
Summary
Grinding Gear Games, the developer behind Path of Exile 2, confirmed a data breach occurred during the week of January 6, 2025. The breach stemmed from a compromised developer's account linked to Steam, resulting in the exposure of player email addresses, Steam IDs, IP addresses, and other sensitive information.
The breach was initiated when an attacker gained access to a developer's admin account, which provided access to the customer support tools used by Path of Exile 2. Upon discovery, the developers swiftly locked the compromised account and enforced password resets across all admin accounts. Further investigation revealed that the breach originated from an old Steam account used for testing, which did not contain personal information but allowed the attacker to manipulate the developer's Path of Exile account.
The data breach affected a "significant number" of accounts, compromising email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. The attacker was able to set random passwords on 66 accounts and delete logs due to a bug, which has since been fixed. While passwords and password hashes were not directly accessible, the attacker could potentially use the compromised email addresses to bypass region locks on Steam accounts linked to Path of Exile 2. Some accounts also had their transaction and private message histories exposed.
To prevent future breaches, Grinding Gear Games has implemented stricter security measures, including the prohibition of linking third-party accounts to staff accounts and enhanced IP restrictions. The community's response has been mixed, with some commending the transparency of the developers, while others are advocating for the addition of two-factor authentication to enhance account security.
Path of Exile 2, which saw its early access release in December 2024, continues to engage its player base with regular updates and open communication from Grinding Gear Games. The most recent update enhanced the game's performance on PlayStation 5 and addressed various in-game issues. The next major patch is expected soon, and the developers have addressed the data breach situation before players dive into the new content.
Players are also expressing a desire for further security enhancements, as well as improvements to in-game content and adjustments to the endgame difficulty in Path of Exile 2.