'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen

A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
(Image credit: Grinding Gear Games)

During an interview earlier this week, developer Grinding Gear Games revealed that around 66 Path of Exile 1 and 2 accounts were hacked after an act of social engineering exploited an old Steam profile—one that was both linked to an admin account and, crucially, forgotten about and unsecured.

The full extent of the damage has been revealed in a post to the Path of Exile forums, which further explains that the Steam account in question "was a regular Steam account and had no purchases, phone numbers, addresses or other information associated with it," meaning that "the only information that they were required to supply was the email, account name and be using a VPN from the same country."

It's a huge breach of privacy—and one Grinding Gear Games seems to be taking seriously. "We have taken steps to ensure that there are more security measures around admin accounts so that this can not happen again. No 3rd party accounts are allowed to be linked to any staff accounts and we have added significantly more stringent IP restrictions."

For context, while some accounts compromised were due to passwords already being out there—a solid reminder to make sure you aren't using the same password for everything, and to check your password against public listings of hacked ones—personal info being scraped is deeply concerning. A hacker knowing someone's IP and shipping address makes that person inherently more vulnerable to other social engineering (that is, using secondary information to access an account).

Harvey Randall
Staff Writer

Harvey's history with games started when he first begged his parents for a World of Warcraft subscription aged 12, though he's since been cursed with Final Fantasy 14-brain and a huge crush on G'raha Tia. He made his start as a freelancer, writing for websites like Techradar, The Escapist, Dicebreaker, The Gamer, Into the Spine—and of course, PC Gamer. He'll sink his teeth into anything that looks interesting, though he has a soft spot for RPGs, soulslikes, roguelikes, deckbuilders, MMOs, and weird indie titles. He also plays a shelf load of TTRPGs in his offline time. Don't ask him what his favourite system is, he has too many.