Action security social Interviews cover track information

'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen

pcgamer.com

During an interview earlier this week, developer Grinding Gear Games revealed that around 66 Path of Exile 1 and 2 accounts were hacked after an act of social engineering exploited an old Steam profile—one that was both linked to an admin account and, crucially, forgotten about and unsecured.

The full extent of the damage has been revealed in a post to the Path of Exile forums, which further explains that the Steam account in question «was a regular Steam account and had no purchases, phone numbers, addresses or other information associated with it,» meaning that «the only information that they were required to supply was the email, account name and be using a VPN from the same country.» Game director Jonathan Rogers previously said that the hacker took advantage of a bug in the studio's audit log system: Wherein password resets were instead considered «notes», and thus were able to be deleted to cover their tracks as they «set random passwords on 66 accounts».

The post promises that «this bug doesn't exist for other support actions and has been fixed now.» In a grim turn, however, it turns out that the hacker was able to also potentially view personal information for «a significant number of accounts».

These include email addresses and Steam IDs «if the account had one associated», as well as IP addresses, shipping addresses «if the account had previously had physical goods sent», and an unlock code for lifting region-specific accounts.

Other personal info at risk in the attack included transaction history and private message histories, some of which were between Grinding Gear Games staff. «It is probable,» the post states, «that the attacker would be able to compare email addresses found using our portal against publicly available lists of compromised passwords from other websites in order to find accounts that shared the same password with their PoE account.

Все новости дня

This page might use cookies if your analytics vendor requires them.