Home > News > Data Breach Confirmed for Path of Exile 2

Data Breach Confirmed for Path of Exile 2

By EmilyApr 11,2025

Data Breach Confirmed for Path of Exile 2

Summary

  • Path of Exile 2 developer Grinding Gear Games has confirmed a data breach that occurred during the week of January 6, 2025.
  • The breach was initiated by unauthorized access to a developer's account, which was linked to Steam.
  • The compromised data includes player email addresses, Steam IDs, IP addresses, and other personal information.

Grinding Gear Games has acknowledged a security breach in Path of Exile 2, stemming from the unauthorized access to a developer's administrative account. This account was connected to Steam, leading to the exposure of sensitive player data. In response, the developers have outlined comprehensive measures to bolster the security of their admin accounts, aiming to prevent future breaches in both Path of Exile 2 and its predecessor, which share a unified login system.

Since its early access launch in December 2024, Path of Exile 2 has sustained a robust player community, thanks to regular updates and open communication from Grinding Gear Games. A recent update enhanced the game's performance on PlayStation 5, addressing issues related to monsters, skills, and damage. With the next major patch on the horizon, the developers have taken this opportunity to address the data breach before players dive into the new content.

The official Path of Exile 2 forum was updated with a notice detailing the breach, which was discovered during the week of January 6, 2025. The compromised account belonged to a developer and had administrative access to the website, allowing the unauthorized user to utilize tools typically reserved for the customer support team. Immediate action was taken to lock the account and enforce password resets across all admin accounts. Further investigation revealed that the breach originated from an old Steam account used for testing, which inadvertently provided the attacker with access to the developer's Path of Exile account.

Path of Exile 2 Developer Grinding Gear Games Confirms Data Breach Involving Compromised Staff Account

  • The breach affected a "significant number" of accounts, compromising email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.

The attacker managed to set random passwords on 66 accounts and exploited a bug to delete logs tracking changes. Although this bug has been rectified and does not affect other support actions, it enabled the attacker to access account information for numerous accounts via the developer portal. While passwords and password hashes were not directly accessible through the customer service portal, Grinding Gear Games noted the potential for the attacker to use compromised email addresses to circumvent region locking on Steam-linked accounts. Additionally, the attacker could view transaction and private message histories. To mitigate future risks, Grinding Gear Games has implemented stricter IP restrictions and prohibited the linking of third-party accounts to staff accounts.

The community's reaction to the breach has been varied. Some players have commended the developers for their transparency, while others advocate for the addition of two-factor authentication to Path of Exile 2 accounts. There is a clear demand from a significant portion of the player base for enhanced security measures, alongside improvements to in-game content and adjustments to the endgame difficulty in Path of Exile 2.

Previous article:Construction Simulator 4: Master Building With Expert Tips Next article:Prickle Launches Minimalist Hedgehog Puzzle Game