Data Breach Notification

"
My poe 2 account was locked since 22 dec for 3 weeks, i had to make this account to post on forums.

i emailed to support on 2 different emails all providing infos regarding what happened, gave payment receipts from paypal and in game character details. after 3-4 back and forth emails, i thought all necessary info needed was given, yet the latest email asked for more info. Why arent all necessary questions needed all asked at once? now how long more do i have to wait? why arent support prioritizing those who emailed first, i learnt not to send follow up emails to reset my position, why is there someone who email later and got theirs resolved first?


after so long, i do not expect a compensation tho i honestly think some small compensation is only right after so long? lets say no compensation, the least you guys can do is let me play the game i paid for by unlocking my account first and refund me unauthorized purchases of 4 EA keys on 19 dec. it was bought via my poe 2 acc, i play via steam, never touched standalone client before even in the brief playthrough in poe 1, no purchase history on my steam history besides first key. scanned pc for malware - clean, did not use 3rd party apps and i only used poe 2 trade website.

if the next email still asks me for info to prove that im the owner of this account, i will be so f mad, that i think u guys are just toying with me or stalling for whatever reason.

i gave u what i can remember from the 3 week of no login, how much more or longer can i remember those details? but i did made a typo in my latest email reply - i wanted to say i purchase all variations of stash tabs but instead i typed guild tabs. THANK F i saved my poe 2 profile website as a bookmark for convenience, i didnt even know thrs a # 4 digit number attached.

unlock my account and let me play
akatsuki_wei#5715


Welcome to the club buddy.

Also i dont worry anymore, i just bought new key with 300 points (it's enough to play) if they still dont unlock my account before next league or economy reset i just play from new one, GGG support is messed up so bad.
Last edited by derilzdota#2658 on Jan 15, 2025, 12:03:45 AM
We need 2FA!
no i understand they are overwhelmed but even if they cannot clear tickets fast enough, efficiency would be the most important here? part of my work requires me to handle customer service online so i know what it feels like on the other end to a certain extend. after our last email exchange idk what more i need to show or proof. im also so fed up and tired from work, the last thing i need to worry about is my outlet for fun
"
"
Unfortunately there was a bug in the event log for this particular support action that allowed the attacker to delete the event showing that the change had occurred.


More likely it was overlooked than the possibility of it being a specific bug.
Calling it a "bug" was for future liability reasons.
I appreciate that they tell us at all what happened. I'm sadly used to Blizzard responses, which isn't much more than we are working on it or already have. They almost never reveal how hacks happen.


Yea, I dont buy the bug explanation either.

I do massive and widespread data logging for my job, windows logs, msq logs etc etc.

This screams "someone forgot to set to write only and left it as modify/full control."

I've seen far to many complacent admins set up services then forget to apply the proper security polices/GPOs like that.
Last edited by Offskee#9795 on Jan 15, 2025, 12:11:49 AM
lol


We can’t verify, but it’s only 66 accounts so trust us!


New Zealand I don’t care how your laws work but this is [Removed by Support] country and you about to find out!
Last edited by ShaunB_GGG#0000 on Jan 15, 2025, 2:00:41 AM
As a tech professional of 20 years, I think I've earned the right to say that its not really acceptable for a company as big as GGG, who makes as much money as they do and hire many many engineers as they do - to not have 2 factor authentication set up by now.

This is the bread and butter of web security: 2FA is the bare basics.

(Happy to come work for you if you would only change your silly "work from office" policy. This is turning away all the best engineers, by the way).

I've been in companies of only a dozen engineers who still served a product to millions of users and it only cost us money NOT TO have 2FA set up.

Maybe GGG is about to learn this lesson too.

Hard way to learn it... Corner cutting usually doesn't pay off in tech. Its best to be very risk-averse.

All the best with your upcoming security sprint, GGG engineers. I see you, I know its probably not your fault (its always some manager saying "No time for that! We gotta get this other release out TONIGHT: I've promised the shareholders!!!").

Don't be too hard on the engineers, Exiles. They're almost certainly our allies here.

Shareholders? Not so much. They'll ruin the whole damn world for a payday, and are.
Last edited by evilstarship#1007 on Jan 15, 2025, 12:29:21 AM
Hi GGG,

Can you answer my email? You confirmed in this post that the user could see messages. My POE2 additional keys were redeemed in this breech, and I can confirm the person I shared it with, did not redeem it.
I love how everyone and their mother is screaming "give us MFA", even if MFA would do nothing for an attack like this. Unless its implemented for GGG accounts first, which Jonathan clearly said it will be.

And at the same time there are people waiting for ages for locked account recovery - and thats exactly what will spread like epidemic, if MFA is forced on everyone.

Dont get me wrong, i fully support MFA everywhere, its easy to implement in 2025 - but it not so easy to cover with support in case anything happens...
Its GG
"The PoE account in question was linked to an old steam account that was created by a developer for testing a long time ago, and didn't have any purchases on it. The compromise occurred when the attacker was able to supply enough information to steam support to steal the account."
I can't wrap my head around this, how can a hacker have access to this information? How can they find your old admin Steam account, how can they provide your admin information to Steam and take over the account?

Report Forum Post

Report Account:

Report Type

Additional Info