Path of Exile 2 Developer Confirms Data Breach Affecting Player Information
Grinding Gear Games, the developer behind Path of Exile 2, recently disclosed a data breach that occurred during the week of January 6, 2025. The breach stemmed from a compromised developer account linked to Steam.
What Information Was Compromised?
A significant number of player accounts were affected. The compromised data includes email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the potential for the attacker to use compromised email addresses to access accounts via password lists from other breaches exists. In some instances, transaction history and private messages between players and Grinding Gear Games staff were also viewed.
How Did the Breach Occur?
The breach originated from a compromised developer admin account, granting the attacker access to tools used by Path of Exile 2's customer support team. The compromised account was linked to an old Steam account used for testing purposes. This connection provided the attacker with sufficient information to gain control of the account. A bug, since patched, allowed the deletion of logs tracking account modifications.
Grinding Gear Games' Response:
Following the discovery, Grinding Gear Games immediately took action:
- Locked the compromised account.
- Enforced password resets for all admin accounts.
- Launched a thorough investigation.
- Implemented stricter security measures, including eliminating third-party account linking for staff accounts and significantly tightening IP restrictions.
Community Reaction:
The community's response has been varied. While some players appreciate the developer's transparency, others are advocating for the implementation of two-factor authentication for enhanced security. Many players also expressed concerns regarding the game's security and called for improvements to in-game content and endgame difficulty adjustments.
Moving Forward:
Grinding Gear Games is committed to improving the security of its systems to prevent future breaches. The company's proactive response and transparency are noteworthy, however, the incident highlights the ongoing need for robust security measures in online gaming.