Path of Exile 2 Developer Confirms Data Breach: Player Information Compromised
Grinding Gear Games, the developer behind Path of Exile 2, recently disclosed a data breach affecting a significant number of player accounts. The breach, discovered the week of January 6th, 2025, stemmed from a compromised developer account linked to Steam.
The Breach: A malicious actor gained unauthorized access to a developer's admin account, granting them access to the Path of Exile 2 support portal. This resulted in the compromise of sensitive player data, including email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the potential for the attacker to utilize compromised email addresses against known password lists to circumvent regional account restrictions remains a concern. In some cases, transaction and private message histories were also viewed.
Impact and Response: Grinding Gear Games immediately took action, locking the compromised account and initiating password resets for all admin accounts. A subsequent investigation revealed the breach originated from an old, test-only Steam account linked to the developer's Path of Exile account. The developer's Steam account itself contained no sensitive purchase or personal information. The company has since implemented enhanced security measures, including stricter IP restrictions and the prohibition of linking third-party accounts to staff accounts. A bug that allowed the deletion of logs related to account changes was also identified and patched. The attacker also randomly changed passwords on 66 accounts.
Community Reaction and Future Steps: Player reactions have been varied, with some commending the developer's transparency while others advocate for the implementation of two-factor authentication. Many players also expressed a desire for further security improvements and adjustments to endgame difficulty and in-game content. Grinding Gear Games has acknowledged these concerns and is actively working to strengthen account security.
Summary of Compromised Data:
- Email addresses
- Steam IDs
- IP addresses
- Shipping addresses
- Unlock codes
- (In some cases) Transaction history
- (In some cases) Private messages from Grinding Gear Games staff
(Replace https://images.yfzfw.complaceholder_image.jpg with an appropriate image if available.)