Compromised PoE Accounts: Stolen Items and Hacked Accounts - Discussion and Leads

"
Don't install shit on your computers.

I've had 3 steam accounts hacked because I was dumb enough to install cracked office. They made off with my cs go skins, without even using my password.
They hijack the session. They don't need your password.

All we have here is your word that you didn't use any 3th party apps.

I don't think this is a GGG issue but a steam issue.
Even if they add more security to PoE, session hijacks won't care.

Enable family view on steam as extra security, and put all games behind that pin code. They wont be able to do anything even if they hijack your session without the pin to exit the session.

Unless GGG comes out and admits to a breach, and as a tech that's been working in IT for over 10y, I'm inclined to believe that its far more likely user stupidity than established security system.

Stop. Using. 3th party tools, and never disable anti-virus to install them. It detects them for a reason.


It's understandable to assume a malicious program/hack when only a few people report an issue, but we are far beyond that point. There are numerous cases now, involving a wide range of circumstances—players using third-party programs, players without any, and even players on consoles.

At this stage, it’s crucial to set aside any bias. This thread is approaching 20 pages of reports, and it’s reasonable to believe that many affected players are not even posting here—they’re simply quitting or moving on to other games out of frustration.

The problem is widespread, and dismissing the experiences shared here isn’t helpful. As a guild leader, I’ve seen two long-time POE1 players quit the game outright. Neither posted here, but both were deeply frustrated. One used Overwolf, the other didn’t use any third-party programs, yet neither received an email unlock code. Both scanned their systems thoroughly with no issues found.

We need clear action and guidance from GGG on how to address this situation and ensure players can protect themselves effectively.
Last edited by WinterMaps#2257 on Jan 2, 2025, 3:11:22 PM
You are the type we are talking about that is not fully reading the posts and just defending GGG.

My account uses an external password manager
My account has random 30+ chats
My account passwords are not shared between accounts
My account has 2fa on steam
No emails of external access to my steam account
No 3rd party apps
No 3rd party websites
No overlays
I was only trading using the official website
I was not even in a party when this happened.

This is 100% a GGG issue/exploit. We can make random excuses all you want but some of us don't fall into "change your password" idea. Many are in the same criteria as me, some use apps, some don't. The only thing in common is the game itself
"
Malejas#1960 wrote:
You are the type we are talking about that is not fully reading the posts and just defending GGG.

My account uses an external password manager
My account has random 30+ chats
My account passwords are not shared between accounts
My account has 2fa on steam
No emails of external access to my steam account
No 3rd party apps
No 3rd party websites
No overlays
I was only trading using the official website
I was not even in a party when this happened.

This is 100% a GGG issue/exploit. We can make random excuses all you want but some of us don't fall into "change your password" idea. Many are in the same criteria as me, some use apps, some don't. The only thing in common is the game itself


And I don't believe you.
It doesn't need to be a 3th party app.

It can be anything recently downloaded that was cracked. Repacked. Or modified in any way.

You can have all the passwords you want, all the 2fa's, and they won't amount to anything. If the password was used during this, then you'd have gotten a notification that someone is trying to log into your account.

You kind sir, got session hijacked. They don't need passwords.

Have you read when I said it was cracked Office that got me lose 3 steam accounts and all skins in CS GO? Cracked Office. I had nothing else on the computer just plain old windows, and steam.

I didn't go to complain on Steam.

These people that send these stuff in these programs that randoms download because we're poor and we can't buy them, they don't just target PoE. They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS.

PoE is just the recent addition.

If you played CS GO, and had skins, you'd lose them too, not just PoE.
"
"
Don't install shit on your computers.

I've had 3 steam accounts hacked because I was dumb enough to install cracked office. They made off with my cs go skins, without even using my password.
They hijack the session. They don't need your password.

All we have here is your word that you didn't use any 3th party apps.

I don't think this is a GGG issue but a steam issue.
Even if they add more security to PoE, session hijacks won't care.

Enable family view on steam as extra security, and put all games behind that pin code. They wont be able to do anything even if they hijack your session without the pin to exit the session.

Unless GGG comes out and admits to a breach, and as a tech that's been working in IT for over 10y, I'm inclined to believe that its far more likely user stupidity than established security system.

Stop. Using. 3th party tools, and never disable anti-virus to install them. It detects them for a reason.


It's understandable to assume a malicious program/hack when only a few people report an issue, but we are far beyond that point. There are numerous cases now, involving a wide range of circumstances—players using third-party programs, players without any, and even players on consoles.

At this stage, it’s crucial to set aside any bias. This thread is approaching 20 pages of reports, and it’s reasonable to believe that many affected players are not even posting here—they’re simply quitting or moving on to other games out of frustration.

The problem is widespread, and dismissing the experiences shared here isn’t helpful. As a guild leader, I’ve seen two long-time POE1 players quit the game outright. Neither posted here, but both were deeply frustrated. One used Overwolf, the other didn’t use any third-party programs, yet neither received an email unlock code. Both scanned their systems thoroughly with no issues found.

We need clear action and guidance from GGG on how to address this situation and ensure players can protect themselves effectively.


I understand.
If it was data breach this wouldn't be 20 pages long. It would be tens of thousands of people. Not thousands. There are barely 30 unique users in this thread.

Also, it's so much easier to blame anyone. ANYONE but our own negligence.
Last edited by ex_IllusionisT#8571 on Jan 2, 2025, 3:35:05 PM
"
"
"
Don't install shit on your computers.

I've had 3 steam accounts hacked because I was dumb enough to install cracked office. They made off with my cs go skins, without even using my password.
They hijack the session. They don't need your password.

All we have here is your word that you didn't use any 3th party apps.

I don't think this is a GGG issue but a steam issue.
Even if they add more security to PoE, session hijacks won't care.

Enable family view on steam as extra security, and put all games behind that pin code. They wont be able to do anything even if they hijack your session without the pin to exit the session.

Unless GGG comes out and admits to a breach, and as a tech that's been working in IT for over 10y, I'm inclined to believe that its far more likely user stupidity than established security system.

Stop. Using. 3th party tools, and never disable anti-virus to install them. It detects them for a reason.


It's understandable to assume a malicious program/hack when only a few people report an issue, but we are far beyond that point. There are numerous cases now, involving a wide range of circumstances—players using third-party programs, players without any, and even players on consoles.

At this stage, it’s crucial to set aside any bias. This thread is approaching 20 pages of reports, and it’s reasonable to believe that many affected players are not even posting here—they’re simply quitting or moving on to other games out of frustration.

The problem is widespread, and dismissing the experiences shared here isn’t helpful. As a guild leader, I’ve seen two long-time POE1 players quit the game outright. Neither posted here, but both were deeply frustrated. One used Overwolf, the other didn’t use any third-party programs, yet neither received an email unlock code. Both scanned their systems thoroughly with no issues found.

We need clear action and guidance from GGG on how to address this situation and ensure players can protect themselves effectively.


I understand.
If it was data breach this wouldn't be 20 pages long. It would be tens of thousands of people. Not thousands. There are barely 30 unique users in this thread.

Also, it's so much easier to blame anyone. ANYONE but our own negligence.


Like I said in my post, of the two people I know it happened two neither of them posted here...they simply quit the game. Additionally the best lead right now is that it has to do with trading and accessing some sort of data during that trade. Neither received log in e-mails. Their e-mail history & steam history shows no access from any other location.
"
"
Malejas#1960 wrote:
You are the type we are talking about that is not fully reading the posts and just defending GGG.

My account uses an external password manager
My account has random 30+ chats
My account passwords are not shared between accounts
My account has 2fa on steam
No emails of external access to my steam account
No 3rd party apps
No 3rd party websites
No overlays
I was only trading using the official website
I was not even in a party when this happened.

This is 100% a GGG issue/exploit. We can make random excuses all you want but some of us don't fall into "change your password" idea. Many are in the same criteria as me, some use apps, some don't. The only thing in common is the game itself


And I don't believe you.
It doesn't need to be a 3th party app.

It can be anything recently downloaded that was cracked. Repacked. Or modified in any way.

You can have all the passwords you want, all the 2fa's, and they won't amount to anything. If the password was used during this, then you'd have gotten a notification that someone is trying to log into your account.

You kind sir, got session hijacked. They don't need passwords.

Have you read when I said it was cracked Office that got me lose 3 steam accounts and all skins in CS GO? Cracked Office. I had nothing else on the computer just plain old windows, and steam.

I didn't go to complain on Steam.

These people that send these stuff in these programs that randoms download because we're poor and we can't buy them, they don't just target PoE. They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS.

PoE is just the recent addition.

If you played CS GO, and had skins, you'd lose them too, not just PoE.



You can choose to believe me or come up with your own scenarios. My job is to tell you what happened in my scenario, I dont use cracked software either, you can continue to blame 3rd party apps or anything else under the sun, but this is the same case to many players and again the only thing in common is the game, not a cracked software that happened to get us all, not a weak password that happened to get us all.

So again you can continue to make up stories or actually read what people are reporting. I guess next it will be "its your bnet application and d4 that caused it" its literally the only other app on this pc. OR maybe there is an exploit/bug that GGG was unaware of. Again either read the room or make up your own stories which seems more accurate?
"
You kind sir, got session hijacked. They don't need passwords.

Have you read when I said it was cracked Office that got me lose 3 steam accounts and all skins in CS GO? Cracked Office. I had nothing else on the computer just plain old windows, and steam.

I didn't go to complain on Steam.

These people that send these stuff in these programs that randoms download because we're poor and we can't buy them, they don't just target PoE. They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS.

PoE is just the recent addition.


If it is some ominous "session hijacking" (could u explain what that is and how people can protect them) and "They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS" why is it only peoples PoE2 account that has been hacked?

Why dont people report their other game accounts, bank accounts or emails got hacked too? From every post i've read it is only PoE2 accounts that got hacked.
"
"
You kind sir, got session hijacked. They don't need passwords.

Have you read when I said it was cracked Office that got me lose 3 steam accounts and all skins in CS GO? Cracked Office. I had nothing else on the computer just plain old windows, and steam.

I didn't go to complain on Steam.

These people that send these stuff in these programs that randoms download because we're poor and we can't buy them, they don't just target PoE. They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS.

PoE is just the recent addition.


If it is some ominous "session hijacking" (could u explain what that is and how people can protect them) and "They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS" why is it only peoples PoE2 account that has been hacked?

Why dont people report their other game accounts, bank accounts or emails got hacked too? From every post i've read it is only PoE2 accounts that got hacked.


I am quickly finding out GGG has A LOT of PR people, literally anyone that hasn't been hacked *yet* is talking like that so I wouldn't worry about them, when they wake up and half their stuff is gone, they will have to tell themselves maybe it was a pdf file they downloaded in 2019 that did it.
"
Don't install shit on your computers.

I've had 3 steam accounts hacked because I was dumb enough to install cracked office. They made off with my cs go skins, without even using my password.
They hijack the session. They don't need your password.

All we have here is your word that you didn't use any 3th party apps.

I don't think this is a GGG issue but a steam issue.
Even if they add more security to PoE, session hijacks won't care.

Enable family view on steam as extra security, and put all games behind that pin code. They wont be able to do anything even if they hijack your session without the pin to exit the session.

Unless GGG comes out and admits to a breach, and as a tech that's been working in IT for over 10y, I'm inclined to believe that its far more likely user stupidity than established security system.

Stop. Using. 3th party tools, and never disable anti-virus to install them. It detects them for a reason.


I have 2FA enabled on Steam.
I have Family View enabled.
There are no suspicious logins in my Steam history, all were made by me from the same location. Same for eMail.
I was hacked.
"
"
Malejas#1960 wrote:
You are the type we are talking about that is not fully reading the posts and just defending GGG.

My account uses an external password manager
My account has random 30+ chats
My account passwords are not shared between accounts
My account has 2fa on steam
No emails of external access to my steam account
No 3rd party apps
No 3rd party websites
No overlays
I was only trading using the official website
I was not even in a party when this happened.

This is 100% a GGG issue/exploit. We can make random excuses all you want but some of us don't fall into "change your password" idea. Many are in the same criteria as me, some use apps, some don't. The only thing in common is the game itself


And I don't believe you.
It doesn't need to be a 3th party app.

It can be anything recently downloaded that was cracked. Repacked. Or modified in any way.

You can have all the passwords you want, all the 2fa's, and they won't amount to anything. If the password was used during this, then you'd have gotten a notification that someone is trying to log into your account.

You kind sir, got session hijacked. They don't need passwords.

Have you read when I said it was cracked Office that got me lose 3 steam accounts and all skins in CS GO? Cracked Office. I had nothing else on the computer just plain old windows, and steam.

I didn't go to complain on Steam.

These people that send these stuff in these programs that randoms download because we're poor and we can't buy them, they don't just target PoE. They target ANY AND ALL GAMES that have ANY VALUE WITH TRADABLE ITEMS.

PoE is just the recent addition.

If you played CS GO, and had skins, you'd lose them too, not just PoE.


I absolutely adore that you think your anecdotal experiences being a particularly stupid person must pertain to everybody else on the planet.
Last edited by Cosette#9244 on Jan 2, 2025, 8:45:40 PM

Report Forum Post

Report Account:

Report Type

Additional Info