Home News "Path of Exile 2 Confirms Data Breach Incident"

"Path of Exile 2 Confirms Data Breach Incident"

by Liam Apr 13,2025

"Path of Exile 2 Confirms Data Breach Incident"

Summary

  • Path of Exile 2 developer Grinding Gear Games confirmed a data breach occurred during the week of January 6, 2025, caused by a user gaining access to a developer's account linked to Steam.
  • Compromised data included player email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes.
  • Grinding Gear Games has outlined plans to enhance security measures to prevent future breaches.

Grinding Gear Games recently confirmed that Path of Exile 2 suffered a data breach after a developer's admin account was compromised. The breach occurred because the compromised account was linked to an old Steam account used for testing purposes. This allowed the attacker to access the developer portal and affect other accounts. The developers took immediate action by locking the compromised account and resetting passwords for all other admin accounts.

Since its early access release in December 2024, Path of Exile 2 has maintained a strong player base, thanks to ongoing updates and clear communication from Grinding Gear Games. A recent update improved performance on the PlayStation 5 and addressed issues with monsters, skills, and damage. With a major patch on the horizon, the developers addressed the data breach to keep players informed before they dive back into the game.

The official Path of Exile 2 forum was updated to inform the community about the breach discovered on the week of January 6, 2025. The compromised account belonged to a developer and provided access to customer support tools. The investigation revealed that the attacker could manipulate 66 accounts, setting random passwords and deleting logs due to a now-fixed bug. This breach compromised email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes for a "significant number" of accounts.

Although no passwords or password hashes were accessible through the customer service portal, Grinding Gear Games noted the potential for attackers to use compromised email addresses to bypass region locking on Steam accounts. Some affected accounts had their transaction and private message histories viewed by the attacker. To prevent future breaches, Grinding Gear Games has implemented stricter security measures, including prohibiting third-party account linking for staff accounts and enforcing more stringent IP restrictions.

The community's response to the breach has been varied. While some players appreciate the transparency, others are advocating for the addition of two-factor authentication to enhance account security. There's also a call for improvements in in-game content and adjustments to the endgame difficulty in Path of Exile 2.

Latest Articles More+
  • 13 2025-04
    M3GAN Re-Release: 'Second Screen' and Live Chatbot Added

    Top horror studio Blumhouse is gearing up to celebrate its 15th anniversary in style by bringing the 2022 hit film M3GAN back to theaters. This move is timed perfectly ahead of the sequel's release and includes a limited theatrical engagement with some innovative, yet controversial, features that en

  • 13 2025-04
    The Valley of the Architects explores Liz’s journey through hidden ruins, now available on iOS

    Indie developer Whaleo has just launched an enthralling elevator-based puzzler, The Valley of the Architects, now available on iOS for $3.99. Step into the shoes of Liz, a fervent architectural writer, as she embarks on a gripping journey across Africa to unravel the mysteries left behind by the eni

  • 13 2025-04
    Hollow Knight: Silksong Dev Hints at Nintendo Switch 2 with Cake Image

    It's been six years since Team Cherry announced Hollow Knight: Silksong, the highly anticipated sequel to the 2017 Metroidvania masterpiece Hollow Knight. Over these years, fans have experienced a rollercoaster of anticipation with Silksong appearing and disappearing at various events. At one point,