Summary
- Grinding Gear Games, the developer of Path of Exile 2, confirmed a data breach occurring the week of January 6, 2025.
- The breach stemmed from a compromised developer account linked to Steam.
- Compromised data included player email addresses, Steam IDs, IP addresses, and other information.
Grinding Gear Games acknowledged a data breach affecting Path of Exile 2 resulting from a compromised developer admin account. The developers outlined steps to enhance the security of their admin accounts, preventing future breaches across both Path of Exile 2 and its predecessor (sharing a common account login).
Since its early access launch in December 2024, Path of Exile 2 has maintained a strong player base, fueled by consistent updates and developer communication. Recent updates addressed PlayStation 5 performance and various in-game issues (monsters, skills, damage). Grinding Gear Games proactively addressed the data breach before the release of the game's next major patch.
A notice on the official Path of Exile 2 forum confirmed Grinding Gear Games' awareness of the breach the week of January 6, 2025. A developer's website admin account was compromised, granting access to tools normally used by the customer support team. The account was immediately locked, and all other admin accounts underwent forced password resets. The investigation revealed the compromised account was linked to an old, test-only Steam account, providing the attacker sufficient information to gain access. While this Steam account lacked purchase or personal information, access to the developer's Path of Exile account allowed manipulation of other accounts via the developer portal.
Path of Exile 2 Developer Grinding Gear Games Confirms Data Breach Involving Compromised Staff Account
- The breach affected a "significant number" of accounts, compromising email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.
The attacker randomly set passwords on 66 accounts, exploiting a bug to delete logs tracking changes. Grinding Gear Games confirmed this bug, affecting only this specific action, has been fixed. The breach allowed access to account information for a "significant number" of accounts on the developer portal, exposing email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.
While passwords and password hashes were not directly accessible via the customer service portal, Grinding Gear Games acknowledged the possibility of the attacker cross-referencing email addresses with compromised password lists from other websites to circumvent region locking for Steam-linked Path of Exile 2 accounts. For some accounts, the attacker viewed transaction and private message history with Grinding Gear Games staff. To prevent future breaches, third-party account linking to staff accounts is prohibited, and IP restrictions have been significantly tightened.
Community reaction to the breach is mixed. While some praise the developers' transparency, others advocate for two-factor authentication for Path of Exile 2 accounts. A significant portion of the player base desires improved security, enhanced in-game content, and adjustments to endgame difficulty.