Grinding Gear Games, the developers behind Path of Exile (PoE), have issued a heartfelt apology following a significant data breach that affected their community. The incident, which was detailed in a post titled "Data Breach Notification" on the official PoE forums, involved a compromised Steam account with administrative privileges, originally created for testing purposes. This breach led to unauthorized access and the manipulation of over 66 PoE 1 and PoE 2 accounts.
Developers Promise Enhanced Security Measures
The hacker gained access to the test account by deceiving Steam customer support with basic information, including the account's email address and name, aided by a VPN to appear in the same country. Once inside, they used the account's administrative tools, typically used by customer support, to reset passwords on the affected accounts. These actions were concealed by deleting notification emails, preventing the account holders from being alerted to the changes.
The breach allowed the attacker to access sensitive data such as email addresses, Steam IDs, IP addresses, shipping addresses, unlock codes, transaction histories, and private messages. This information could potentially be used maliciously against the affected users' other online accounts.
In response, Grinding Gear Games has vowed to strengthen their security protocols. "We have taken steps to ensure that there are more security measures around admin accounts so that this cannot happen again," the developers stated. They have implemented stricter IP restrictions and banned the linking of third-party accounts to staff accounts. Acknowledging the oversight, they expressed deep regret and committed to further enhancing security measures to prevent future incidents.
The community's response on the forums was mixed, with some players appreciating the transparency of Grinding Gear Games, while others called for the implementation of two-factor authentication (2FA) to bolster account security. As the developers consider future security enhancements, PoE players are advised to change their passwords and remain vigilant about their account information to protect themselves from potential threats.