Path of Exile studio warns of 'malicious' phishing post that appeared on Steam, tells players 'please take immediate action to secure your account'

Grinding Gear Games is warning followers to change their passwords after a post containing a phishing link appeared briefly on the Path of Exile page on Steam.

"Earlier today, a malicious news post containing a phishing link went up on the Path of Exile Steam page from a compromised account," the studio wrote in a message posted to Steam and Twitter. "The post was taken down quickly, but if you followed the link or suspect your account may also be compromised, please take immediate action to secure your account."

(Image credit: Grinding Gear Games (Twitter))

Phishing, simply put, is a type of scam that uses fake links in emails or websites to entice people to share personal or sensitive information, or install malware onto their PCs. It's a very common form of "social engineering," to use the polite term for it, and often easy to pick out: If you've ever received a poorly-spelled email warning that your mailbox is full and telling you to "click here to increase storage space," you know what I'm talking about.

We should all know better by now, but as we noted a couple years ago, phishing emails are still a big danger because of the sheer volume of the things, but more importantly because of their increasing sophistication. Bad spelling and weird fonts are easy to pick out, but sometimes it's honestly hard to tell what's legit and what's going to cause you a very bad Tuesday three months down the road.

No information about the malicious post itself is provided in the update, but Steam user Keijokainen said in the comments that the link led to a fake registration page for a Path of Exile 2 beta test. The scam site was "pretty well disguised" according to Keijokainen, and "a higher effort than normal scam attempts." Another user said the link led to "pathofexiie.com"—note the sequential "ii" rather than il, which is sometimes easy to overlook at a quick glance—rather than pathofexile.com.

In a statement provided to PC Gamer, Grinding Gear Games confirmed that this is in fact what happened. "An attacker managed to gather a lot of semi-public information about one of our developers, with that information they were able to answer all the Steam verification questions about the account and have the email address changed," a studio representative said. "After this occurred they posted the phishing links as official news for Path of Exile.

"Yes, it was a link to a fake signup, and we don't know how many people were added to it, but it was taken down asap."

Making the phishing post more believable is that a Path of Exile 2 beta is on the way: It was recently delayed from June until "later this year" but it's not unreasonable that Grinding Gear Games would be taking sign-ups for it now.

News of the phishing attempt has sparked discussion about whether the phishers would be able to bypass Steam's multifactor authentication (MFA), and the answer seems to be a definite maybe. The login credentials could be used in the standalone Path of Exile launcher if it's been set up to work independently of Steam, and while PoE will apparently send an email verifying a login if it comes from a new IP address, several users say that system is inconsistent at best. Of course, it's not just the risk of your Path of Exile account getting hosed that's an issue: If you use a shared password across multiple accounts, they're at risk too.

If you didn't hit the link there's nothing to worry about, but if you did (or even if you're just not sure) then follow Grinding Gear's advice: Change your password immediately and enable MFA. 

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Path of Exile 2 showing the Warbringer ascendancy class bludgeoning his way through a pack of hyenas
'You deserve better customer service': Path of Exile 2 studio apologizes for long support wait times but with 545,000 emails received, it's kind of understandable
Diver looking at a fish
Subnautica 2 dev sounds foghorn about 'fraudulent links' being sent to community members: 'We will never contact anyone by Steam DM for any potential playtests'
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Latest in RPG
Minthara BG3 looking upset
Another round of Baldur's Gate 3 unearthing reveals Minthara can end up living in a sewer, an unused beach ending, and more
Person battling bizarre four-eyed monster with stylish UI elements surrounding them
Persona and Metaphor: ReFantazio's UI designer is open to accessibility options for players who find the stylish menus overstimulating: 'That is something we understand we'll need to work on and provide in the future'
Like a Dragon: Infinite Wealth money farm - Super Crazy Delivery
Like a Dragon series director sums up why sidequests are essential to a great RPG with a single metaphor: 'a good main dish alone will not earn you a Michelin star'
Image of a sweetroll with a candle in it
Bethesda marks Oblivion's 19th with a sweetroll, a candle, and absolutely no happy birthday gift for fans eager for the still-unannounced remaster
Fallout 76 ghoul screenshots
Getting to level 50 in Fallout 76 to become a ghoul actually isn't as daunting as it seems, which is why I created a new character
Koana, a main character in Final Fantasy 14: Dawntrail, stares thoughtfully at a book in his hands.
After a controversial coding slip-up fed stalkers info on their victim's alts, FF14 wipes the slate clean to try and fix its mistakes
Latest in News
Shadow of Mordor's beloved nemesis system exists because the publisher threw a tantrum about second-hand sales
Silent Hill f transmission trailer screenshots
Silent Hill f is not messing around – now it's been banned in Australia
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
'Google must divest the Chrome browser:' DOJ renews call for Google to sell Chrome, and Android could be next
Victory screen of Big Rigs showing infamous "You're Winner" message under a three-handle gold trophy
One of the worst games ever made is coming to Steam, but we won't know how cruel this joke is until we see the price tag
Sci-fi character from Dune
Dune: Awakening promises us a breath of fresh air, skipping early access for a full launch with no monthly subscription in May
Baldur's Gate 3 Karlach concept art
'The dream of the tech industry is to sell off your company at an overinflated price and retire,' says actor behind Baldur's Gate 3's Karlach, 'And I feel that's being done with game studios right now'