Path of Exile developer, Grinding Gear Games, sincerely apologizes for a recent security breach stemming from a compromised test Steam account with administrator privileges. This announcement details the events and the steps taken to prevent future incidents.
Over 66 Accounts Compromised
Grinding Gear Games acknowledged a data breach in a forum post titled "Data Breach Notification." A hacker compromised a Steam account with administrative access to Path of Exile (PoE). This account, used for internal testing and lacking linked purchases, phone numbers, or addresses, was exploited. The attacker successfully impersonated the account owner to Steam support, providing minimal information like email and account name, potentially aided by VPN use to mask their location. This granted them access to alter passwords on 66 PoE 1 and PoE 2 accounts using internal customer support tools.
Further, the attacker deleted password change notifications, concealing their actions from account holders. Compromised information included email addresses, Steam IDs, IP addresses, shipping addresses, unlock codes, transaction histories (for some accounts), and private messages. This data poses a significant risk to affected users' other online accounts.
The developers stated, "We have implemented enhanced security measures for admin accounts to prevent recurrence. Third-party account linking to staff accounts is prohibited, and significantly stricter IP restrictions are now in place. We deeply regret this security lapse. The necessary admin website security measures should have been implemented earlier, and we're committed to further improvements to prevent similar incidents."
Community responses praised the developers' transparency, while urging the implementation of two-factor authentication (2FA) for enhanced security. While the timeline for 2FA remains unclear, players are advised to change their passwords and remain vigilant regarding account information.