
Grinding Gear Games, the developer behind Path of Exile (PoE), has issued a heartfelt apology following a significant data breach earlier this month. The breach was caused by a compromised test Steam account with admin rights, leading to serious security concerns for the community. Here's a detailed look at the incident and the steps being taken to prevent future breaches.

In a post titled "Data Breach Notification" on the official PoE forums, Grinding Gear Games explained the sequence of events. A hacker gained access to a Steam account used for testing purposes, which had admin rights. This account, created long ago, had no linked purchases, phone numbers, or addresses, making it vulnerable to the attacker's impersonation tactics. The hacker used basic information like the email address and account name, along with a VPN to mimic the user's location, to deceive Steam customer support into granting them access.
Once inside, the hacker utilized customer support tools to set random passwords on 66 different PoE 1 and PoE 2 accounts. They also deleted the password change notifications to avoid alerting the account owners. This breach allowed the hacker to access sensitive personal information, including email addresses, Steam IDs, IP addresses, shipping addresses, and unlock codes. They viewed transaction histories and private messages, potentially using this data for malicious purposes that could affect users' other accounts.

In response to the breach, Grinding Gear Games has taken immediate action to bolster their security protocols. They stated, "We have taken steps to ensure that there are more security measures around admin accounts so that this cannot happen again. No third-party accounts are allowed to be linked to any staff accounts, and we have added significantly more stringent IP restrictions. We are incredibly sorry for this lapse in security. The measures taken to secure the admin website really should have already been in place and in the future, we will be taking even more steps to make sure that this kind of issue never occurs again."

Players have responded to the developers' transparency with mixed sentiments. Some have praised Grinding Gear Games for their honesty and quick response, while others have called for the implementation of two-factor authentication (2FA) to enhance account security. While the developers have not yet confirmed plans for 2FA, they are actively working to improve security measures.
In the meantime, PoE players are encouraged to change their passwords and remain vigilant about their account information to protect themselves from potential threats.