
Summary of the Path of Exile 2 Data Breach – January 2025
Overview: Grinding Gear Games (GGG) confirmed a significant data breach affecting Path of Exile 2 during the week of January 6, 2025. The incident stemmed from a compromised developer administrative account linked to Steam, which allowed unauthorized access to internal customer support systems.
🔍 Root Cause:
- A developer’s admin account—originally tied to an outdated Steam test account—was breached.
- The attacker exploited weak security around legacy accounts, gaining access to the developer portal, a tool used by GGG’s support team.
- Although the Steam account had no purchases or personal data, it provided a critical foothold into the internal system.
📌 Exposed Data:
The attacker accessed and manipulated user data through the developer portal, resulting in exposure of:
- Email addresses
- Steam IDs
- IP addresses
- Shipping addresses
- Unlock codes
- Transaction histories (for some users)
- Private messages from staff to players
⚠️ Note: Passwords and password hashes were not directly accessible via the portal. However, the exposure of email addresses raises concerns about credential stuffing attacks, especially if users reused passwords from other breaches.
🔒 Attack Actions:
- 66 accounts had randomized passwords set by the attacker.
- A bug in the system allowed deletion of activity logs, enabling the attacker to erase traces of their actions.
- The bug has since been patched and confirmed non-replicable in live systems.
- The attacker could view account details for a “significant number” of users, leveraging access to the developer portal.
✅ Immediate Response by Grinding Gear Games:
- Account locked and compromised credentials immediately isolated.
- All admin accounts were forced to reset passwords.
- Third-party accounts (e.g., Steam) can no longer be linked to staff accounts.
- Stricter IP restrictions implemented for administrative access.
- Full investigation conducted; no evidence of data exfiltration beyond internal system access.
🎮 Context: Path of Exile 2’s Status
- Launched in early access (December 2024) with strong player engagement.
- Recent patch improved performance on PlayStation 5 and addressed gameplay issues (monsters, skills, damage).
- A major new patch is imminent, but the breach has delayed player re-entry as GGG prioritized transparency and security.
💬 Player Reactions:
- Positive: Many praised GGG for immediate transparency, prompt action, and detailed public disclosures.
- Negative/Concerned: Players are calling for:
- Mandatory two-factor authentication (2FA) for all accounts.
- Enhanced account recovery procedures.
- Stronger security for cross-platform logins (especially Steam-linked accounts).
🛡️ Future Security Measures:
- 2FA rollout is expected in the near-term, with development underway.
- All legacy test accounts have been decommissioned.
- Ongoing security audits and improved monitoring of admin access.
- Players are encouraged to change passwords and enable 2FA as soon as available.
✅ Final Takeaways:
- The breach was not a direct hack of player accounts, but an internal security failure via a compromised developer account.
- No evidence that user passwords were stolen, but risk of account takeover via credential reuse exists.
- GGG has acted swiftly and transparently—a model response in crisis management.
- Players should proactively secure their accounts and monitor for suspicious activity.
🔗 Next Steps for Players:
- Change your Path of Exile 2 password (if not already done).
- Enable 2FA when available.
- Review linked accounts (especially Steam).
- Monitor email and in-game notifications for anomalies.
Bottom Line:
While the breach was serious, Grinding Gear Games’ prompt, clear, and comprehensive response has helped maintain trust. With ongoing improvements, Path of Exile 2 remains on track for a strong future — provided players and developers alike prioritize security moving forward.