Path of Exile 2 Confirms Data Breach
Path of Exile 2 Developer Confirms Data Breach: Player Information Compromised
Grinding Gear Games, the developer behind Path of Exile 2, has confirmed a data breach affecting a significant number of player accounts. The breach, discovered the week of January 6th, 2025, stemmed from a compromised developer account linked to Steam.
Compromised Data:
The breach exposed sensitive player information, including email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the risk of credential stuffing remains due to the exposure of email addresses. In some cases, transaction and private message histories were also viewed.
The Breach:
A malicious actor gained unauthorized access to a developer's admin account, granting them access to the Path of Exile 2 customer support portal. This access allowed the attacker to view account information and, in 66 instances, even reset passwords. A subsequently discovered bug allowed the deletion of logs tracking these changes, though this bug has since been patched.
Security Enhancements:
In response, Grinding Gear Games has implemented several security measures:
- Disabled the linking of third-party accounts (like Steam) to staff accounts.
- Substantially tightened IP address restrictions on admin accounts.
- Mandated password resets for all admin accounts.
Community Reaction:
Player reaction has been varied, with some commending the developer's transparency while others advocate for the implementation of two-factor authentication (2FA) for improved account security. Concerns regarding endgame difficulty and content updates have also been expressed.
Conclusion:
This incident highlights the ongoing challenges of maintaining robust online security. While Grinding Gear Games has taken steps to address the immediate threat and prevent future breaches, the incident underscores the importance of strong security practices and the need for continuous vigilance in the gaming industry. The company's response, while welcomed by some, has also sparked discussions around broader security improvements and the need for features like 2FA to further protect player data.
Latest Articles