Path of Exile 2 Developer, Grinding Gear Games, Addresses Data Breach
Grinding Gear Games recently disclosed a data breach affecting Path of Exile 2 players. The breach, discovered the week of January 6th, 2025, stemmed from a compromised developer account linked to Steam. This unauthorized access granted the perpetrator access to sensitive player data.
Compromised Information:
A significant number of accounts were affected, with the breach exposing email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. While passwords and password hashes were not directly accessible, the potential for the attacker to leverage compromised email addresses against publicly available password lists to circumvent region locks remains a concern. In some cases, transaction and private message histories were also viewed.
The Breach and its Aftermath:
The breach originated from a developer's compromised admin account, providing access to tools used by the Path of Exile 2 customer support team. Grinding Gear Games swiftly responded by locking the affected account and initiating password resets for all admin accounts. A subsequent investigation revealed the compromised account's link to an old, inactive Steam account used for testing purposes. Exploiting this connection, the attacker gained access to the developer portal.
A critical bug, since patched, allowed the attacker to delete logs tracking account modifications. However, Grinding Gear Games assures players that this vulnerability was isolated to this specific action and does not impact other support functions.
Security Enhancements:
In response to the breach, Grinding Gear Games has implemented several security measures to prevent future incidents. These include eliminating the ability to link third-party accounts to staff accounts and implementing significantly stricter IP restrictions.
Community Response and Future Steps:
The community's reaction has been varied, with some commending the developer's transparency while others advocate for the implementation of two-factor authentication. Many players also expressed desires for broader security improvements, enhanced in-game content, and endgame difficulty adjustments.
The incident highlights the ongoing challenges in maintaining online game security and the importance of robust security protocols. Grinding Gear Games' prompt response and proactive security enhancements are steps towards addressing these challenges and restoring player trust.