
Summary
- Path of Exile 2 developer Grinding Gear Games confirmed a data breach occurred during the week of January 6, 2025, due to a compromised developer's account linked to Steam.
- The breach exposed player email addresses, Steam IDs, IP addresses, and other sensitive information.
Grinding Gear Games disclosed a significant data breach in Path of Exile 2, triggered by the unauthorized access to a developer's admin account connected to Steam. In response, the developers are taking immediate action to bolster the security of their admin accounts, aiming to prevent future breaches across both Path of Exile 2 and its original version, which share a common login system.
Since its early access launch in December 2024, Path of Exile 2 has sustained a robust player base, driven by regular updates and transparent communication from Grinding Gear Games. A recent update enhanced the game's performance on the PlayStation 5 and addressed issues related to monsters, skills, and damage. As the next major patch approaches, the developers are addressing the data breach to ensure player confidence before the release of new content.
Grinding Gear Games updated their official Path of Exile 2 forum on the week of January 6, 2025, to inform the community about the breach. The compromised account, belonging to a developer, granted the attacker access to customer support tools. The developers promptly secured the account and enforced password resets across all admin accounts. Further investigation revealed that the breach stemmed from an old Steam test account linked to the developer's Path of Exile account, which did not contain personal information or purchases but allowed access to the developer portal.
Path of Exile 2 Developer Grinding Gear Games Confirms Data Breach Involving Compromised Staff Account
- The breach affected a "significant number" of accounts, compromising email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.
The attacker exploited the compromised account to set random passwords on 66 accounts and deleted logs tracking these changes due to a now-fixed bug. While no passwords or password hashes were accessible through the customer service portal, the attacker could potentially bypass region locking by matching email addresses with compromised passwords from other sources. Additionally, some account transaction and private message histories were viewed. To prevent future incidents, Grinding Gear Games has severed links between third-party accounts and staff accounts, implementing stricter IP restrictions.
The community has responded variably to the breach. Some players appreciate the developers' transparency, while others demand the implementation of two-factor authentication for Path of Exile 2 accounts. There is a consensus among players for enhanced security measures, alongside requests for improvements in in-game content and adjustments to endgame difficulty.