
Summary of the Path of Exile 2 Data Breach – January 2025
Grinding Gear Games (GGG) has confirmed a significant data breach affecting Path of Exile 2, occurring during the week of January 6, 2025. The incident stemmed from a compromised developer administrative account linked to Steam, which granted unauthorized access to internal tools used by the customer support team.
🔐 Key Details of the Breach:
- Root Cause: A legacy Steam test account — previously used for development and testing — was exploited. Though it had no purchases or personal data, its connection to a GGG developer account enabled full access to the internal developer portal.
- Attack Impact:
- 66 accounts had randomized passwords set by the attacker.
- A bug allowed deletion of activity logs, enabling the attacker to obscure their actions and view sensitive user data.
- Exposed data includes:
- Email addresses
- Steam IDs
- IP addresses
- Shipping addresses
- Unlock codes
- Transaction histories (for some)
- Private messages from GGG staff to users
⚠️ Note: Passwords and password hashes were not directly accessible via the portal. However, attackers may have attempted to match exposed emails with credentials from prior third-party breaches, potentially bypassing regional locks on Steam-linked accounts.
✅ GGG's Response & Security Improvements:
- Immediate action:
- The compromised admin account was locked.
- All admin accounts underwent mandatory password resets.
- System-wide fixes:
- Third-party accounts (e.g., Steam) can no longer be linked to staff accounts.
- Stricter IP restrictions now enforce access from approved networks only.
- The log deletion bug has been patched and confirmed to not affect other customer support functions.
- Preventive measures:
- Enhanced monitoring and access controls for developer portals.
- Full review of legacy accounts and testing infrastructure.
📢 Player Reaction & Community Feedback:
- Positive: Many players commended GGG for swift transparency, timely updates, and responsible disclosure.
- Concerns Raised:
- Widespread calls for mandatory two-factor authentication (2FA) for all player and staff accounts.
- Demand for stronger end-to-end encryption and privacy safeguards.
- Expectations for increased difficulty and polish in endgame content, especially post-breach as trust rebuilds.
🧩 Context: Why This Matters
- Path of Exile 2 launched in December 2024 with strong momentum, praised for its balance, performance, and development team communication.
- The game shares a unified login system with the original Path of Exile, meaning both player bases are potentially affected.
- The next major patch is imminent, and GGG intends to restore trust before releasing new content.
✅ Final Takeaways:
- This breach highlights the risks of legacy systems and outdated access protocols, even within well-managed studios.
- GGG has taken credible steps to mitigate damage and strengthen infrastructure.
- Player trust is fragile — while transparency is appreciated, future security improvements (especially 2FA and stricter account controls) are now essential.
🔐 Recommendation for Players:
- Change passwords immediately, especially if using the same credentials elsewhere.
- Enable 2FA as soon as it becomes available.
- Monitor accounts for suspicious activity, including unauthorized changes or login attempts.
Grinding Gear Games has reaffirmed its commitment to player safety, and while this incident is serious, it may serve as a catalyst for lasting improvements in security across the Path of Exile ecosystem.