If a week, as Harold Wilson famously observed, is a long time in politics, it sure as hell is in gaming.
In just seven days, what began as frustration at not being able to play online has unravelled into an unprecedented crisis in which tens of millions of users' personal data and – possibly – banking details have been compromised.
The technical issues of how, why and what happens next take some time to sift through before the full facts become clear. But if one thing is certain at this stage, Sony has made a terrible hash of its communications strategy throughout, leaving consumers confused, worried and angry – and making a bad situation even worse.
For seven days the only source for official updates has been the PlayStation Blog, with – up until yesterday evening's shock admission – a hopelessly irregular trickle of short statements that served only to compound concerns while allowing the issue to spiral out of Sony's control.
How many of the claimed 77 million PSN account holders are even aware that a PlayStation blog or Twitter feed exists? For those that were, hopes for clarity and reassurance were soon dashed.
Sony's first official statement on the outage came on 20th April. "We're aware certain functions of PlayStation Network are down," announced Patrick Seybold, Sony's senior director for corporate communications and social media, via the blog. "We will report back here as soon as we can with more information. Thank you for your patience."
"A begrudging acknowledgement of a security breach, but nothing more."
Then nothing for two days. As Sony went to ground, the Internet duly stepped up to fill the void with a torrent of speculation over what had happened.
Finally, late on the 22nd, up popped Patrick to inform blog readers: "An external intrusion on our system has affected our PlayStation Network and Qriocity services."
Note the awkward, euphemistic wording to avoid the dreaded "H" word. A begrudging acknowledgement of a security breach, but nothing more.
24 hours later and another vague update in which Sony revealed it was "re-building our system to further strengthen our network infrastructure. Though this task is time-consuming, we decided it was worth the time necessary to provide the system with additional security".
OK. "Further strengthen". "Additional security". Sensible, appropriate measures after an attack, but how and what? And more to the point, gamers chorused: when?
Fresh silence until the 25th, and – now five days since PSN and Qriocity went down – we are told: "I don't have an update or timeframe to share at this point in time."
No details, no timeframe and – critically – no hint of what was to come. A further 24 hours of silence and then the bombshell. User accounts had been compromised. Which Sony "discovered" had been going on since 17th April.
That means it took Sony an astonishing nine days from the initial attack (which it says it didn't notice until the 19th) to inform its customers that their personal and banking details could have been nicked.
After days of urging "patience", an out-of-blue admission of stolen data and panic warnings of "identity theft" and "financial loss".
The fallout from this revelation has reverberated around the globe, making PlayStation front page news for all the wrong reasons. And whether fair or not, the impression left is one of a company that has failed to come clean soon enough; that cannot be trusted to handle sensitive information; and that, in the middle of a crisis, fails badly to communicate with its customer base.
After fumbling the issue while the flow of information was within its control, the story now risks developing too quickly for Sony to keep up. While it ponders its next move, security experts, credit agencies, banks, public watchdogs, journalists and, of course, consumers line up to talk to the media about the severity of a situation in which so much is still unknown.
When did Sony first realise users' personal data had been compromised? If the company takes "information protection very seriously", why weren't the "additional measures" it is promising already in place?
What was the original security arrangement? Will the rebuilt system become more secure than is standard or simply brought in line with comparable services? Were, as speculation suggests, details held in unencrypted form? If so, why?
Who is the "outside help" brought in and at what point? If there is indeed a "clear path" for restoring "some services within a week", which ones?
"Some are already calling this Sony's "Deepwater Horizon moment"."
It's important not to lose sight of the fact that the real villains here are the hackers, depriving gamers of access to PSN and causing major harm to Sony's reputation.
And I must spare a thought for PlayStation's UK PR team, which has endured a torrid few days while forced to rely on US-led updates to filter through – a strategy that has so far proved calamitous for the company.
Some are already calling this Sony's "Deepwater Horizon moment", in reference to the oil rig explosion and the subsequent handling of it by BP that caused the company's reputation so much damage.
Even Max Clifford wouldn't be able to put a positive spin on the present PSN fiasco. But Sony's response so far betrays a worrying short-sightedness over how information – and, equally, misinformation – spreads in the age of the social network.
Treating the issue as a one-way conversation meant Sony was never in control of it. And failing to prepare users, after a week of uncertainty, for last night's startling admission only served to magnify its negative impact.
All of which means, when Sony attempts to clarify the reasons for the lack of communication, as far as the momentum of the story is concerned, it's too little, too late.
Technical problems aside, Sony now has a mountain to climb to rebuild trust in its online services once they're switched back on. And that process can only begin once it starts engaging openly and transparently with the millions of PlayStation fans still wondering exactly how this happened.