Home > News > Path of Exile 2 Confirms Data Breach, Underscoring Cyber Risks

Path of Exile 2 Confirms Data Breach, Underscoring Cyber Risks

Feb 19,25(3 months ago)
Path of Exile 2 Confirms Data Breach, Underscoring Cyber Risks

Path of Exile 2 Developer Acknowledges Data Breach Following Staff Account Compromise

Grinding Gear Games, the developer behind Path of Exile 2, has confirmed a data breach impacting a significant number of player accounts. The breach, discovered the week of January 6, 2025, stemmed from a compromised developer account linked to Steam.

Compromised Information: The breach exposed sensitive player data, including email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible via the compromised portal, Grinding Gear Games acknowledges the potential for the attacker to utilize compromised email addresses and publicly available password lists to circumvent region locks on Steam-linked accounts. In some cases, transaction and private message histories were also viewed.

The Breach's Origin: An attacker gained access to a developer's admin account, exploiting a now-patched vulnerability that allowed log deletion. This access granted the attacker the ability to view player information through the developer portal. Sixty-six accounts had their passwords arbitrarily changed by the attacker.

Grinding Gear Games' Response: The developer immediately took action, locking the compromised account and mandating password resets for all admin accounts. A subsequent investigation revealed the compromised account was linked to an old, inactive Steam account used for testing purposes. To prevent future incidents, the company has implemented stricter IP restrictions and prohibited linking third-party accounts to staff accounts.

Community Reaction: Player response has been varied. While some commend Grinding Gear Games' transparency, others advocate for the implementation of two-factor authentication for enhanced account security. The incident highlights ongoing player concerns regarding security measures and desired improvements to in-game content and endgame difficulty.

Summary of Key Points:

  • Date of Discovery: Week of January 6, 2025.
  • Cause: Compromised developer account linked to Steam.
  • Data Compromised: Email addresses, Steam IDs, IP addresses, shipping addresses, unlock codes, and (in some cases) transaction and private message histories.
  • Grinding Gear Games' Actions: Account lockdown, password resets, enhanced security measures (stricter IP restrictions, prohibition of third-party account linking to staff accounts), and bug fixes.
Discover
  • Weather Radar by WeatherBug
    Weather Radar by WeatherBug
    Get the most accurate local forecast, storm radar, maps, and more with WeatherBug, your go-to source for reliable weather information. With over 20 map layers, including Radar and Severe Storm Risk, WeatherBug delivers comprehensive weather insights to keep you safe. From real-time lightning to real
  • MSNBC News Live On MSNBC
    MSNBC News Live On MSNBC
    Experience the latest news and updates from MSNBC anytime, anywhere with the top-rated MSNBC News Live On MSNBC app. Stay informed with live streaming of popular shows like Rachel Maddow and Morning Joe, ensuring you never miss out on critical updates. With a variety of news categories including pol
  • Citas Honduras
    Citas Honduras
    Honduras Dating is a premier dating platform designed specifically for singles in Honduras who are eager to forge meaningful relationships. The platform allows users to create detailed profiles showcasing their interests, utilize advanced search filters to find ideal matches, and engage in private m
  • Merge Master Superhero Battle Mod
    Merge Master Superhero Battle Mod
    Get ready to unleash your inner hero with the Merge Master Superhero Battle Mod! This exciting app lets you dive into the thrilling world of merging and battling with your very own team of superheroes. Collect and nurture your superheroes, strategically positioning them to dominate in epic battles a
  • FVH - Free Video Hider
    FVH - Free Video Hider
    Discover the ultimate privacy tool with FVH - Free Video Hider, designed to shield your most private videos from unwanted eyes. With a single click, you can effortlessly conceal your personal videos, ensuring they remain hidden from your gallery. No longer worry about accidental discoveries of your
  • Código Verde
    Código Verde
    Discover the exciting world of Green Code, an innovative educational app designed to boost computational thinking among children and young adults aged 10 and up. Brought to you by the Ministry of Information and Communications Technologies in collaboration with the British Council under the Colombia