Home >  News >  Path of Exile 2 Confirms Data Breach

Path of Exile 2 Confirms Data Breach

by Sophia Feb 20,2025

Path of Exile 2 Confirms Data Breach

Path of Exile 2 Developer Confirms Data Breach: Player Information Compromised

Grinding Gear Games, the developer behind Path of Exile 2, has confirmed a data breach affecting a significant number of player accounts. The breach, discovered the week of January 6, 2025, stemmed from a compromised developer account linked to Steam.

Compromised Data: The breach exposed sensitive player information, including email addresses, Steam IDs, IP addresses, and in some cases, shipping addresses and unlock codes. While passwords and password hashes were not directly accessible, the risk of credential stuffing (using compromised credentials from other sites) remains a concern. For a subset of accounts, the attacker accessed transaction and private message histories.

Root Cause and Remediation: The breach originated from a developer's admin account, used for testing purposes and linked to an old Steam account. This allowed the attacker access to the developer portal and player account data. Grinding Gear Games has since implemented several security measures, including disabling the linking of third-party accounts to staff accounts and significantly tightening IP restrictions. A bug allowing the deletion of activity logs has also been patched.

Developer Response and Community Reaction: Grinding Gear Games has been praised for its transparency in disclosing the breach. However, the incident has sparked calls for enhanced security measures, particularly the implementation of two-factor authentication for player accounts. The community also expressed concerns regarding endgame difficulty and desires for further content updates.

In summary: The Path of Exile 2 data breach highlights the importance of robust security practices, even for established game developers. While Grinding Gear Games has taken steps to address the immediate threat, the incident underscores the ongoing need for improved security measures and ongoing dialogue with the player community. Players are advised to remain vigilant and monitor their accounts for any suspicious activity.

Trending Games More >