Path of Exile 2 Issues Apology for Massive Data Breach

Apr 10,25

Path of Exile 2 Apologizes for Major Data Breach

Path of Exile 2 Apologizes for Major Data Breach Grinding Gear Games, the developer behind Path of Exile (PoE), has issued a heartfelt apology following a significant security breach. The incident, which affected over 66 accounts, was caused by a compromised test Steam account with administrative privileges. Read on to understand the full scope of the breach and the steps taken to prevent future occurrences.

Over 66 Accounts Compromised

Path of Exile 2 Apologizes for Major Data Breach In a detailed post on the official PoE forums titled "Data Breach Notification," Grinding Gear Games explained the sequence of events. A hacker gained access to a Steam account used for testing purposes, which had admin rights but no linked personal information. The attacker tricked Steam's customer support into granting access by using basic information like the email address and account name, along with a VPN to mimic the account's country of origin.

Path of Exile 2 Apologizes for Major Data Breach Once inside, the hacker used customer support tools to reset passwords on 66 PoE 1 and PoE 2 accounts, deleting notifications to cover their tracks. This breach allowed access to sensitive data including email addresses, Steam IDs, IP addresses, shipping addresses, unlock codes, transaction histories, and private messages. The compromised information could potentially be used for malicious purposes, impacting the affected users' other accounts.

Developers Promise Better Security Measures

Path of Exile 2 Apologizes for Major Data Breach In response, Grinding Gear Games has implemented several new security measures. "We have taken steps to ensure that there are more security measures around admin accounts so that this cannot happen again," the developers stated. These measures include prohibiting third-party account links to staff accounts and enforcing stricter IP restrictions. The team expressed deep regret for the security lapse and committed to further enhancing security protocols to prevent similar incidents in the future.

The community's response on the forum was mixed, with some players appreciating the transparency and others calling for the addition of two-factor authentication (2FA) to bolster account security. While Grinding Gear Games has not yet implemented 2FA, players are advised to change their passwords and remain vigilant about their account information to safeguard against potential future breaches.

Copyright © 2024 godbu.com All rights reserved.