Summary
Grinding Gear Games, the developer behind Path of Exile 2, has confirmed a data breach that occurred during the week of January 6, 2025. The breach resulted from an unauthorized user gaining access to a developer's admin account linked to Steam. This incident compromised player data, including email addresses, Steam IDs, IP addresses, and other sensitive information.
The breach was initiated through a compromised developer's account, which had admin access to the game's website. Upon discovering the breach, Grinding Gear Games immediately secured the account and enforced password resets across all admin accounts. The investigation revealed that the compromised account was connected to an old Steam account used for testing, allowing the attacker to manipulate other accounts via the developer portal.
The breach affected a significant number of accounts, compromising additional data such as shipping addresses and unlock codes. The attacker was able to set random passwords on 66 accounts and exploit a bug to delete logs, though this bug has since been fixed. While passwords and password hashes were not accessible through the customer service portal, the attacker could potentially use email addresses to bypass region locking on Steam-linked accounts. They also accessed transaction and private message histories for some accounts.
In response to the breach, Grinding Gear Games has implemented stricter security measures, including prohibiting the linking of third-party accounts to staff accounts and enhancing IP restrictions. The community's reaction has been varied, with some commending the developers' transparency, while others demand the addition of two-factor authentication and improvements to in-game security and content.
Path of Exile 2, which entered early access in December 2024, continues to engage players with regular updates. Recent patches have enhanced performance on the PlayStation 5 and addressed issues related to monsters, skills, and damage. The next major patch is expected soon, and the developers are keen to address the data breach before players dive into the new content.
Grinding Gear Games is committed to preventing future breaches and improving the security of both Path of Exile 2 and its predecessor, which share a common account system.