Data Breach NotificationLast week we became aware that a PoE account with admin access to the website owned by one of our developers had been compromised. This gave them access to the tools that our customer support agents use. We immediately locked the account, and forced password resets on all other admin accounts. We then began an investigation into what had occurred. The PoE account in question was linked to an old steam account that was created by a developer for testing a long time ago, and didn't have any purchases on it. The compromise occurred when the attacker was able to supply enough information to steam support to steal the account. Since the account was a regular steam account and had no purchases, phone numbers, addresses or other information associated with it, the only information that they were required to supply was the email, account name and be using a VPN from the same country. The attacker set random passwords on 66 accounts. Unfortunately there was a bug in the event log for this particular support action that allowed the attacker to delete the event showing that the change had occurred. This bug doesn't exist for other support actions and has been fixed now. The attacker also viewed account information for a significant number of accounts through our portal. For those accounts they got access to the following private information:
No passwords or password hashes were viewable through the customer service portal. In addition there are some accounts where the attacker looked at transaction history which would have shown a list of previous purchases. There are also some accounts where the attacker looked at the private message history on the account. Many of these are for GGG staff. It is probable that the attacker would be able to compare email addresses found using our portal against publicly available lists of compromised passwords from other websites in order to find accounts that shared the same password with their PoE account. If that was the case, they would have been able to bypass the region locking using the unlock code. We have taken steps to ensure that there are more security measures around admin accounts so that this can not happen again. No 3rd party accounts are allowed to be linked to any staff accounts and we have added significantly more stringent IP restrictions. We are incredibly sorry for this lapse in security. The measures taken to secure the admin website really should have already been in place and in the future we will be taking even more steps to make sure that this kind of issue never occurs again. |
|
" I really look forwarding to 2FA available to the wider player base to bolster the security of the entire PoE community. Last edited by ClumsyParasite#3060 on Jan 14, 2025, 7:46:11 PM
|
|
rue is a cat
|
|
Nice
|
|
oh my
|
|
pog?
|
|
You hate to see it. Gotta stay on top of those developer accounts. Access review is key.
|
|
W transparency
|
|
Will people who have had their accounts lost or items stolen receive support in getting those back?
|
|
What happens to the items they stole? This is on GGG.
You said they looked at a significant amount of accounts information. The EXACT information GGG uses to verify if someone who claims they own an account actually does. " How are we supposed to protect our accounts now that someone could possibly have all the information needed to recover the account through support. The exact same method that they used to get through Steam support works with GGG support. Except this time, they have ALL the information they could need saved with screen shots. Where is 2FA? Last edited by PoE#8983 on Jan 14, 2025, 9:37:06 PM
|