
Path of Exile 2 Developer, Grinding Gear Games, Addresses Data Breach
Grinding Gear Games recently disclosed a data breach affecting Path of Exile 2 players. The breach, discovered the week of January 6th, 2025, stemmed from a compromised developer account linked to Steam. This unauthorized access granted the perpetrator access to sensitive player data.
Compromised Information:
A significant number of accounts were impacted, with the breach exposing email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the potential for the attacker to leverage compromised email addresses against known password lists to circumvent regional restrictions exists. Some accounts also had their transaction and private message histories viewed.
The Breach's Origin:
The breach originated from a developer's compromised admin account, providing access to tools used by the Path of Exile 2 customer support team. The compromised account was linked to an old Steam account used for testing purposes. While this Steam account lacked personal information or purchase history, its connection to the developer's Path of Exile account allowed access to the developer portal and subsequent data compromise. A bug allowing the deletion of relevant logs was also exploited. This bug, however, has since been patched.
Grinding Gear Games' Response:
Following the discovery, Grinding Gear Games immediately took action: the compromised account was locked, all admin accounts were forced to reset their passwords, and a thorough investigation was launched. To prevent future incidents, the company has implemented stricter IP restrictions and prohibited linking third-party accounts to staff accounts.
Community Reaction and Future Steps:
Player reactions have been varied, with some commending the developer's transparency while others advocate for the implementation of two-factor authentication. Many players also expressed a desire for enhanced security measures and improvements to in-game content and endgame difficulty.