Home >  News >  Path of Exile 2 Confirms Data Breach

Path of Exile 2 Confirms Data Breach

by Nova May 16,2025

Path of Exile 2 Confirms Data Breach

Summary

Grinding Gear Games, the developer behind Path of Exile 2, confirmed a data breach that occurred during the week of January 6, 2025. The breach stemmed from a compromised developer's account, which was linked to Steam, leading to the exposure of player email addresses, Steam IDs, IP addresses, and other sensitive information.

The breach was initiated when an unauthorized user accessed a developer's admin account, which had been linked to an old Steam account used for testing. This access allowed the attacker to use customer support tools, affecting other accounts through the developer portal. Grinding Gear Games promptly locked the compromised account and enforced password resets for all admin accounts. The investigation revealed that the breach enabled the attacker to alter passwords for 66 accounts and delete logs due to a bug, which has since been fixed.

The compromised data included email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes for a significant number of accounts. Although passwords and password hashes were not directly accessible, the attacker could potentially bypass region locking by comparing email addresses against lists of compromised passwords from other sites. The attacker also accessed transaction and private message histories for some accounts.

In response to the breach, Grinding Gear Games has implemented stricter security measures, including prohibiting third-party account linkages to staff accounts and enforcing more stringent IP restrictions. The community has shown a mixed reaction, with some appreciating the transparency while others demand the addition of two-factor authentication to enhance account security.

Path of Exile 2, which entered early access in December 2024, continues to receive updates and has recently improved performance on PlayStation 5, alongside fixes for monsters, skills, and damage. The next major patch is expected soon, and the developers addressed the data breach situation to ensure players are informed before engaging with the new content.

The community is also expressing a desire for improved security measures, additional in-game content, and adjustments to the endgame difficulty in Path of Exile 2.