
What happened
In 2005, Sony BMG distributed approximately 22 million music CDs containing copy-protection software that used rootkit techniques to hide its files. The software — Extended Copy Protection (XCP) on about 2 million CDs and MediaMax on the remaining 20 million — installed itself on Windows when the CD was played, ran constantly in the background, and reported user listening habits. Winternals researcher Mark Russinovich discovered the rootkit and published his findings on October 31, 2005.
The rootkit created security vulnerabilities that were quickly exploited by malware, worms, and trojans. US-CERT, part of the Department of Homeland Security, issued an advisory calling the software a security threat. Sony BMG initially denied the rootkit was harmful, then released a flawed uninstaller that introduced additional security holes. The company recalled unsold CDs on November 15, 2005, but investigators found affected CDs still on store shelves weeks later.
Texas Attorney General Greg Abbott sued Sony BMG under the state's 2005 spyware law. Additional class-action suits were filed in New York and California, and the Electronic Frontier Foundation pursued its own action. The Federal Trade Commission charged Sony BMG with unfair and deceptive business practices. Sony BMG settled with Texas for $750,000 in legal fees plus up to $150 per damaged computer, and agreed to a class-action settlement providing compensation to affected consumers. The company suspended CD copy-protection in early 2007.
Why it happened
- Sony BMG installed rootkit software on 22 million CDs that hid itself from the operating system, ran constantly, and reported user listening habits — without adequately informing customers.
- The rootkit created security holes that were exploited by malware, worms, and trojans, turning Sony's anti-piracy measure into a public security threat.
- Sony BMG initially denied the rootkits were harmful and released a flawed uninstaller that introduced new security vulnerabilities, prolonging the scandal.
- The company faced lawsuits from Texas, California, New York, the EFF, and the FTC — a legal bill that dwarfed the piracy losses the DRM was meant to prevent.
The lesson
Treating your customers as adversaries in the name of copy protection creates adversaries out of your customers, your regulators, and the security researchers who find your backdoors.
Sources
- Sony BMG copy protection rootkit scandal — Wikipedia
- FTC — Sony BMG Settles FTC Charges (January 2007)
spotted an error? The club wants to know.
More like this
Twitter reused 2FA phone numbers for ads — a $150M FTC penalty
Anthropic settled a $1.5B copyright lawsuit — the price of training AI on pirated books
Ross Intelligence trained its AI on Westlaw's headnotes — a court called it theft
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.