Path of Exile 2 Developer Confirms Data Breach Affecting Player Accounts
Grinding Gear Games, the developer behind Path of Exile 2, has confirmed a data breach that occurred during the week of January 6, 2025. The breach stemmed from a compromised developer account linked to Steam.
The Breach: A developer's account with administrative access was compromised, granting unauthorized access to tools used by the customer support team. This resulted in the exposure of sensitive player data for a substantial number of accounts.
Compromised Information: The compromised data includes email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the attacker potentially used compromised email addresses to attempt password resets and circumvent regional account restrictions. In some cases, transaction and private message histories were also viewed.
Grinding Gear Games' Response: The developer immediately took action, including locking the compromised account, implementing mandatory password resets for all admin accounts, and launching a thorough investigation. The investigation revealed a vulnerability that allowed the attacker to delete logs, which has since been patched. To prevent future breaches, third-party account linking to staff accounts has been disabled, and IP restrictions have been significantly tightened.
Community Reaction: The community's response is varied. While some players appreciate the developer's transparency, others are demanding the implementation of two-factor authentication for enhanced security. Concerns regarding endgame difficulty and overall game content are also being voiced.
Summary of Key Points:
The incident highlights the importance of robust security measures in online gaming and the ongoing need for developers to adapt to evolving threats.