Home News Path of Exile 2 Confirms Data Breach

Path of Exile 2 Confirms Data Breach

by Amelia Apr 05,2025

Path of Exile 2 Confirms Data Breach

Summary

  • Path of Exile 2 developer Grinding Gear Games confirmed a data breach occurred during the week of January 6, 2025, due to a compromised developer's account linked to Steam.
  • The breach exposed player email addresses, Steam IDs, IP addresses, and other sensitive information.

Grinding Gear Games has acknowledged a significant data breach in Path of Exile 2, resulting from a compromised developer's admin account. This account, linked to an old Steam testing account, was exploited, leading to unauthorized access to the developer's tools typically used by the customer support team. In response, the developers swiftly locked the compromised account and enforced password resets across all admin accounts. Their investigation revealed that the breach allowed access to critical player data, including email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.

Following the early access launch of Path of Exile 2 in December 2024, the game has enjoyed a robust player base, supported by continuous updates and developer communication. Recent updates have enhanced performance on PlayStation 5 and addressed issues with monsters, skills, and damage. As the next major patch approaches, Grinding Gear Games has taken the opportunity to address the data breach, ensuring players are informed before diving into the new content.

The breach affected a significant number of accounts, with the attacker setting random passwords on 66 accounts and exploiting a bug to delete logs of their actions. Although this bug has since been fixed, it allowed the attacker to view sensitive account information. Importantly, no passwords or password hashes were accessible through the customer service portal. However, the attacker could potentially use compromised email addresses to bypass region locking on Steam-linked accounts. Some accounts also had their transaction and private message histories exposed.

To prevent future breaches, Grinding Gear Games has implemented stricter security measures, including prohibiting third-party account linking to staff accounts and enforcing more stringent IP restrictions. The community's reaction has been varied, with some commending the transparency of the developers, while others demand the addition of two-factor authentication to enhance account security. Players are also looking forward to further improvements in game content and adjustments to the endgame difficulty in Path of Exile 2.