Shares of Sony Corp extended losses to trade down as much as 5.2 percent, hitting a one-month low on Thursday as investors worried over the widening impact of a massive leak of personal information of users of its PlayStation network.
Sony said on Tuesday that hackers had breached the network a week earlier, compromising confidential information including the names, addresses and possibly credit card data of 77 million users.
Experts say Sony could face legal action across the globe due to the incident.
The stock is now down more than 8 percent this week with investors nervous about the fall out of the data leak episode that plagued the company.
There is concern that loyal PlayStation gamers could ditch Sony in the wake of the data theft. The theft could cost the company more than $1.5 billion, or an average of $20 for each of the 77 million customers whose data was compromised, according to Ponemon, whose firm specializes in securing information on computer networks.
Security experts say that Sony needs to account for the loss of that business — as well as damage to its brand — when it tallies up the cost of dealing with the breach. Other costs include notifying customers of the attack and bringing in experts to cleanse its network.
In the United States, several members of Congress seized on the breach, in which hackers stole names, addresses and possibly credit card details from users of Sony’s PlayStation Network, to push for tougher laws protecting personal information.
The staff of a House of Representatives subcommittee were directed to investigate the hacking incident.
Attorneys general, who act as consumer advocates, had begun investigating the matter or reviewing it with staff in several states, including in Iowa, Connecticut, Florida and Massachusetts, according to their offices.
One U.S. class-action lawyer said he was considering filing a lawsuit on behalf of consumers as soon as this week.
In Britain, a government watchdog said it had already launched an investigation of the incident, which put credit card information at risk.
Britain’s Information Commissioner’s Office said it had contacted the company and was investigating whether Sony violated laws that require it to safeguard personal information. The commissioner’s investigation would depend in part on whether Sony stored user information in Britain.
While the Japanese electronics company pulled the plug on the PlayStation network on April 19, it did not tell the public about the hackers’ attack until Tuesday.
The disclosure sparked immediate outrage among gamers and revived criticisms of Japan’s corporate culture that plagued Toyota Motor during its huge automotive recall in 2010.
A Sony spokesman has said that after learning of the breach it took “several days of forensic investigation” before the company knew consumers’ data had been compromised.
Sony said on Tuesday that hackers accessed personal details on 77 million users.
“This is a huge data breach and the clients who have called are really upset, not just because of the data breach but it looks like Sony sat on information for as much as five days,” said Jay Edelson, an attorney at law firm Edelson McGuire.
Edelson’s firm specializes in class-action lawsuits over data breaches. He said he would decide in the next 24 hours whether to file a lawsuit.
Sony did not immediately return a call on Wednesday seeking a comment.
The incident could give momentum for tougher policies in the United States.
U.S. Representative Mary Bono Mack of California said she directed staff of the House subcommittee for commerce, manufacturing and trade, which she chairs, to begin investigating the matter to determine if hearings are needed.
Representative Bobby Rush of Illinois said he would reintroduce legislation that would require companies to have reasonable security measures and Senator Tom Carper of Delaware said he hoped for a comprehensive cyber security bill this year.
U.S. regulators could get involved as well. The Federal Trade Commission has been known to pursue companies that failed to safeguard consumer data. It could investigate if it determines Sony failed to tell its customers about the company’s privacy policies.
A spokeswoman for the agency declined to comment.
Sony reported the breach to the FBI’s cybercrimes unit in San Diego, which is investigating, a person familiar with the probe told Reuters. The person was not authorized to discuss the matter publicly.
Sony may come under the toughest scrutiny from non-U.S. regulators, which have stricter consumer privacy laws.
“European countries are going to go crazy and be all over this,” said Dan Burk, a professor at the University of California, Irvine School of Law. “They are absolutely obsessed about companies holding personal information.”
Burk said subscribers will need to show they suffered damages as a result of the hacking for a U.S. lawsuit to have legs.
“If it was just hacking for fun, then it’s going to be tough,” he said.